Map the first hour
Write down who can contact the insurer, who can authorise emergency work and where the details are stored if company systems are unavailable. Ask how quickly specialist support is accessible and what information the team will need. Keep an offline copy of the process.
Ask before appointing outside help
Clarify whether forensic specialists, lawyers and recovery suppliers must be approved by the insurer. Discuss what can be done immediately to contain an incident and what needs consent. This avoids a plan that relies on services the policy will not reimburse.
Test the assumptions in the proposal
Review the answers given about backups, software updates, access controls and staff procedures with the people operating the systems. Correct inaccuracies before buying. A policy is a financial and response tool, while practical security and recovery planning remain ongoing work.
Take these questions to your provider
- Can the business meet the declared controls, including backups and authentication?
- Is a response team available, and must approved specialists be used?
- Are fraud, recovery, interruption and other benefits subject to separate smaller limits?
- How are incidents affecting cloud providers and other suppliers treated?
Sources & further reading
Checked 26 September 2026. Policy terms and source ratings can change.