The following examples are simplified and hypothetical. They illustrate questions that can arise under cyber insurance; they do not show that a real claim would be accepted or paid.
Cover depends on the policy wording, event, timing, security information supplied to the insurer, limits, excesses, consent requirements and evidence. Start with the Cyber Insurance UK guide and What Cyber Insurance Covers before using these scenarios.
Scenario 1: ransomware stops trading
A small wholesaler opens a malicious attachment. Attackers encrypt servers and shared files. Orders cannot be processed for four days, and the business hires forensic specialists and restores systems from backups.
Potentially relevant cover may include:
- incident-response and forensic costs;
- data and software restoration;
- business interruption after the waiting period;
- increased cost of working;
- cyber-extortion response.
Questions include whether the event meets the policy definition, whether backups and multi-factor authentication matched the application answers, whether approved suppliers were used and how loss of income is calculated.
A ransom payment is not automatic. The NCSC and UK law-enforcement bodies do not encourage, endorse or condone payment, and legal restrictions can apply.
Scenario 2: fraudulent supplier bank details
A finance employee receives an apparently genuine email from a supplier asking for bank details to be changed. The employee pays an invoice to the attacker’s account.
The business discovers the fraud two days later.
Potential cover depends on whether the policy includes social engineering, invoice manipulation, funds-transfer fraud or crime cover. A standard cyber-liability section may not cover the stolen money.
The insurer may ask whether independent call-back verification was required and followed. The business should contact its bank and appropriate reporting authorities immediately rather than waiting for an insurance decision.
The distinction between cyber and crime extensions is one reason to review what cyber insurance covers in detail.
Scenario 3: accidental email disclosure
An employee attaches the wrong spreadsheet to an email, disclosing customer information to an unintended recipient.
The organisation must contain the breach, assess what information was involved and decide whether notification to the ICO or affected individuals is required. If Article 33 applies, the ICO notification is required without undue delay and, where feasible, within 72 hours of awareness.
A cyber policy may fund legal assessment, notification and response support. Coverage questions include the breach definition, applicable excess and whether the incident falls within privacy-response cover even though no malicious attack occurred.
Scenario 4: cloud platform outage
A software-as-a-service platform used for bookings suffers a cyber attack. The insured business cannot access appointments or take online payments for two days.
Potential business-interruption cover depends on the dependent-system wording. The supplier may need to fall within a definition or be named. A waiting period, separate sub-limit or exclusion for infrastructure and widespread events may apply.
The business should retain service-status notices, sales records and evidence of additional costs. The Cyber Insurance Costs for SMEs guide explains why supplier dependence affects both underwriting and limit selection.
Scenario 5: stolen laptop with personal data
A laptop is stolen from a staff member’s vehicle. It contains locally stored personal information.
The organisation investigates whether the device was encrypted, what information was accessible and whether credentials could be used to reach cloud systems.
A cyber policy may provide breach-response support. An exclusion or condition concerning encryption, unattended devices or security controls may be relevant. Property insurance may address the physical laptop, while cyber insurance addresses selected data and response consequences.
Scenario 6: client alleges insecure software
A software developer delivers an application. An attacker later exploits a vulnerability and the client suffers interruption and response costs. The client alleges that the developer failed to follow agreed security requirements.
The developer may need to notify both cyber and professional indemnity insurers. Cyber cover may address the developer’s own incident or network-security liability; PI may address the allegation that the professional service was defective.
Read Cyber Insurance vs Professional Indemnity Insurance for the policy-boundary questions.
Scenario 7: employee account takeover
An attacker obtains an employee’s cloud-email password and creates forwarding rules. The attacker monitors conversations and sends fraudulent payment requests.
Potential costs include forensic investigation, account recovery, customer communication and fraudulent payments. The last category may need a specific social-engineering or crime extension.
The insurer may examine multi-factor authentication, privileged access and the accuracy of the proposal answers. The organisation should reset credentials, preserve logs and investigate whether other accounts or data were affected.
Scenario 8: website denial-of-service attack
An online retailer’s website is overwhelmed by malicious traffic during a peak trading period. The site is unavailable and emergency mitigation services are purchased.
Potential cover may include incident response, mitigation, business interruption and increased cost of working. Questions include the waiting period, evidence of lost sales, whether the incident meets the definition and whether a specialist provider required prior approval.
Scenario 9: supplier compromise spreads malware
A managed IT supplier distributes a compromised update to several customers. Malware reaches the insured’s network and interrupts operations.
The insured’s policy may respond to its own system event. It may also preserve rights against the supplier. Dependent-system or supply-chain provisions, contractual liability and recovery rights need review.
The insured should notify the insurer promptly and avoid destroying logs during containment.
Scenario 10: disgruntled insider deletes data
A departing administrator deliberately deletes cloud resources and backup snapshots.
Potential cover depends on employee-dishonesty, malicious-insider and data-restoration wording. Some cyber policies exclude dishonest acts by senior management but preserve cover for acts of other employees; crime insurance may also be relevant.
Access termination, privileged-account controls and backup separation will affect both recovery and the insurer’s factual investigation.
Scenario 11: payment processor incident
A retailer’s payment processor suffers a security incident. Customers cannot complete purchases, but the retailer’s own network is not compromised.
Dependent-system business interruption may be relevant if the processor is within scope. Loss calculation, waiting period and alternative payment arrangements matter. The processor’s own contract and liability do not replace the retailer’s need to follow its insurance notification process.
Scenario 12: personal-data complaint and regulator enquiry
After a breach, a customer complains that the business failed to secure personal information. The ICO asks for information about controls and the incident response.
A policy may provide legal advice and defence of a covered privacy claim or regulatory investigation. It may not cover every fine or penalty. The organisation remains responsible for cooperating with the regulator and providing accurate information.
Scenario 13: business voluntarily shuts systems down
A business detects suspicious activity and disconnects its network as a precaution. Later investigation shows that the attacker had limited access and no systems were encrypted.
The shutdown may have prevented a larger loss, but business-interruption cover can depend on whether voluntary shutdown is expressly included, objectively necessary or approved by the insurer. Keep a decision log explaining the information available at the time.
Scenario 14: corrupted backup delays recovery
A business expects to restore within one day, but the latest backup is corrupted and the previous usable copy is two weeks old. Staff must reconstruct transactions manually.
Data-restoration and interruption cover may be relevant. The insurer may examine backup testing and the recovery assumptions disclosed during underwriting. The claim calculation may distinguish restoration cost, ordinary operating cost and betterment.
Scenario 15: multi-client incident exhausts a sub-limit
A service provider suffers one compromise that affects many clients. It incurs its own response costs and receives several demands.
The policy may treat the matters as one event or several claims. An aggregate limit or privacy sub-limit can be exhausted across the clients. Defence costs may reduce the amount available for damages.
This scenario shows why the main limit, event aggregation and sub-limits must be reviewed together.
What to do after a suspected incident
Although the technical steps depend on the event, an organisation should normally:
- protect people and essential operations;
- contain the incident while preserving evidence;
- use a trusted communication route;
- notify the insurer or broker under the policy;
- contact the bank immediately for payment fraud;
- involve suitable forensic and legal specialists;
- assess ICO and individual-notification duties;
- report crime or serious incidents through the appropriate route;
- document costs, approvals and decisions;
- restore carefully and monitor for recurrence.
Do not admit liability, promise reimbursement or appoint unapproved suppliers without checking the policy and obtaining appropriate advice where time permits.
Evidence that may support a claim
Useful records can include:
- incident timelines;
- system and security logs;
- screenshots and malicious messages;
- forensic reports;
- backup and restoration records;
- bank and payment information;
- contracts and supplier notices;
- customer complaints;
- ICO correspondence;
- invoices for response and recovery;
- sales, payroll and expense records;
- decision and approval logs.
The Business Insurance Documents guide explains how to keep the policy schedule, wording and endorsements available alongside these incident records.
How to use these examples
Use each scenario to ask:
- Which event definition would be triggered?
- Which first-party and third-party sections are relevant?
- Is there a waiting period or sub-limit?
- Are security conditions satisfied?
- Does another policy also need notification?
- Which evidence would prove loss?
- Which supplier requires insurer consent?
- What legal or regulatory duty runs independently of insurance?
The examples are not predictions of settlement. A real outcome depends on the complete facts and policy.
Next step
Return to the Cyber Insurance UK guide to review the buying checklist, or compare likely loss categories with the cyber cost guide before requesting quotations.
Scenario 16: compromised social-media account
An attacker takes control of the business’s social-media account, posts fraudulent offers and directs customers to a false payment page.
Potential issues include account recovery, forensic work, customer communications, privacy or network liability and loss of funds suffered by customers. The business should also use the platform’s recovery process and preserve messages and screenshots.
Cyber insurance may help with response or liability, but the policy may exclude the customer’s direct payment loss or require a specific media-liability section.
Scenario 17: lost access to a domain name
A criminal compromises the registrar account and redirects the company’s domain and email. Customers cannot reach the genuine site and staff lose trusted email communication.
Relevant costs may include forensic support, emergency communications, domain recovery and interruption. Cover depends on the definitions of computer system, digital asset and interruption. The incident plan should contain an alternative domain or communication method where proportionate.
Scenario 18: unpatched software exploited
An attacker exploits a vulnerability for which a security update had been available. The business believed updates were automated, but one internet-facing server was outside the process.
The insurer may investigate proposal answers, patch-management conditions and whether the omission was material to the loss. The result depends on wording and causation; it should not be assumed that every control failure automatically defeats a claim or that it is irrelevant.
Scenario 19: former contractor retains access
A contractor’s account remains active after the engagement ends. Months later it is used to download confidential files.
The response includes access revocation, investigation, data-breach assessment and possible client communication. The insurer may ask about joiner, mover and leaver processes and privileged-access reviews.
Scenario 20: deepfake payment instruction
A finance worker receives a video or voice message that appears to come from a director and authorises an urgent payment. The message was generated or manipulated by criminals.
Whether the loss is insured depends on social-engineering or crime wording and any verification condition. The business should maintain independent payment checks that do not rely solely on the apparent realism of a message.
Lessons across the scenarios
The same themes recur:
- notify promptly;
- preserve evidence;
- verify which specialists may be appointed;
- separate legal duties from insurance decisions;
- check sub-limits and waiting periods;
- keep security information accurate;
- consider all potentially relevant policies;
- document reasonable mitigation decisions.
A claim is easier to manage when the response plan, insurance documents and decision authority are available before the incident.