Guide
Reporting duties that run alongside a cyber policy
Updated
A cyber incident can create two separate obligations at once: one to your insurer under the policy, and one to a regulator under data protection law. They have different timescales and different consequences, and the policy does not discharge the second.
Two clocks, not one
The policy will set out how and when to notify a claim, and late notification is a standard route to a declined one. Separately, where personal data is involved, a breach may have to be reported to the Information Commissioner's Office, and that duty exists whether or not you are insured and whether or not you claim.
Treat them as parallel tasks from the first hour. The instinct to wait until you understand what happened is exactly what makes both harder.
Why the insurer's response team helps here
The breach response services attached to most policies include legal support, and part of what that support does is help you work out whether a report is required and what it should say.
That is a strong practical argument for calling the incident line early rather than waiting: it starts the clock on the help as well as on the claim.
Records, before and after
Underwriters ask what data you hold, and regulators ask what happened to it. Both questions are far easier to answer if you counted beforehand.
A simple inventory of what personal data you hold, where it lives and who can reach it is useful for the proposal form, useful during an incident, and useful for reducing the exposure in the first place. The NCSC publishes practical guidance aimed at organisations of this size.
Do not let the claim decide the disclosure
Deciding whether to report to a regulator based on whether you want to claim is the wrong way round, and it is a decision to take with legal advice rather than commercial instinct.
The two obligations are independent. Handle each on its own terms.