Insurance
Sep. 21, 2026
When systems crash: Avoiding common errors in network interruption claims
Policyholders can maximize recovery from network interruption claims by avoiding four common mistakes that can lead to disputes, delays and denials of coverage.
Richard DeNatale
Richard DeNatale is recognized as one of the nation's leading authorities in cyber insurance. He has represented over 125 companies in obtaining coverage for data breaches and cyberattacks, including some of the largest in history. DeNatale is semi-retired after a career of almost 40 years in Big Law, most recently as a partner at Jones Day.
It is every CEO's nightmare: hackers penetrate the company's defenses and remain undetected for several days. They exfiltrate files and install malware that corrupts and deletes data. The network is shut down to contain the attack, but recovery takes several weeks as systems are rebuilt and data restored. In the interim, the company suffers disruptions in production, logistics and deliveries, resulting in significant revenue losses.
If the company had the foresight to purchase cyber insurance, the CEO will look to the risk management group to recoup these losses. Almost all cyber policies provide network interruption coverage, which insures losses resulting from a network shutdown. But this type of coverage is poorly understood and often underutilized as policyholders make errors that reduce their recovery.
Coverage for shutdown losses
Network interruption coverage is triggered by a computer system shutdown that causes a material interruption in business operations. Most current policies cover shutdowns resulting from both malicious attacks and technical failures. The insurer will reimburse the policyholder for lost profits and extra expenses for a defined period, typically four to six months. The goal is to put the company in the same financial position it would have achieved in the absence of a shutdown. This goal is simple to state but difficult to implement, largely because calculation of lost profits requires a projection of future performance in a hypothetical world where the shutdown never occurred.
Not surprisingly, insurers tend to scrutinize such claims closely. They frequently question assumptions and methodology or contend that future sales figures are inflated. Regarding extra expenses, insurers will reject costs that are unreasonable, excessive or incurred in the ordinary course of business. And cyber policies create procedural obstacles as well. Most policies require insurer preapproval for certain expenses. Some recent policies provide that the policyholder must provide a final and binding loss calculation within as little as 90 days.
In short, many pitfalls lie in the path of a successful network interruption claim. Below we discuss four common missteps made by policyholders--each of which can reduce the recovery, yet each is easily avoided.
Mistake No. 1: The delayed start
When a major cyber incident occurs, companies must confront multiple simultaneous crises. They must investigate and contain the attack; remediate damage and restore systems; respond to regulators and claimants; etc. Many companies will defer pursuing the insurance claim until the other crises subside. Such delay is likely to prove costly. In the early stages of a recovery effort, employees throughout the company will incur a wide range of covered expenses to retain consultants, replace hardware and software, and establish temporary systems for critical operations. Companies need to quickly establish a protocol for reporting these costs and complying with insurance requirements. Otherwise, some costs will go unreported while others will lose coverage due to failure to obtain insurer approval or necessary documentation.
Mistake No. 2: The DIY claim
Another common error is the do-it-yourself claim--one the policyholder prepares on its own using in-house resources rather than outside coverage counsel and forensic accountants. In our view, policyholders should retain coverage counsel for any cyber claim of significance because (among other reasons) the insurer is certain to assign a lawyer to the claim.
As for forensic accountants, they are especially useful for network interruption claims that require a calculation of lost profits. To be sure, company executives play an important role in identifying potential areas of loss that are not obvious to an outside observer. But once the areas are identified, the use of forensic accountants offers several benefits. They will calculate and present the loss in a manner consistent with insurance industry practice, thereby facilitating the review process. They also serve as effective advocates for the claim in negotiations with the insurer. In addition, some stages of work, if done under supervision of counsel, can be protected as privileged in subsequent litigation.
Many policyholders choose not to retain outside professionals due to concerns about their fees. But for claims valued at seven figures or more, forensic accountants and coverage counsel can pay for themselves by increasing the ultimate recovery.
Mistake No. 3: Bullish public statements
In the aftermath of a cyber incident, companies often issue public statements to reassure customers, shareholders and other key constituencies. There are important reasons to do this, but companies should bear in mind that their insurer will track these communications looking for inconsistencies with the insurance claim. The more specific the statement, the more likely it will be treated as a factual admission. For example, if companies make statements regarding when systems were restored and when operations resumed, or regarding the amount of revenue loss, it will be difficult to convince the insurer to disregard such comments for purposes of the insurance claim. This tension can usually be resolved by avoiding overstatement and including appropriate caveats. But problems will arise when public statements are made without considering their potential impact on coverage.
Mistake No. 4: The inflated claim
Policyholders are sometimes tempted to pack the claim with items for which coverage is doubtful. Examples include the cost of software upgrades, hardware purchases that were scheduled prior to the shutdown, or lost sale opportunities that are speculative at best. By increasing the dollar value of the claim, the policyholder hopes to position itself for settlement negotiations in which it will be forced to settle at a discount.
In reality, submitting a maximalist claim is unlikely to increase the ultimate recovery. There is little chance the insurer will agree to pay for items that are not truly covered. Moreover, the maximalist approach will likely delay resolution of the claim and increase fees paid to outside professionals. Most important, this approach will undermine the policyholder's credibility and lead the insurer to question other aspects of the claim.
While judgment calls must be made in preparing any insurance claim, the best practice is to present a clean claim that can be defended to the last dollar and then refuse to settle for an unwarranted discount.
By submitting a clean and well-supported claim, and avoiding the other errors discussed above, the policyholder will put itself in the optimal position to recover its shutdown losses.
Submit your own column for publication to Diana Bosetti
For reprint rights or to order a copy of your photo:
Email
Jeremy_Ellis@dailyjournal.com
for prices.
Direct dial: 213-229-5424
Send a letter to the editor:
Email: letters@dailyjournal.com