← All Compliance Insights

IT & Cybersecurity

Right Coverage, Wrong Response: How Incident-Response Mistakes Can Cost Cyber Insurance Coverage

Buying cyber insurance is only one part of managing cyber risk.

What happens after an incident is discovered can matter just as much. Cyber policies can contain requirements governing when an incident or claim must be reported, what information must be provided, whether the insurer's consent is required before taking certain actions, and how the insured must cooperate with the claims process.

Those provisions are not administrative details to sort out later. Real cases show that failing to follow them can result in a business having the right kind of insurance—and still losing coverage for the incident.

Heart of Gold Title: The Policy Existed, but the Notice Came Too Late

A 2026 federal court decision involving Heart of Gold Title, LLC illustrates the problem. In early 2024, individuals were tricked by someone impersonating the title company into wiring money to a fraudulent account. Heart of Gold had its IT provider examine its systems and concluded that its environment had not been infiltrated. The company did not notify its cyber insurer at that time.

Months later, the individuals who lost the money sued Heart of Gold for negligence. The company then notified its insurer in November 2024—approximately eight months after the original incidents. By then, according to the court, it was too late.

The Notification Clock Had Already Started

Heart of Gold had two consecutive claims-made-and-reported cyber policies. The court found no coverage under either.

Under the first policy, the claim was not made and reported before that policy period ended. Under the second policy, notice was required within 30 days of “Discovery.” The court concluded that discovery occurred when Heart of Gold first investigated the events in February and March—not months later when the lawsuit was filed. The eventual notice was therefore approximately seven months late.

A separate prior-knowledge exclusion also applied, and the court rejected the company's bad-faith claim against the insurer.

THE COMPANY HAD CYBER INSURANCE.
THE CLAIM STILL FAILED BECAUSE NOTICE CAME TOO LATE.

The lesson is that the policy's clock may begin running earlier than management assumes it does.

“We Called IT” Is Not the Same as “We Notified the Insurer”

One detail in Heart of Gold is particularly relevant to small businesses. The company did what many firms would instinctively do: it called its IT provider and investigated whether its systems had been compromised.

That was a sensible technical response. But technical investigation and insurance notification are separate processes.

An IT provider determining that no intrusion is visible does not necessarily answer questions such as:

  • Does the policy define this event as an incident, circumstance or potential claim?
  • Has a contractual reporting period begun?
  • Does the insurer need notice even if the full extent of the loss is not yet known?
  • Does the insurer require use of approved forensic, legal or remediation providers?
  • Must the insurer consent before the business takes certain actions?

Those are policy and claims-management questions, not purely technical ones. The firm should already know who is responsible for asking them.

Another Way to Lose Coverage: Acting Without the Insurer's Consent

Construction Financial Administration Services, LLC, or CFAS, experienced a business-email compromise involving fraudulent payment instructions. Attackers compromised a client's email account and caused CFAS to send two fraudulent payments totaling approximately $1.3 million. Only about $127,000 was recovered.

The company sought coverage under its Errors & Omissions policy. A federal court found two separate reasons coverage was unavailable. One involved a policy exclusion relating to unauthorized computer access. But the second reason is particularly important from an incident-response standpoint.

CFAS had settled the underlying dispute with its own client without first notifying the insurer and obtaining the insurer's consent. The court found that violation of the policy condition independently defeated coverage. Even if CFAS had been able to overcome the separate exclusion, the way it handled the claim would still have created a coverage problem.

THE COVERAGE QUESTION WASN'T ONLY WHAT HAPPENED.
IT WAS ALSO WHAT THE INSURED DID AFTERWARD.

Your Incident-Response Plan Should Know That Cyber Insurance Exists

Many incident-response plans focus primarily on technology:

  • isolate systems;
  • change passwords;
  • preserve logs;
  • restore backups;
  • investigate the attack.

Those steps matter. But if the company carries cyber insurance, the plan also needs to recognize that an insurance contract is now part of the response process.

Before an incident happens, the firm should know:

  • who maintains the current cyber policy;
  • who has authority to contact the broker or carrier;
  • what events potentially require notice;
  • what notice periods the policy contains;
  • what telephone numbers, portals or email addresses are used for reporting;
  • whether particular forensic investigators, breach counsel or other vendors must be approved;
  • whether insurer consent is required before settling claims or making certain payments;
  • who documents when the incident was first discovered;
  • who records when the insurer was notified; and
  • who coordinates the technical, legal and insurance workstreams.

The incident itself will still require judgment. But the basic process should not be invented while everyone is already responding to an emergency.

This Is Different From Getting the Insurance Application Wrong

There is another well-documented cyber-insurance risk: telling an insurer that a security control exists when it does not. In Travelers Property Casualty Company of America v. International Control Services, Inc., inaccurate representations concerning multifactor authentication ultimately resulted in the policy being treated as void from inception.

We discuss that issue separately in:

Cyber Insurance: Your Application Needs to Match Your Actual Security

The distinction is important. The Travelers case concerns the accuracy of the representations made when insurance was obtained. Heart of Gold and CFAS illustrate what can happen after an incident has already occurred.

Before the incident: Make sure the application accurately describes the security environment.

After the incident: Make sure the response follows the notification, consent and claims requirements contained in the policy.

Doing one correctly does not excuse getting the other wrong.

Cyber Insurance Should Be Part of Incident-Response Planning Before the Incident

A cyber policy should not be a PDF that someone searches for after ransomware appears on a screen. The relevant policy requirements should already be incorporated into the firm's incident-response process.

That does not mean the IT provider should interpret insurance contracts or make legal coverage determinations. Those questions belong with the firm's insurance professionals and legal counsel. But the security program should make sure the right people are brought into the response quickly enough to protect the firm's options.

The time to discover that the policy required notice within 30 days is not seven months after that period expired.

How GO InfoTek Can Help

GO InfoTek helps CPA and accounting firms build cyber-insurance considerations into their broader security and incident-response program. That can include:

  • documenting the firm's actual security controls;
  • aligning technical safeguards with representations made in cyber-insurance applications;
  • incident-response planning;
  • establishing insurance-notification escalation procedures;
  • identifying technical, management, legal and insurance responsibilities;
  • documenting incident timelines and response actions;
  • maintaining Written Information Security Plans and related policies;
  • security risk assessments; and
  • ongoing vCISO support.

GO InfoTek does not determine insurance coverage, interpret policy language on behalf of the firm or replace the firm's broker, carrier or legal counsel. Our role is to help ensure that the technical security program and incident-response process are organized so those professionals are engaged when they need to be.

Because having insurance and preserving the right to use it are not necessarily the same thing.

This article provides general technology, risk-management and insurance-process information. It is not legal or insurance advice, does not determine coverage and does not replace the firm's broker, carrier or legal counsel.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation