This overview brings together all the questions and answers relating to IT forensics for the insurance industry at LanCologne – from reconstructing the circumstances of a claim, through cyberattacks and business interruptions, to verifying the authenticity of evidence and carrying out technical cross-checks on expert reports. Click on a category to view the relevant questions.
Cyber attacks, ransomware and compromise
- How can the plausibility of a reported cyber incident be assessed without jumping to the conclusion that it is insurance fraud?
- How can the impact of a ransomware attack be reconstructed in terms of the time of encryption and the actual extent of the damage?
- How can an insurance company have the actual start of a cyber incident determined through forensic analysis?
- How can one distinguish between the initial compromise and the actual occurrence of damage?
- How can an insurance company have the point of entry for a cyber attack investigated?
- How can we determine which corporate systems have actually been compromised?
- How can the actual scope of a ransomware attack be determined?
- How can the actual duration of the encryption process in a ransomware attack be reconstructed?
- How can one check whether data was actually exfiltrated prior to encryption?
- How can the volume of corporate data that may have been leaked be objectively determined?
- How can an insurance company distinguish between data that has been compromised and data that has actually been stolen?
- How can a business email compromise be reconstructed from a technical perspective?
- How can one verify whether a fraudulent payment instruction was actually sent from a compromised email account?
- How can an insurance company have an alleged takeover of a Microsoft 365 or cloud account investigated?
- How can the damage caused by a compromised administrator account be mitigated from a technical perspective?
- How can we check whether systems have been taken offline for technical reasons or merely as a precaution?
- How can the need for a complete reinstallation following a cyber attack be technically verified?
- How can you check whether backups have also been compromised by a cyberattack?
- How can the technically necessary recovery time following a cyber attack be determined?
- How can an insurance company determine whether measures to minimise loss were technically appropriate and necessary?
- How can it be verified retrospectively whether an incident response measure has destroyed important digital evidence?
- How can an insurance company have an incident response report from another service provider independently verified?
Business interruption and recovery
- How can the actual duration of an IT-related business interruption be technically determined?
- How can the technical recovery process following an IT incident be documented?
- How can an insurance company determine whether a cloud outage or its own business was the cause of the business interruption?
- How can an outage affecting Microsoft 365, SaaS or cloud services be technically documented as an incident?
- How can the actual duration of a cyber-related business interruption be determined?
- How can an insurance company check whether data from backups could actually be recovered?
- How can a distinction be made between direct IT damage and consequential technical damage?
- How can it be determined whether a subsequent IT failure was still a consequence of the original insured event?
- How can an insurer determine the technical component of a claimed loss of business?
- How can an insurance company arrange for an assessment to be carried out to determine when a business was technically able to resume operations?
- How can an insurance company obtain technical support to verify the plausibility of exceptionally high restoration costs?
Data loss and data recovery
- How can an insurance company have an alleged data loss verified from a technical perspective?
- How can the extent of an actual data loss be determined in a verifiable manner?
- How can we check whether existing backups will limit the reported damage?
- How can it be determined whether a backup was already unusable before the insured event occurred?
- How can an insurance company verify whether the results of data recovery or restoration provided are consistent with the alleged loss?
- How can an insurance company have a claimed loss of business-critical data technically verified?
- How can one check whether corporate data thought to have been lost is still available elsewhere?
- How can one check whether an expensive data recovery operation was technically necessary?
- How can an insurance company determine, following a total loss, what digital evidence, if any, is still available?
- How can an insurance company deal with digital evidence that is incomplete or partially destroyed?
Verification of documents for authenticity and tampering
- How can an insurance company ensure that discrepancies between a claim report and digital evidence are investigated objectively?
- How can one check whether digital files have been altered following the reported incident?
- How can an insurance company verify whether photos of damage were taken at the time of the reported incident?
- How can you check whether a photo of the damage has been edited or saved again?
- How can the authenticity of a submitted screenshot be assessed from a technical perspective?
- How can an insurance company verify whether an invoice or a digital document has been altered retrospectively?
- How can one check whether file timestamps have been deliberately altered?
- How can an insurance company verify whether system logs have been deleted or altered retrospectively?
- How can you check whether a device was reset shortly before or after the damage occurred?
- How can a reinstallation following damage be assessed from a forensic perspective?
- How can an insurance company verify whether data has been deleted following an insurance claim?
- How can it be verified whether a piece of digital evidence was created only after the damage occurred?
- How can an insurance company verify whether a chat history is complete as evidence of a claim?
- How can one check whether emails relating to a claim have been reproduced accurately and in full?
Review of expert reports and technical disputes
- How can an IT forensic report for an insurance company be drawn up in such a way that it remains comprehensible even in any subsequent civil proceedings?
- Why should an insurance company call in an independent IT forensic expert in the event of a high-value or technically complex claim?
- Why is an independent IT forensic reconstruction particularly important in the case of a cyber insurance claim worth millions?
- How can an insurance company arrange for an independent review of an existing private IT forensic report?
- How can an insurance company ensure that technical claims made by a policyholder or their expert are assessed objectively?
- How can a discrepancy between two IT forensic reports be resolved from a technical perspective?
- How can one check whether a previous expert report has failed to take key digital data sources into account?
- How can an insurance company establish whether a technical finding is reproducible?
- How can an insurance company ensure that an expert report clearly distinguishes between technical facts and assumptions?
- How can the evidential value of an individual digital artefact be objectively assessed in the context of an insurance claim?
- How can an insurance company have a technical causal link between an event and a loss investigated?
- How can an insurance company verify whether several reported claims are in fact attributable to the same IT incident?
- How can an IT forensic report present uncertainties in such a way that an insurance company can assess them correctly?
- How can an insurance company prepare a counter-report without simply looking for errors made by the other expert?
Circumstances of the incident, damage to property and reconstruction of the sequence of events
- How can an insurance company have the alleged sequence of events leading to the claim objectively verified using digital evidence?
- How can the time of an insured event be reconstructed digitally?
- How can it be verified whether a computer or Server was actually in operation at the time the damage is said to have occurred?
- How can an insurance company arrange for an investigation to determine whether a technical fault existed before or only after the reported incident?
- How can the state of an IT system be reconstructed immediately prior to a failure?
- How can an insurance company arrange for an investigation to determine which systems were actually affected by a claim?
- How can the cause of an IT incident be investigated in a way that remains open to all possible outcomes?
- How can one determine whether a fault was caused by a user action or by an automated system process?
- How can alleged damage to IT systems caused by power surges or power cuts be categorised digitally?
- How can alleged water damage to digital devices be assessed from a forensic perspective?
- How can a system’s last digital operating state be reconstructed following a fire?
- How can an insurance company arrange for an investigation to determine whether a damaged data storage device was already showing signs of failure before the damage occurred?
- How can the circumstances surrounding the loss or theft of a smartphone be digitally verified?
- How can it be verified whether a reported device is in fact the one affected by the damage?
- How can an insurance company determine the last verifiable time a damaged device was in use?
- How can an insurance company objectively verify the policyholder’s digital details against the data in its existing systems?
- How can an insurance company have location details relating to a claim verified digitally?
- How can one check whether a device was connected to a particular network at the time of the incident?
- How can an insurance company verify whether an account was actually in use at the time of the claim?
- How can it be determined whether remote access was technically relevant to the reported damage?
- How can an insurance company verify whether malware actually caused the damage reported?
- How can an insurance company arrange for a check to be carried out to determine whether an alleged data breach is technically verifiable?
- How can the plausibility of the size of an alleged digital data set be verified prior to the damage occurring?
Other questions
- Why should an insurance company such as LanCologne commission an independent IT forensic investigation into a complex claim?
- How can a suspected case of digital manipulation be investigated without prejudging the outcome?
- Why is a neutral IT forensic plausibility check particularly important for insurers in the case of disputed major claims?
- How can an insurance company formulate technical questions of evidence for subsequent civil proceedings in a meaningful way?
- How can LanCologne support an insurance company’s legal department in a technically complex dispute?
- How can an independent IT forensic expert provide technical support to an insurance company in a legal dispute?