IT Forensics · Insurance
How can the actual duration of a cyber-related business interruption be determined?
There are significant differences between a complete standstill, restricted operation, emergency operation and normal operation.
Why this question is important for an insurance company
Cyber insurance claims can have significant financial consequences. This makes it all the more important to draw a clear distinction between a suspected attack, a confirmed breach and actual technical damage. Only a traceable reconstruction can provide a robust basis for further claims assessment.
Technical research question and research approach
In the event of a cyber insurance claim, the specific technical question of evidence forms the starting point of the investigation. A forensic analysis must not be aimed at either conclusively confirming the claim or providing technical grounds for refusing cover.
LanCologne therefore examines the available primary data without prejudging the outcome. Depending on the question to be answered, this may include system and security logs, endpoint artefacts, network data, authentication events, cloud and audit information, file system structures, backup information or other technically suitable sources. Which sources are actually examined depends on the specific case, their availability and their legal admissibility.
The chronological reconstruction is of particular importance. A distinction must be made between the time of discovery, initial access, compromise, possible persistence, specific acts of damage, isolation and recovery. The time an alert is triggered does not automatically mark the start of an attack. Similarly, the compromise of a system does not automatically prove that data has been leaked or that all accessible data has been encrypted.
Key findings are, as far as possible, cross-checked against several independent data sources. Automated reports and software outputs are not automatically treated as equivalent to the actual source of evidence without verification. In the case of decisive statements, reference is made to the underlying artefacts and primary data.
Even a negative finding is phrased in a nuanced manner. If, for example, no data leakage can be demonstrated, this constitutes a reliable exclusion only if the available telemetry actually permits such an exclusion. If relevant logs are missing, the limits of the conclusion must be explicitly stated.
This provides insurers with a robust technical basis: What has been proven? What is technically plausible but not proven? Which assumption has been refuted? And which questions can no longer be answered reliably on the basis of the data obtained?
How we work
Why LanCologne?
LanCologne does not aim to achieve a desired regulatory outcome. The sole determining factor is the specific technical question of evidence. A finding that confirms the policyholder’s statements carries the same weight as a verifiable contradiction. Where the data do not permit a definitive conclusion, no presumption is substituted for evidence.
Traceability and reproducibility
The key findings are explained in clear, accessible language. The technical section documents the relevant data sources, backup and investigation statuses, integrity information, time references, artefacts and validation steps. This enables another qualified IT forensic expert to carry out a technical review of the key findings.
LanCologne as an independent technical support provider for cyber insurance claims
In cases of complex cyber and business losses, LanCologne supports insurers by providing an objective, unbiased and technically transparent reconstruction. The focus is not on the software used or on achieving a desired outcome, but on the question of what can actually be substantiated on the basis of the available digital evidence.
Legal framework
Section 31 of the German Insurance Contract Act (VVG) is an important starting point for the technical assessment of claims. Under this provision, once an insured event has occurred, the insurer may request the information necessary to determine the insured event or the extent of its obligation to pay benefits. Supporting documents may be requested subject to the conditions set out therein. This does not, however, confer an unlimited right to conduct a comprehensive forensic search of all company or personal data.
In the case of measures taken following the occurrence of an insured event, Section 82 of the German Insurance Contract Act (VVG) may also be relevant. This provision concerns the prevention and mitigation of loss, as well as reasonable instructions from the insurer. Whether a specific incident response measure fulfils or breaches an obligation under the insurance contract, and what legal consequences this entails, is a legal question. From an IT forensics perspective, it is only possible to investigate what the technical situation was at the relevant time and whether a measure was reasonable from a technical point of view.
Where personal data is processed, the principles set out in Article 5 of the GDPR and the requirement for a legal basis under Article 6 of the GDPR apply in particular. The scope of the investigation and the sources of data must therefore be limited to the specific issue in question and the legally permissible purpose.
Should a legal dispute arise at a later date, the assessment of evidence remains a matter for the court. Section 286 of the German Code of Civil Procedure (ZPO) governs the free assessment of evidence; Section 287 of the ZPO contains specific provisions for determining the existence of damage and the extent thereof. A privately commissioned IT forensic investigation provides technical facts and a clear explanation of how they were arrived at, but does not replace a court ruling.
Frequently Asked Questions
LanCologne – IT Forensics for Insurance Companies
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can an insurance company check whether data from backups could actually be recovered?
- How can a distinction be made between direct IT damage and consequential technical damage?
- How can it be determined whether a subsequent IT failure was still a consequence of the original insured event?
- How can an insurer determine the technical component of a claimed loss of business?