After a cyberattack, victims must follow strict timelines and collect specific documents to qualify for insurance compensation. According to the insurance code, a formal complaint must be submitted within 72 hours of discovering the incident to maintain eligibility for cyber insurance benefits, as outlined in article L12-10-1. If personal data was affected, the CNIL (National Commission on Informatics and Liberty) must be informed within 72 hours, as required by the General Data Protection Regulation (GDPR), specifically article 33. Companies subject to the NIS2 directive must alert the ANSSI (National Cybersecurity Agency) within 24 hours, followed by a more detailed report within 72 hours and a final report within a month. These requirements must be handled simultaneously once the technical team evaluates the attack's impact. Once a complaint is submitted, the insurer usually requires an expert evaluation before any payment is made. This process includes gathering documents such as the stamped complaint receipt, incident reports, connection logs, screenshots of unauthorized access, and evidence of security measures in place at the time of the insurance contract, such as multi-factor authentication, tested backups, and recent system updates. For claims related to lost revenue, insurers may request data comparing current revenue to the same period in the past, records of canceled orders, and invoices from service providers involved in fixing the breach. Before incurring any expenses, victims are often advised to contact a crisis hotline provided by their insurance policy. The insurer may then assign an incident response provider, typically a PRIS provider certified by the ANSSI, to prepare a final technical report. This report is usually delivered several weeks after the incident is declared, and during that time, the affected company must cover the costs of any production stoppage using its own funds. Reimbursements are then negotiated based on the report, item by item. Insurers may deny compensation for several reasons, such as failure to meet security measures declared when the policy was signed, intentional false information on the subscription form, or non-compliance with specific terms in the insurance contract. Some insurers may only cover the cost of restoring systems to their original state and not fund improvements to the attacked system. Additionally, some policies use deductibles based on the number of days of production stoppage rather than in euros, which may reduce the compensation for incidents resolved quickly. Insurers are increasingly excluding claims involving attacks by state actors or those exploiting known vulnerabilities that were not patched. Paying a ransom without the insurer's prior written approval may also lead to denial of reimbursement. To secure compensation, victims are advised to file a complaint within the 72-hour window, even if all details are not yet clear. They should avoid paying ransoms without the insurer's written approval and retain all technical evidence from the earliest moments of the attack, including connection logs, screenshots, and isolated backups. Verifying the security measures declared in the insurance contract is essential, as insurers may use false declarations as a reason to deny claims. It is recommended to review the subscription questionnaire annually with an RSSI (Information System Security Officer) or IT service provider and update it if the information system has changed. Engaging a qualified PRIS provider certified by the ANSSI can help with technical expertise and negotiations. Notifying a broker early can speed up the process of alerting the insurer and accessing a crisis hotline. Before signing, it's important to review clauses that exclude state-sponsored attacks and the limits on reimbursement for lost revenue.