ITC Vegas 2026We're on the floor at Mandalay Bay, Sep 29 - Oct 1Meet us there
Use Cases / Cyber Claims

Cyber claims automation, with investigation-grade evidence built in

Cyber claim volume rose almost 40% in 2024 to nearly 50,000 reported claims, and nearly three in four of the cyber claims that closed that year closed without a payment. Forensics reports, sublimits, waiting periods, and business interruption proof of loss are still worked by hand. Hesper AI handles the whole file in hours.

Investigation in progress
CYB-2026-004412
Ransomware + dependent BI · $1.2M claimed
Running
Progress20%
Investigation phases
Notice & forensics report ingest
Coverage, sublimit & endorsement mapping
Log and telemetry timeline rebuild
BI and extra expense quantification
Payee & funds transfer verification
Evidence gathered2 items
PolicyCyber form active - $250K BI sublimit, 8-hour waiting period
DFIRIR report: initial access 19 days before encryption
Risk score
Low signal
28
/ 100

In short

Hesper AI's agents pick up a cyber claim at first notice, read the incident response and forensics reports, test the loss against sublimits, waiting periods, and endorsements, and build the business interruption proof of loss from the insured's own records. Clean claims resolve straight through; questionable ones get an investigation-grade workup.

Last updated

01 · Where cyber claims stall

The four hard problems of a cyber claim

A cyber file is rarely held up by the cyber event. It is held up by measuring the outage, reading the endorsements, working around evidence the insured no longer holds, and testing whether the loss is what it is claimed to be. Hesper works all four in parallel. This page covers the cyber-triggered file; interruption losses triggered by a fire or another physical peril are covered on the business interruption claims page.

!

Business interruption proof of loss

The insured wants the outage paid; the file has no agreed method for measuring it. Hesper AI reconstructs the outage window from the forensics timeline, models covered income loss against historic revenue, margin, and seasonality, and separates extra expense from costs that would have been incurred anyway - with the workings and source documents attached.

How Hesper detects it
Outage window rebuildRevenue and margin modellingExtra expense splitDependent BI tracing

Sublimits, waiting periods, and exclusions

Cyber coverage lives in the endorsements. Hesper AI reads the full form, maps each head of loss to the sublimit that governs it, tests the outage against the waiting period, checks how the social engineering endorsement meets the funds transfer loss, and flags where a war, cyber operation, or infrastructure exclusion is in play on the facts.

How Hesper detects it
Endorsement analysisSublimit mappingWaiting period testCited coverage position

The evidence the insured cannot produce

Retention windows are short and ransomware destroys telemetry, so the logs that would settle causation are often gone. Hesper AI records exactly what is missing and for which dates, then corroborates from mail flow, backup and restore jobs, vendor status pages, ticketing, and payment records, and marks each finding as proven, inferred, or unproven.

How Hesper detects it
Evidence gap mappingMail flow reconstructionRestore job correlationThird-party corroboration
?

Exaggerated loss and pre-existing compromise

Fraud on a cyber claim looks like an inflated income loss, a vendor invoice that was edited, or an intrusion that started before the policy did. Hesper AI tests claimed losses against filed financials, checks invoices and screenshots for tampering and synthetic generation, and compares the forensics timeline against the inception date.

How Hesper detects it
Financial benchmarkingInvoice forensicsSynthetic media detectionInception-date timeline test
02 · Timeline compression

Manual workflow vs. Hesper

Cyber cycle time is dominated by waiting: for the forensics report, for the accountant, for the insured to find records that may not exist. Every one of those waits compresses.

Investigation phase
Manual workflow
Hesper AI
Incident response vendor triage
Panel assignment and scoping, 1-3 days
Matched on intake
Forensics report review
Adjuster read-through, 4-8 hrs per report
Automated
Coverage, sublimit and endorsement read
Policy analysis, 1-2 days
Cited on intake
BI proof of loss assembly
Forensic accountant engagement, 30-60 days
Auto-drafted
Funds transfer recovery push
Adjuster follow-up, 3-5 days
Automated
Total time
30-90 days
hours
03 · Handling flow

How Hesper AI handles a cyber claim

Every cyber claim runs the same structured path from notice to resolution. Phases run in parallel where dependencies allow, and every fact written to the file carries a citation to the document it came from.

01

Notice intake and incident scoping

The breach notification, the incident response engagement letter, the ransom note or fraudulent payment instruction, and the insured's early correspondence are ingested together. The agents build the first version of the incident narrative and flag the heads of loss the claim will turn on.

Notice extractionHead-of-loss flaggingPanel vendor matchSeverity scoring at intake
02

Forensics and evidence reconstruction

DFIR reports, containment logs, EDR exports, and mail flow records are read and reconciled into a single timeline: initial access, dwell time, first impact, exfiltration, restoration. Where the telemetry is missing, the gap is recorded by date and corroborated from what survives.

DFIR report parsingTimeline reconstructionEvidence gap mappingProven vs inferred labelling
03

Coverage, sublimit, and endorsement analysis

The full cyber form and every endorsement are analyzed against the reconstructed facts. Each head of loss is mapped to its sublimit and retention, the waiting period is tested against the real outage window, and war, cyber operation, and widespread infrastructure wordings are assessed on the facts rather than on the label.

Endorsement analysisSublimit and retention mappingWaiting period testDrafted ROR letter
04

Loss quantification and proof of loss

Response costs, extra expense, and income loss are quantified separately. Business interruption is modelled against the insured's own revenue and margin history; dependent business interruption is traced to the named vendor's outage record. Vendor invoices are checked for tampering before they are allowed into the loss.

Income loss modellingExtra expense splitDependent BI tracingInvoice forensics
05

Fraud screening, recovery, and resolution

Every file is screened for an exaggerated loss, an edited invoice, and a compromise that predates inception, and for recovery against a negligent vendor, a bank, or a payment processor on funds transfer fraud. The output is an evidence package with citations, a coverage position, and drafted correspondence.

Pre-existing compromise testPayee and FTF verificationSubrogation screeningCited evidence package
04 · By the numbers
$0B

US cyber insurance direct written premium in 2024

The first ever annual decline, down 7% from $9.84B in 2023

Source: NAIC Report on the Cybersecurity Insurance Market
~0K

Cyber claims reported to US insurers in 2024

Claim count rose almost 40% year over year

Source: NAIC Report on the Cybersecurity Insurance Market
0%

Of US cyber claims closed in 2024 closed without a payment

28,555 closed without payment against 9,941 closed with payment

Source: NAIC Report on the Cybersecurity Insurance Market
$0B

Reported US losses to business email compromise in 2025

Across 24,768 complaints filed with the FBI

Source: FBI IC3 2025 Annual Report
05 · Common questions

Cyber claims automation, answered

How does AI claims automation handle a cyber claim from first notice to resolution?

The agents take the notice, extract the loss facts from the breach notification, the incident response engagement, and the insured's own correspondence, verify coverage against the cyber form and its endorsements, quantify the business interruption and response costs, and recommend a reserve. Straightforward claims resolve without a manual touch. Coverage and payment authority stay with your adjuster, which is why MGAs running a delegated authority book use it the same way a carrier does.

Can AI read an incident response and digital forensics report and pull the claim facts out of it?

Yes. The agents read the full DFIR report, the containment log, and the vendor invoices, and lift out the facts a claim turns on: initial access vector, dwell time, date and time of first impact, systems affected, whether data was exfiltrated, and the restoration milestones. Each fact is written back to the file with a citation to the page it came from, so an adjuster checks the record instead of rebuilding it.

How do you build a business interruption proof of loss when the outage is a cyber event?

The agents reconstruct the outage window from the forensics timeline, then model the loss against the insured's historic revenue, margin, and seasonality, separating covered income loss from extra expense and from costs that would have been incurred anyway. Dependent business interruption is traced to the named vendor's own outage record. The draft proof of loss ships with the workings and the source documents attached.

What happens when the insured cannot produce the logs?

This is the normal case, not the exception, because retention windows are short and ransomware often destroys the telemetry. The agents document exactly which evidence is missing and for which dates, then corroborate from what does survive: mail flow records, backup and restore jobs, vendor status pages, ticketing systems, bank and payment records, and third-party threat intelligence on the named variant. The file states what is proven, what is inferred, and what is unproven.

Can Hesper apply cyber sublimits, waiting periods, and war or infrastructure exclusions?

Yes. The agents read the full form and every endorsement, then write a cited coverage position: which sublimit each head of loss falls under, whether the outage cleared the waiting period, how the social engineering endorsement interacts with the funds transfer fraud loss, and whether a war, cyber operation, or widespread infrastructure exclusion is in play on the facts. Reservation of rights and coverage letters are drafted for your signature.

Can AI catch an exaggerated cyber loss or a pre-existing compromise?

Fraud detection is built into Hesper rather than licensed from another vendor. The agents test the claimed income loss against filed financials and prior periods, check invoices and screenshots for tampering and synthetic generation, and compare the forensics timeline with the policy inception date to surface a compromise that predates the cover. The finding and the denial decision stay with your team.

See Hesper handle your cyber claims

We'll run a sample file on your real cyber claims and show you the coverage position, the proof of loss, and the evidence package it produces. Pricing is scoped to your book, so we'll talk it through on the call.

Request a demo →Explore other use cases