Cyber claims automation, with investigation-grade evidence built in
Cyber claim volume rose almost 40% in 2024 to nearly 50,000 reported claims, and nearly three in four of the cyber claims that closed that year closed without a payment. Forensics reports, sublimits, waiting periods, and business interruption proof of loss are still worked by hand. Hesper AI handles the whole file in hours.
In short
Hesper AI's agents pick up a cyber claim at first notice, read the incident response and forensics reports, test the loss against sublimits, waiting periods, and endorsements, and build the business interruption proof of loss from the insured's own records. Clean claims resolve straight through; questionable ones get an investigation-grade workup.
Last updated
The four hard problems of a cyber claim
A cyber file is rarely held up by the cyber event. It is held up by measuring the outage, reading the endorsements, working around evidence the insured no longer holds, and testing whether the loss is what it is claimed to be. Hesper works all four in parallel. This page covers the cyber-triggered file; interruption losses triggered by a fire or another physical peril are covered on the business interruption claims page.
Business interruption proof of loss
The insured wants the outage paid; the file has no agreed method for measuring it. Hesper AI reconstructs the outage window from the forensics timeline, models covered income loss against historic revenue, margin, and seasonality, and separates extra expense from costs that would have been incurred anyway - with the workings and source documents attached.
Sublimits, waiting periods, and exclusions
Cyber coverage lives in the endorsements. Hesper AI reads the full form, maps each head of loss to the sublimit that governs it, tests the outage against the waiting period, checks how the social engineering endorsement meets the funds transfer loss, and flags where a war, cyber operation, or infrastructure exclusion is in play on the facts.
The evidence the insured cannot produce
Retention windows are short and ransomware destroys telemetry, so the logs that would settle causation are often gone. Hesper AI records exactly what is missing and for which dates, then corroborates from mail flow, backup and restore jobs, vendor status pages, ticketing, and payment records, and marks each finding as proven, inferred, or unproven.
Exaggerated loss and pre-existing compromise
Fraud on a cyber claim looks like an inflated income loss, a vendor invoice that was edited, or an intrusion that started before the policy did. Hesper AI tests claimed losses against filed financials, checks invoices and screenshots for tampering and synthetic generation, and compares the forensics timeline against the inception date.
Manual workflow vs. Hesper
Cyber cycle time is dominated by waiting: for the forensics report, for the accountant, for the insured to find records that may not exist. Every one of those waits compresses.
How Hesper AI handles a cyber claim
Every cyber claim runs the same structured path from notice to resolution. Phases run in parallel where dependencies allow, and every fact written to the file carries a citation to the document it came from.
Notice intake and incident scoping
The breach notification, the incident response engagement letter, the ransom note or fraudulent payment instruction, and the insured's early correspondence are ingested together. The agents build the first version of the incident narrative and flag the heads of loss the claim will turn on.
Forensics and evidence reconstruction
DFIR reports, containment logs, EDR exports, and mail flow records are read and reconciled into a single timeline: initial access, dwell time, first impact, exfiltration, restoration. Where the telemetry is missing, the gap is recorded by date and corroborated from what survives.
Coverage, sublimit, and endorsement analysis
The full cyber form and every endorsement are analyzed against the reconstructed facts. Each head of loss is mapped to its sublimit and retention, the waiting period is tested against the real outage window, and war, cyber operation, and widespread infrastructure wordings are assessed on the facts rather than on the label.
Loss quantification and proof of loss
Response costs, extra expense, and income loss are quantified separately. Business interruption is modelled against the insured's own revenue and margin history; dependent business interruption is traced to the named vendor's outage record. Vendor invoices are checked for tampering before they are allowed into the loss.
Fraud screening, recovery, and resolution
Every file is screened for an exaggerated loss, an edited invoice, and a compromise that predates inception, and for recovery against a negligent vendor, a bank, or a payment processor on funds transfer fraud. The output is an evidence package with citations, a coverage position, and drafted correspondence.
US cyber insurance direct written premium in 2024
The first ever annual decline, down 7% from $9.84B in 2023
Source: NAIC Report on the Cybersecurity Insurance MarketCyber claims reported to US insurers in 2024
Claim count rose almost 40% year over year
Source: NAIC Report on the Cybersecurity Insurance MarketOf US cyber claims closed in 2024 closed without a payment
28,555 closed without payment against 9,941 closed with payment
Source: NAIC Report on the Cybersecurity Insurance MarketReported US losses to business email compromise in 2025
Across 24,768 complaints filed with the FBI
Source: FBI IC3 2025 Annual ReportCyber claims automation, answered
How does AI claims automation handle a cyber claim from first notice to resolution?
The agents take the notice, extract the loss facts from the breach notification, the incident response engagement, and the insured's own correspondence, verify coverage against the cyber form and its endorsements, quantify the business interruption and response costs, and recommend a reserve. Straightforward claims resolve without a manual touch. Coverage and payment authority stay with your adjuster, which is why MGAs running a delegated authority book use it the same way a carrier does.
Can AI read an incident response and digital forensics report and pull the claim facts out of it?
Yes. The agents read the full DFIR report, the containment log, and the vendor invoices, and lift out the facts a claim turns on: initial access vector, dwell time, date and time of first impact, systems affected, whether data was exfiltrated, and the restoration milestones. Each fact is written back to the file with a citation to the page it came from, so an adjuster checks the record instead of rebuilding it.
How do you build a business interruption proof of loss when the outage is a cyber event?
The agents reconstruct the outage window from the forensics timeline, then model the loss against the insured's historic revenue, margin, and seasonality, separating covered income loss from extra expense and from costs that would have been incurred anyway. Dependent business interruption is traced to the named vendor's own outage record. The draft proof of loss ships with the workings and the source documents attached.
What happens when the insured cannot produce the logs?
This is the normal case, not the exception, because retention windows are short and ransomware often destroys the telemetry. The agents document exactly which evidence is missing and for which dates, then corroborate from what does survive: mail flow records, backup and restore jobs, vendor status pages, ticketing systems, bank and payment records, and third-party threat intelligence on the named variant. The file states what is proven, what is inferred, and what is unproven.
Can Hesper apply cyber sublimits, waiting periods, and war or infrastructure exclusions?
Yes. The agents read the full form and every endorsement, then write a cited coverage position: which sublimit each head of loss falls under, whether the outage cleared the waiting period, how the social engineering endorsement interacts with the funds transfer fraud loss, and whether a war, cyber operation, or widespread infrastructure exclusion is in play on the facts. Reservation of rights and coverage letters are drafted for your signature.
Can AI catch an exaggerated cyber loss or a pre-existing compromise?
Fraud detection is built into Hesper rather than licensed from another vendor. The agents test the claimed income loss against filed financials and prior periods, check invoices and screenshots for tampering and synthetic generation, and compare the forensics timeline with the policy inception date to surface a compromise that predates the cover. The finding and the denial decision stay with your team.
Go deeper on cyber claims handling
Research, technical deep-dives, and playbooks from the Hesper AI team.
See Hesper handle your cyber claims
We'll run a sample file on your real cyber claims and show you the coverage position, the proof of loss, and the evidence package it produces. Pricing is scoped to your book, so we'll talk it through on the call.