Printable discussion aid

Cyber Claim Timeline Template

A claim timeline is most useful when it distinguishes facts, decisions, communications, approvals and financial effects. Record dates as precisely as evidence allows, and identify assumptions rather than filling gaps with certainty.

Discovery and first awareness

Who first noticed the issue, what was observed, which systems or services were involved, and when the organization first had reason to believe a covered event might exist.

Initial containment and continuity

Emergency actions, work-arounds, service interruption, safety issues, vendor involvement and decisions made before the full facts were known.

Insurer and broker notice

Date, method, recipients, claim number, acknowledgement, instructions, reservations and requested information.

Professional and vendor approvals

Counsel, forensic firms, restoration providers, negotiators, notification vendors and any consent or panel requirements.

Evidence and scope changes

New findings, affected records, root-cause developments, revised downtime, customer effects and changes to the response plan.

Cost and loss milestones

Invoices, accruals, payroll effects, lost revenue, extra expense, saved expense, customer credits, settlements and regulatory costs.

Third-party and regulatory activity

Notices, demands, claims, lawsuits, regulator communications and vendor disputes.

Proof of loss and resolution

Submitted calculations, follow-up questions, payments, partial payments, denials, settlement terms and remaining open items.

Reminder: Adapt the template to the actual policy, contracts, facts, jurisdiction and professional instructions. Do not use a generic checklist to delay notice or urgent response.