When ransomware is confirmed in your environment, the instinct is to call the most technically capable resource available immediately. That instinct is understandable and mostly correct, with one critical exception: if you have cyber insurance, the insurance carrier must be your first call, not your second or third.
This sequencing question is not procedural. It is financial. The order in which you make your first calls during a ransomware event determines what costs your policy covers, which vendors you can engage with coverage, and whether decisions made in the first hours of the response create coverage gaps that cannot be undone.
Organizations that get this sequence wrong do not discover the consequences until weeks or months later, during the claims process, when they learn that costs they assumed were covered are not because the conditions for coverage were not met. By that point, the incident is over, the costs are incurred, and the coverage dispute is the only remaining issue.
This article explains exactly why the insurance call comes first, what happens when you call technical help first, what the insurance carrier provides that makes the first call so important, and how to build the call sequence into your response so it executes correctly under pressure.
Organizations preparing for ransomware events should also review cybersecurity services, managed IT services, and incident response services.
Why the Insurance Call Must Come First
The answer to the sequencing question is not intuitive because the insurance carrier feels like an administrative relationship and the incident response firm feels like the operational one. During a ransomware event, the feeling is reversed. The insurance carrier call is the operational call that activates the entire response infrastructure. Everything else follows from it.
Coverage Conditions Begin at Discovery
Cyber insurance policies condition coverage on actions that must be taken promptly following discovery of a covered event. The most universal of these conditions is notification: the insured must notify the carrier within a specified timeframe following discovery. That timeframe is defined in the policy and varies by carrier, but it typically ranges from 24 to 72 hours, with some policies requiring notification as soon as practicable, which courts have interpreted to mean within hours for significant incidents.
The notification clock starts at discovery, not at the point when you decide to make a claim. An organization that spends the first four hours of a ransomware event engaging technical help without notifying the carrier, then notifies the carrier, has already consumed a significant portion of its notification window and has incurred costs during a period the carrier was not informed of the incident.
The consequence of late notification ranges from partial coverage reduction to full denial of the claim depending on the policy terms and the delay involved. Most carriers do not exercise this provision aggressively for minor delays, but significant delays, and the definition of significant varies by policy and by claim amount, create legitimate coverage disputes that the carrier has contractual grounds to pursue.
Vendor Approval Requirements Are Real
Most cyber insurance policies that cover incident response costs require that the vendors engaged for that response be on the carrier’s approved panel or receive prior carrier approval. This condition exists because the carrier has negotiated rates with approved vendors and because carrier approval is the mechanism through which coverage is confirmed before costs are incurred.
Organizations that engage an incident response firm before notifying the carrier, and before confirming that the firm is on the approved panel or receiving approval for an out-of-panel engagement, incur costs that the carrier may decline to reimburse. The carrier’s position in that scenario is straightforward: you engaged a vendor without following the policy conditions for coverage, and therefore the vendor costs do not qualify for reimbursement under the policy.
This is the most common and most financially significant coverage gap that organizations discover after a ransomware event. The incident response firm they called first, often a firm they have a prior relationship with or one they found quickly under pressure, is not on the carrier’s approved panel. The response is complete, the costs are incurred, and the carrier declines coverage because the approval condition was not met.
The resolution is simple: call the carrier first, confirm which vendors are approved, and engage only approved vendors or obtain prior approval for specific exceptions. That resolution requires making the carrier call first.
The Breach Coach Coordinates the Entire Response
When you call your cyber insurance carrier’s emergency line, you are not calling a claims adjuster. You are activating a breach coach, typically an attorney with cybersecurity incident expertise whose role is to coordinate the response and ensure that every decision made during the incident is defensible, legally appropriate, and consistent with preserving coverage.
The breach coach provides functions that no technical incident response firm provides and that most organizations cannot provide internally:
Legal privilege protection for the forensic investigation is structured through the breach coach’s engagement before the forensic work begins. Investigations conducted under attorney direction as anticipated litigation produce findings that may be protected as attorney work product. Investigations conducted without that structure produce findings that are fully discoverable. This distinction matters for any incident that may result in regulatory proceedings or litigation.
Regulatory notification obligations are assessed and managed by the breach coach from the first hour. The notification timelines that apply to your industry and the data involved begin running at discovery. The breach coach identifies which obligations apply, what the timelines are, and what the notification content must include, then manages the notification process to meet those requirements. Organizations that begin this assessment hours into the incident, after technical resources have been engaged, are already behind on notification timelines in the most demanding regulatory frameworks.
The payment decision, if it becomes relevant, is managed by the breach coach in coordination with the carrier. OFAC sanctions screening of the attacker group, assessment of payment conditions under the policy, and legal review of the payment decision are all breach coach functions that occur in parallel with technical response. Organizations that reach the payment decision without the breach coach engaged are making it without the legal framework that the decision requires.
The breach coach also manages communication between the organization and the carrier, ensuring that the carrier has the information needed to process the claim and that the organization’s response decisions are documented in the way the claim process requires.
Organizations managing regulatory exposure should also review cybersecurity compliance services and business continuity planning.
What Happens When You Call Technical Help First
Understanding the specific consequences of calling technical help before the insurance carrier clarifies why the sequencing matters operationally, not just procedurally.
Uncovered Vendor Costs
If the technical resource you call first, whether an incident response firm, a managed IT provider, or a freelance IT consultant, is not on your carrier’s approved panel, their costs are not covered under the policy’s incident response coverage provisions. For a ransomware incident where incident response engagement costs range from tens of thousands to hundreds of thousands of dollars, this coverage gap is financially significant.
The out-of-panel engagement might still be covered if you subsequently obtain carrier approval for the exception. Some carriers approve out-of-panel vendors after the fact when the engagement was reasonable and the costs were appropriate. But retroactive approval is discretionary, not guaranteed, and negotiating it after costs are incurred is a weaker position than obtaining approval before engagement.
Unstructured Investigation Findings
If the forensic investigation begins before the breach coach structures the legal privilege framework, the investigation findings may not be protected as attorney work product. Those unprotected findings are fully discoverable in subsequent regulatory proceedings and litigation, including findings about the security gaps that allowed the attack to succeed and the full scope of data that was accessed.
For organizations in industries where regulatory enforcement and litigation exposure follow ransomware events, investigation findings that reveal security program failures are exactly the findings that need privilege protection. Beginning the investigation before that protection is in place eliminates the protection for whatever work occurred before the breach coach engagement.
Missed Notification Timelines
Regulatory notification timelines that are missed because the breach coach was not engaged to assess them from the first hour create independent regulatory exposure that compounds the cost of the incident. Healthcare organizations that miss the HIPAA 60-day notification deadline, financial services organizations that miss the FFIEC 36-hour requirement, and defense contractors that miss the DFARS 72-hour requirement face regulatory consequences that are independent of the technical recovery and that the breach coach engagement is specifically designed to prevent.
The breach coach’s notification assessment in the first hour of the incident sets the timeline for each applicable framework and establishes the process for meeting each deadline. Delay in that assessment is delay in the notification process, which is delay against deadlines that do not adjust for the organization’s response timeline.
Defense contractors should also review CMMC consulting services when building ransomware response procedures.
Uncoordinated Payment Decisions
Organizations that reach the payment decision without the breach coach engaged are making it without OFAC sanctions screening of the attacker group, without carrier involvement that policy conditions require, and without the legal framework that the decision’s regulatory implications demand.
A payment made to a sanctioned attacker group, made without carrier approval that the policy requires, creates simultaneous federal sanctions exposure and potential coverage denial for the payment itself. Recovering from both consequences after the fact is significantly harder than the brief delay required to make the carrier call before the payment decision is reached.

What the Technical Call Covers and When to Make It
Calling the carrier first does not mean delaying technical response. It means making the carrier call in the first minutes and making the technical call in the minutes immediately following.
The carrier’s emergency line does not take hours to activate the breach coach. It is an emergency service designed for exactly this scenario. A competent carrier emergency line activates breach coach assignment within minutes of first contact and begins the vendor approval process immediately. The total time added to technical engagement by making the carrier call first is measured in minutes, not hours.
During those minutes, your internal team is executing immediate containment actions that do not require external guidance: disconnecting infected systems from the network, disabling remote access infrastructure, establishing out-of-band communication. These actions should be underway during the carrier call and the technical engagement call that follows immediately.
The technical call sequence after the carrier call is:
Call the breach coach’s referred incident response vendor or your pre-approved retainer firm. If the breach coach has referred a specific vendor, engage that vendor. If you have a retainer agreement with a firm that is on the approved panel, engage that firm. If neither applies, ask the breach coach for an approved firm recommendation and engage immediately.
Brief the incident response firm on what your team has observed and what containment actions have been taken. The incident response firm begins remote response immediately based on this briefing, providing specific guidance on containment completion, evidence preservation, and initial investigation steps.
Continue executing containment actions under incident response guidance. Your internal team implements the specific guidance from the remote incident response firm while the breach coach coordinates the legal and regulatory response in parallel.
This sequence activates all response resources within the first 30 minutes of the incident with coverage preserved and the legal framework established.
Organizations strengthening technical response capability should also review network security monitoring and co-managed IT services.
When the Sequence Is Different
There are specific scenarios where the sequencing described above requires adjustment.
No Cyber Insurance
Organizations without cyber insurance do not have a carrier call to make. For these organizations, the technical call is the first call. Engage an incident response firm, contact legal counsel, and notify law enforcement through the FBI IC3. The absence of cyber insurance does not eliminate the legal and regulatory obligations that begin at discovery, but it does change the first call in the sequence.
For uninsured organizations, legal counsel engagement in the first hours is particularly important because there is no breach coach provided by the carrier. Identifying legal counsel with cybersecurity incident expertise before an incident, as a preparation investment, ensures that the legal response can activate immediately even without insurance coordination.
Life Safety Emergency
If the ransomware event affects systems whose compromise creates immediate life safety risk, including hospital patient care systems, industrial control systems managing physical processes, or emergency services infrastructure, life safety response takes precedence over the call sequence. Stabilize the life safety situation first, then execute the call sequence.
This exception is narrow. Most ransomware events do not create immediate life safety risk, and the urgency of the situation does not override the call sequence for incidents where life safety is not immediately at stake.
Active Exfiltration in Progress
If real-time monitoring has identified that data is actively being exfiltrated during the incident and the exfiltration can be stopped by taking a specific immediate technical action that does not require external guidance, taking that action before completing the call sequence is appropriate. Preventing additional data loss when the specific action required is clear and immediate takes priority over the minutes required to complete the first call.
This exception also is narrow. Most organizations do not have the real-time visibility into active exfiltration that would make this scenario applicable, and the specific action required to stop exfiltration in progress is not always obvious without expert guidance.
Building the Correct Sequence Into Your Response Plan
The sequencing knowledge in this article is only useful if it is embedded in your incident response plan in a way that executes correctly under the pressure of an active incident. Knowing the correct sequence intellectually is different from having it built into a plan that your team will follow automatically when the situation is most stressful.
The specific plan elements that ensure correct sequencing are:
A printed emergency contact card that lists the calls in order with contact information for each: carrier emergency line first, with policy number, then the breach coach contact if known, then the pre-approved incident response firm contact, then legal counsel, then FBI IC3. This card must be physically accessible without computer access and must be familiar to the people who will use it.
Pre-authorized containment actions that your team can execute during the carrier call and the technical call without waiting for guidance. These actions do not depend on external authorization and should be executing in parallel with the calls rather than waiting until the calls are complete.
A written statement of first call priority in the incident response plan that explicitly states the carrier call is first and explains why, so that team members under pressure do not revert to the intuitive but incorrect sequence of calling technical help first.
Regular tabletop exercises that practice the call sequence alongside the technical response actions, so that the sequence is familiar before an incident requires it. Exercises that practice only the technical response without practicing the call sequence leave the sequencing decision to real-time judgment under pressure.
Insurance policy review that confirms the conditions for coverage including notification timeline, approved vendor requirements, and breach coach engagement process, so that the people making the first call understand what they are initiating and what it provides.
Organizations improving ransomware readiness should also review ransomware protection services.
What to Say on Each Call
Knowing what to communicate on each call reduces the time spent on each call and accelerates the activation of each resource.
The Carrier Emergency Line Call
Identify yourself and your organization. Provide your policy number. State that you are calling to report a ransomware incident. Describe what you are observing: which systems are affected, what the ransom note says if visible, whether you have begun containment actions, and whether you believe customer or employee data may be involved. Request immediate breach coach assignment and ask which incident response vendors are approved for engagement.
You do not need a complete assessment before making this call. Call immediately with whatever information you have and update as more becomes available.
The Incident Response Firm Call
Identify yourself, your organization, and your location. State that you are calling under a policy with the named carrier and that the carrier has approved engagement. Describe the incident: number of affected systems, ransomware indicators observed, containment actions taken, backup availability status, and any variant identification information available. Request immediate remote response and discuss on-site mobilization if needed.
The Legal Counsel Call
If you are engaging legal counsel separate from the breach coach, provide the same incident description and add: the industries you operate in, the states where your customers or patients are located, and whether you are in a regulated industry with specific notification requirements. Legal counsel needs this information to begin the notification obligation assessment immediately.
Meet Our CEO, Matt Rosenthal
With more than 30 years of experience in business and technology leadership, Matt Rosenthal has guided organizations across healthcare, finance, legal, manufacturing, and defense through ransomware events where sequencing decisions made in the first minutes had financial and legal consequences that extended through the entire incident and beyond. As President and CEO of Mindcore Technologies, Matt leads a team that helps organizations build the incident response infrastructure and pre-established relationships that make correct sequencing automatic rather than dependent on real-time judgment under pressure.
Matt’s approach to incident response preparation consistently emphasizes that the decisions made before an incident, including establishing the correct call sequence in a plan that executes automatically, determine outcomes as much as the technical response capability that follows.
Frequently Asked Questions
What if the carrier emergency line does not answer immediately?
Document every attempt to reach the carrier including timestamps, call times, and any voicemails left. Continue attempting to reach the carrier while beginning the technical engagement in parallel. Most carriers with legitimate 24/7 emergency lines answer promptly, but if reaching the primary emergency contact fails, try the carrier’s general customer service line, the agent or broker who placed the policy, and any alternative contact information in the policy documents. Demonstrating good-faith notification efforts through documented attempts protects coverage even when initial contact is delayed by carrier availability issues.
Can we call the incident response firm and the carrier simultaneously?
Yes, if you have sufficient personnel. Assign one person to the carrier call and a separate person to the incident response firm call simultaneously, with both calls on personal mobile phones using the out-of-band communication channel. The risk of simultaneous calls is that the incident response firm engagement precedes confirmed carrier approval of that firm. Mitigate this by engaging only your pre-approved retainer firm or by immediately confirming approval status in the parallel call with the carrier.
What if our pre-established incident response firm is not on the carrier’s approved panel?
Disclose this to the carrier immediately and request approval for an exception. Some carriers approve specific out-of-panel vendors when the customer has a pre-established relationship and the engagement is otherwise appropriate. If the carrier declines the exception, you face a choice between engaging the approved panel vendor for covered costs and your preferred firm at your own expense. Engaging both in defined roles, with the approved vendor handling the work for which coverage is sought and the preferred firm advising in a role that does not generate covered costs, is a practical resolution in some cases. Legal counsel and the breach coach should advise on this structure.
How does the call sequence change for a weekend or holiday incident?
The call sequence does not change, but the logistics change. Carrier emergency lines are 24/7. Legal counsel emergency contacts must be established before an incident because reaching legal counsel through standard office channels on weekends and holidays is not reliable. Incident response firm emergency lines are 24/7 for firms with genuine emergency capability. The preparedness investment of establishing these contacts before they are needed, including personal mobile numbers for legal counsel and confirmed 24/7 availability from the incident response firm, eliminates the logistics difference between business hours and off-hours incidents.
Should we document the calls as we make them?
Yes. Document each call with the time initiated, the person reached, the information conveyed, and any commitments made by the responding resource. This documentation supports the insurance claim, demonstrates timely notification, and provides the record that regulatory compliance requires. Assign someone to documentation from the first minute of the response, separate from the people making calls and executing containment actions.
Establish the Sequence Before You Need It
The organizations that execute the correct call sequence during an active ransomware event are the ones that established it before the incident required it. Under the pressure of a live ransomware event, the intuitive response is to call whoever feels most immediately useful. Overriding that intuition requires having the correct sequence embedded in a plan that your team has practiced and that is physically accessible when production systems are not.
The preparation investments that ensure correct sequencing, a printed emergency contact card in the correct order, pre-approved vendor relationships, a practiced incident response plan, and a team that has executed the sequence in tabletop exercises, cost a fraction of the coverage gaps they prevent.
Mindcore’s cybersecurity services and managed IT services help organizations across healthcare, finance, legal, manufacturing, and defense build the incident response infrastructure and pre-established relationships that make the correct call sequence automatic rather than dependent on judgment under pressure. If your organization does not have the emergency contact sequence established, printed, and practiced before an incident requires it, contact Mindcore to build that infrastructure before the incident that makes it urgent.
Source content adapted from uploaded file. :contentReference[oaicite:0]{index=0}

