Skip to main content
Category: Claims Handling

First Notice of Loss

Also known as: FNOL, First Notification of Loss, Notice of Loss
Simply put

First Notice of Loss (FNOL) is the first official report you make to your insurance provider after something happens that may lead to a claim, such as damage, loss, or theft of a covered item. It is the initial step that lets the insurer know an incident has occurred and typically starts the claims process. Whether the reported event is ultimately covered depends on the terms of the specific policy.

Formal definition

FNOL is the formal initial report made by a policyholder (or their representative) to an insurer following an incident affecting a covered asset or interest, and it generally triggers the opening of a claim file and the start of a claims investigation. In practice the FNOL captures preliminary details of the loss, damage, or theft; it initiates but does not by itself determine coverage, which remains subject to the specific policy wording, conditions, exclusions, and any applicable notice provisions. The FNOL is a procedural step in the claims lifecycle and is distinct from the insurer's subsequent coverage determination and adjustment of the loss.

Why it matters

In cyber insurance, the First Notice of Loss is the moment the clock starts on the claims process and, often, on the insurer's ability to help control the loss. Many cyber policies contain strict notice provisions and conditions precedent to coverage, meaning that late or improperly directed notification can jeopardize a claim regardless of whether the underlying event would otherwise have been covered. Because a cyber incident can escalate rapidly, unlike a static property loss, the timing and accuracy of the FNOL can have outsized practical consequences for both the insured and the insurer.

FNOL also matters because it is frequently the trigger that unlocks the insurer's incident response resources. Many cyber policies operate through a panel of pre-approved vendors, breach counsel, forensic investigators, negotiators, and public relations advisers, and using those resources may be a condition of coverage for the associated costs. Reporting through the FNOL channel is often what mobilizes that support and preserves the insured's ability to recover first-party costs such as forensics and, where applicable, business interruption. Acting before notice, for example retaining an off-panel vendor without insurer consent, can create disputes over whether those costs are reimbursable.

It is important to keep the FNOL in its correct place in the process: it initiates but does not decide coverage. Filing a First Notice of Loss does not guarantee that the reported event falls within the policy, nor does it substitute for the organization's own resilience measures. Whether the loss is ultimately paid depends on the specific policy wording, exclusions, and conditions, and the FNOL is a procedural step distinct from the insurer's subsequent coverage determination and adjustment.

Who it's relevant to

Risk Managers
Risk managers should ensure their organizations know exactly how and to whom to submit an FNOL, and within what timeframe, because notice provisions are often conditions precedent to coverage. Building the FNOL step into the incident response plan helps avoid the risk that a covered loss is disputed on procedural grounds.
Insurance Brokers
Brokers frequently act as the conduit for a client's First Notice of Loss and advise on when and how to report. Their role includes clarifying the policy's notice requirements and helping the client engage insurer-approved resources so that first-party costs remain within scope, while being clear that the FNOL does not confirm coverage.
Underwriters and Claims Professionals
For insurers, the FNOL opens the claim file and starts the investigation. It provides the preliminary information used to assign resources and begin assessing the loss, but the coverage determination and adjustment are separate, later steps governed by the policy terms.
CISOs and Incident Response Teams
Security leaders need to understand that reporting an incident to the insurer via FNOL is often what mobilizes panel breach counsel and forensic support, and that engaging off-panel vendors without consent may affect reimbursement. Coordinating the technical response with the insurance notification process is important, though the FNOL is an insurance procedure and not a substitute for the organization's own containment and recovery activities.
Legal and Compliance Professionals
Counsel should be aware that insurance FNOL obligations are distinct from any statutory or regulatory breach-notification duties, which run on their own timelines and to different recipients. Both may be triggered by the same incident, and satisfying one does not satisfy the other; the specific policy wording and applicable regulatory regime govern each.

Inside FNOL

Insured and Policy Identification
Details identifying the policyholder and the applicable policy number, so the insurer can confirm coverage is in force and locate the relevant terms, endorsements, and limits that will govern the claim.
Description of the Incident
An account of what occurred (for example, a suspected network intrusion, ransomware event, or data exposure), including the nature of the event and how it was discovered. At the FNOL stage this is often preliminary and may be updated as investigation proceeds.
Date and Time of Discovery
When the insured first became aware of the event or circumstance. This can be significant because many cyber policies are written on a claims-made or claims-made-and-reported basis and contain conditions about timely notice, subject to the specific wording.
Known or Potential Impact
An initial indication of affected systems, data, or operations, and whether the event may give rise to first-party losses (such as business interruption or data restoration) or third-party liability (such as privacy claims or regulatory action). This is typically provisional at first notice.
Contact and Reporting Party Information
The name and contact details of the person reporting on behalf of the insured, enabling the insurer, claims handler, or panel breach coach to follow up and coordinate next steps.
Immediate Actions Taken
Any containment, preservation, or response measures already undertaken. This helps the insurer understand the current posture and coordinate approved vendors, though engaging vendors before insurer consent may affect coverage under some policy conditions.

Common questions

Answers to the questions practitioners most commonly ask about FNOL.

Does submitting a First Notice of Loss mean the insurer has accepted my claim?
No. First Notice of Loss (FNOL) is the initial notification that a loss or potential claim has occurred or may occur; it opens the claim process but does not by itself constitute acceptance of coverage. Whether the loss is ultimately covered depends on the specific policy wording, applicable exclusions, conditions precedent, and the facts developed during the insurer's investigation. Treat FNOL as the start of a determination process, not a coverage confirmation.
Is First Notice of Loss the same thing as filing a formal proof of loss or a detailed claim?
No. FNOL is typically the preliminary notification, often communicated with limited information soon after an event is discovered. A formal proof of loss or a fully documented claim usually comes later and generally requires more detailed substantiation of the amounts and circumstances involved. Many policies treat these as distinct steps with different timing and content requirements, so review the specific wording to understand what each stage demands.
When should FNOL be submitted after a suspected cyber incident?
Many cyber policies contain notice provisions that call for reporting as soon as practicable, and some are written on a claims-made-and-reported basis where timing can affect coverage. Because late notice can, subject to the specific wording and jurisdiction, jeopardize a claim, organizations often notify at the point of a reasonable suspicion rather than waiting for full confirmation. Consult your broker and the policy's notice conditions to understand the applicable timeframe and any conditions precedent.
Who within an organization should be responsible for triggering FNOL?
Responsibility is commonly assigned to a designated role or team, such as risk management, legal, or a named incident coordinator, and reflected in the incident response and crisis management plans. Because a cyber event may surface first through security operations, it is useful to define in advance how a technical detection escalates to the person authorized to notify the insurer, so that notice conditions are met without confusion during an incident.
What information is typically expected in a First Notice of Loss?
FNOL generally captures the essentials known at the time: the policy or insured details, the date and nature of the event or circumstance, an initial description of what is known, and relevant contact points. Because early information is often incomplete, insurers commonly expect that details will be supplemented as the investigation proceeds. Check the policy and any insurer guidance for the specific notice content and method required, as these vary across forms.
How does FNOL interact with an insurer's incident response resources or panel providers?
In many cyber policies, providing notice is the step that enables access to panel or approved vendors such as breach counsel and forensic providers, and some wordings require using approved vendors or obtaining consent before incurring certain costs. Engaging providers before notifying, or outside the approved panel, may affect whether those costs are reimbursed, subject to the specific wording. Coordinate FNOL timing with your response actions so that resource access and coverage conditions align.

Common misconceptions

Submitting a First Notice of Loss guarantees the claim will be paid.
FNOL initiates the claims process; it is not an admission or determination of coverage. Whether any loss is ultimately covered depends on policy wording, applicable exclusions (such as war or failure-to-maintain-standards exclusions), conditions precedent, sublimits, retentions, and the specific facts, subject to the insurer's investigation.
FNOL only matters for the insured's own first-party losses.
First notice can be relevant to both first-party coverage (such as business interruption, data restoration, and cyber extortion) and third-party coverage (such as privacy liability and regulatory defense). A single event may trigger notice obligations across multiple coverage parts, and the notice provisions can differ by part and by policy.
There is no rush to file, so notice can wait until the full impact is understood.
Many cyber policies contain notice conditions and, where written on a claims-made-and-reported basis, reporting deadlines; late or non-compliant notice may jeopardize coverage depending on the wording and jurisdiction. FNOL is generally intended to be prompt and preliminary rather than complete.

Best practices

Review your policy's specific notice provisions in advance, including any deadlines, the designated notice recipient, and whether the policy is claims-made-and-reported, so reporting obligations are understood before an incident occurs.
Report promptly upon discovery even when facts are incomplete, and treat FNOL as a preliminary notice that can be supplemented as investigation reveals more.
Confirm the insurer's requirements for engaging incident response vendors (such as breach coaches or forensics firms) before retaining them, because pre-consent engagement may affect coverage under some policy conditions.
Capture and preserve key details at first notice, date and time of discovery, description of the event, affected systems or data, and actions already taken, to support both the claim and any later investigation.
Assess whether the event may implicate both first-party and third-party coverage parts and provide notice under each applicable part rather than assuming a single notice suffices.
Coordinate FNOL within your broader incident response and crisis management process, recognizing that filing notice transfers a claim to the insurer but does not itself contain the incident or restore operations.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps