Skip to main content
Category: Claims Handling

Loss Adjustment

Also known as: Claims Adjustment, Loss Adjusting
Simply put

Loss adjustment is the process an insurance company uses to review a claim, confirm what happened, and decide how much (if anything) it should pay. It covers investigating the cause of a loss, verifying the details, and settling or defending the claim. The costs of doing this work are incurred even when a claim turns out to be invalid.

Formal definition

Loss adjustment refers to the activities by which an insurer investigates, evaluates, verifies, determines coverage for, negotiates, settles, or defends a submitted claim. The associated costs are known as loss adjustment expenses (LAE): the costs of administering, determining coverage for, settling, or defending claims, incurred even if the claim is ultimately determined to be invalid. In a cyber insurance context, loss adjustment applies to both first-party elements (for example, verifying business interruption, data restoration, or extortion losses claimed by the insured) and third-party elements (for example, evaluating and defending privacy liability or regulatory claims brought against the insured), though the specific process and what qualifies as a covered loss depend on the policy wording, endorsements, exclusions, and applicable jurisdiction. LAE is distinct from the indemnity payment for the loss itself; whether particular adjustment costs are treated as allocated (attributable to a specific claim) or unallocated varies by insurer accounting practice and is not addressed by the evidence here.

Why it matters

Loss adjustment sits at the point where a cyber insurance policy's promise is tested against a specific event. Whether a claimed business interruption, data restoration cost, extortion payment, or third-party privacy liability is ultimately covered depends not on the loss occurring but on how the insurer investigates the facts, applies the policy wording, and evaluates exclusions and conditions. For insureds, understanding that this process exists helps set realistic expectations: a submitted claim is reviewed and verified, not automatically paid, and the outcome turns on the specific terms of the policy and the applicable jurisdiction.

A critical and often underappreciated point is that loss adjustment expenses (LAE) are incurred even when a claim is ultimately determined to be invalid. The insurer bears the cost of administering, determining coverage for, settling, or defending a claim regardless of whether it pays indemnity. This has practical consequences for both sides: insurers price and reserve for these costs as a distinct element from the loss payment itself, and disputes over coverage can generate significant adjustment activity before any settlement or denial is reached.

Because cyber claims frequently involve both first-party and third-party elements, loss adjustment in this context can be procedurally complex. Verifying a first-party business interruption or data restoration loss involves different evidence and expertise than evaluating and defending a third-party privacy liability or regulatory claim brought against the insured. Treating these as a single undifferentiated process can obscure where coverage questions actually arise and how the adjustment effort is likely to unfold.

Who it's relevant to

Risk managers and insureds
Risk managers should understand that submitting a claim initiates an investigation and verification process, not an automatic payment. Whether a first-party loss such as business interruption or data restoration is reimbursed, or a third-party claim is defended, depends on the specific policy wording, endorsements, and exclusions. Anticipating the evidence an insurer will seek to verify a claim can help an organization prepare documentation in advance.
Underwriters and insurers
Underwriters and insurers must account for loss adjustment expenses as a category distinct from indemnity, recognizing that these costs are incurred even when a claim is ultimately determined to be invalid. How adjustment costs are classified as allocated or unallocated is a matter of the insurer's own accounting practice and affects reserving and pricing.
Insurance brokers
Brokers advising clients should be able to explain how the adjustment process differs for first-party and third-party cyber elements, and that coverage determinations are conditional on policy terms, exclusions, and jurisdiction. Setting client expectations about verification and the possibility of coverage disputes is part of managing the claims relationship.
Legal and compliance professionals
Legal and compliance teams may become involved where loss adjustment turns on coverage questions, contested facts, or the defense of third-party privacy or regulatory claims. Because outcomes depend on policy wording and applicable jurisdiction, and because defense costs form part of loss adjustment expenses, early legal input can be relevant to how a disputed claim is handled.

Inside Loss Adjustment

Claim Investigation and Validation
The process by which the insurer, often through an adjuster or forensic specialist, examines whether a reported event falls within the policy's coverage triggers and is not barred by exclusions or conditions. In cyber claims this typically involves reviewing the incident timeline, affected systems, and whether conditions precedent (such as timely notice) were met.
Quantification of Loss
The measurement of the financial impact being claimed. For first-party cyber coverages this can include data restoration costs, cyber extortion payments, and business interruption loss calculated against the policy's waiting period and indemnity period; for third-party coverages it can involve defense costs and liability amounts. Whether any element is payable is subject to the specific policy wording, sublimits, and retentions.
Application of Retentions, Sublimits, and Waiting Periods
The adjustment applies the insured's self-insured retention, any coverage-specific sublimits, and, for business interruption, the waiting period (a time-based deductible) before indemnity begins. These are policy terms and should not be confused with resilience metrics such as RTO or RPO.
Coverage Determination Against Exclusions and Conditions
An assessment of whether exclusions (such as war, infrastructure, or failure-to-maintain-standards exclusions) or unmet conditions reduce or eliminate the recoverable amount. Outcomes depend on policy wording, endorsements, and jurisdiction rather than on any fixed rule.
Documentation and Proof of Loss
The evidence the insured must assemble to substantiate the claim, which may include forensic reports, financial records supporting business interruption calculations, invoices for restoration or response services, and records demonstrating compliance with policy conditions.
Use of Experts and Vendors
Loss adjustment for cyber events frequently draws on forensic accountants, incident response firms, and legal counsel to establish both the cause and the quantum of loss. Insurer-appointed and insured-retained experts may reach differing conclusions, and this is a recognized area of negotiation.

Common questions

Answers to the questions practitioners most commonly ask about Loss Adjustment.

Does the loss adjuster work for me as the policyholder?
Not usually. In most cyber claims, the loss adjuster is appointed by or on behalf of the insurer to investigate and quantify the loss, so their role is to assess the claim against the policy wording rather than to advocate for the insured. This does not mean the process is adversarial by default, but it does mean the adjuster's duty runs primarily to the insurer. Policyholders who want representation on their own side sometimes engage a public adjuster or a broker's claims advocacy team, subject to the specific arrangements and jurisdiction. You should confirm who has appointed any adjuster you deal with.
Is loss adjustment the same as the claims settlement or the payout decision?
No. Loss adjustment is the investigation and quantification process that informs a claim decision, but it is not itself the coverage determination or the settlement. Whether a quantified loss is actually payable depends on the policy wording, applicable exclusions, conditions precedent, retentions, sublimits, and any waiting periods, and coverage counsel or the insurer's claims team typically make that determination. An adjuster may measure a business interruption loss precisely, yet coverage can still turn on separate questions such as whether a covered trigger occurred. Treat adjustment and the coverage decision as distinct steps.
How does loss adjustment differ for first-party versus third-party cyber losses?
First-party loss adjustment focuses on quantifying the insured's own losses, such as business interruption, data restoration costs, and cyber extortion outlays, often using financial records, forensic accounting, and system recovery evidence. Third-party matters instead involve assessing the insured's potential liability to others, such as privacy claims or regulatory defense, where the analysis centers on legal exposure and defense and settlement costs rather than the insured's direct losses. The evidence, experts, and timing differ between the two, and a single incident can generate both. Subject to the specific wording, different sublimits and retentions may apply to each category.
What documentation should we prepare to support the adjustment of a business interruption cyber loss?
Adjusters typically look for evidence that establishes both the fact of interruption and its financial magnitude, so contemporaneous records are valuable. This can include incident timelines, forensic reports establishing the cause and duration of the outage, financial statements and management accounts showing normal performance, and records of extra expenses incurred to mitigate the loss. Because many policies apply a waiting period and measure loss against a defined indemnity period, records that pinpoint timing matter as much as those showing amounts. Retaining this material as the incident unfolds, rather than reconstructing it later, generally strengthens the quantification; the precise requirements depend on the policy wording.
When should we notify the insurer so that loss adjustment can begin, and why does timing matter?
Notification is often a condition of the policy, and many cyber policies require prompt or timely notice of a claim or circumstance, so early engagement is generally advisable. Prompt notice can allow the insurer to appoint panel forensic, legal, and adjustment resources whose costs may be covered, and using non-panel vendors without consent can affect recovery under some wordings. Delayed notice can complicate quantification, because evidence may degrade and the cause or duration of an interruption becomes harder to establish. The exact notice obligations, deadlines, and consequences vary by policy and jurisdiction, so review your conditions and any pre-approval requirements.
How do policy features like retentions, sublimits, and waiting periods interact with the adjusted loss figure?
These features operate on the loss after or alongside quantification rather than changing the underlying measurement. A waiting period may exclude losses arising in an initial time window before coverage responds, a retention represents an amount the insured bears before the insurer pays, and a sublimit caps the amount payable for a particular category even if the adjusted loss is higher. As a result, an accurately adjusted loss can exceed the ultimately recoverable amount once these apply. How each feature is calculated and layered depends on the specific wording, so it is worth modeling the interaction rather than assuming the adjusted figure equals the recovery.

Common misconceptions

Loss adjustment is a formality once a claim is filed, and the full claimed amount is paid.
Adjustment is a conditional evaluation. The recoverable amount depends on how the loss is quantified and on the application of retentions, sublimits, waiting periods, exclusions, and conditions precedent under the specific policy wording, so the paid amount may differ from the amount claimed.
The recovery point and recovery time objectives set by the insured determine how business interruption loss is adjusted.
RTO and RPO are resilience metrics that describe recovery goals, not policy terms. Business interruption adjustment is instead governed by the policy's waiting period and indemnity period and by the documented financial loss, which are distinct concepts.
Having cyber insurance and a settled claim means the organization was resilient to the incident.
Insurance is a risk-transfer mechanism that addresses financial consequences after the fact; it does not reduce the likelihood of an incident or by itself constitute resilience. Loss adjustment determines financial recovery, not operational preparedness.

Best practices

Preserve forensic and financial evidence early, since proof of loss for both first-party and third-party cyber coverages typically depends on documentation assembled during and immediately after the incident.
Confirm and satisfy conditions precedent such as timely notice, because failure to meet policy conditions can affect the adjustment outcome regardless of the size of the underlying loss.
Read the specific policy wording to understand how retentions, sublimits, and any business interruption waiting period will be applied before assuming a loss amount is recoverable.
Engage qualified experts (forensic accountants, incident response firms, and coverage counsel) and recognize that insurer-appointed and insured-retained experts may reach differing conclusions that require negotiation.
Keep resilience metrics and insurance terms separate in internal reporting, so that RTO/RPO planning targets are not mistaken for the policy triggers, waiting periods, or indemnity periods that actually drive the adjustment.
Review exclusions and endorsements (such as war, infrastructure, or failure-to-maintain-standards provisions) with the broker before a loss, since these provisions and the governing jurisdiction can materially shape what is ultimately adjusted and paid.
Application Security Isn’t Optional Anymore.