Send the bill for a cyber incident to the right address.
Coverage testing of cyber policies, post-incident loss recovery and recourse against at-fault suppliers: the financial remedy for a cyber incident in a single strategy.
A policy is tested before the incident
The hard truth about cyber policies: coverage is determined on the day of purchase, not the day of the incident. Ransom payments, business interruption, data-breach costs and administrative fines — each item has its own terms, deductibles and security warranties. The declared controls (MFA, backups) not actually working is the most common ground for denial.

Incident day: notification discipline
Policies have short notification deadlines and approved-vendor (digital forensics, PR) requirements; expenses incurred without the insurer’s knowledge may fall outside coverage. Our response line embeds the notification and approval flow into incident management.
Claim negotiation and recourse
A claim file requires documenting the loss items, a business-interruption calculation and mapping to the policy wording — against the insurer’s adjuster, it is your file that speaks. In parallel, the chain of fault is examined: the IT supplier that left a system unpatched, the poorly configured cloud, the negligent software provider. The liability limits in their contracts are tested and a recourse action strategy is built.
The annual cycle and the incident file
In peacetime, the work is an annual cycle: the policy wording is stress-tested against your realistic incident scenarios, declared controls are cross-checked with IT so the security-warranty trap is closed before renewal, and a coverage-gap report goes to management. On incident day, the protocol takes over: notifications leave within policy deadlines, approved vendors are engaged, and every expense is documented for the claim. The claim file itself is built like a pleading — loss items, the business-interruption calculation and the mapping to policy wording — while the recourse track runs in parallel against the suppliers whose failures contributed. Deliverables: the gap report, the incident-day protocol and the claim-and-recourse file.
The Turkish frame around the policy
Policy interpretation and claim disputes sit within the insurance book of the Turkish Commercial Code (Law No. 6102): the duties of notification, the aggravation of risk and subrogation — the claim that passes to an insurer who has paid, against the third party at fault — are the backbone of any recourse. The company’s own recourse then runs on two further tracks: the undertakings and liability provisions of the supplier contract, and liability under the Turkish Code of Obligations (No 6098). On both, the limitation calendar has to be set early. Whether administrative fines under the KVKK can be met from the policy turns on the policy wording and the governing law — which makes it a question to ask when the cover is bought, not on the day of the loss. Typical clients: e-commerce and SaaS companies, manufacturers with connected production lines, and Türkiye subsidiaries insured under a German group master policy — where the interplay between the local policy and the group tower must be mapped before the incident. The preventive layer is completed through our ISMS legal framework and the wider Cybersecurity focus.
Who is it for, and what do you get?
The service is used most by companies that hold a cyber policy and have never tested it, by operations that have had an incident and become stuck in the claims process, and by groups with heavy IT procurement.
What you get: a coverage-and-gap report on the policy, a reality check on the security representations it rests on, recourse clauses worked into the supplier contracts, and a notification flow chart for the day of an incident. The technical and organisational whole is dealt with in our cyber security focus area, and the sector-specific obligation layer in our NIS2 record.
Renewal is the only window in which cover can actually be negotiated, which is why the gap report is put on the calendar to land before it.
We are by your side for Cyber Insurance & Recourse
We test your policy against incident scenarios each year, manage the notification-approval-documentation triangle on the day of the incident, and pursue collection through two channels — insurance + recourse. The aim is that the financial burden of a technical incident does not remain on the company.

Other Applications of This Service
Litigation — our other specialised solutions in this area.
Matter Connections
The focus areas, practice areas, desks and legislation connected with this sub-service.
Our Matters in This Service
The anonymised examples of our work that relate to this service.
Representation of a Turkish manufacturer in ICC arbitration
Strategy, case management and representation in a dispute arising from a cross-border supply contract.
Review the matter →Dispute · LitigationDebt recovery in a CMR carriage dispute
Managing the litigation and enforcement process in a compensation dispute arising from cross-border carriage.
Review the matter →Dispute · ReinstatementDefence management of a collective reinstatement dispute
Managing the serial reinstatement claims filed after a restructuring with a single defence strategy and a consistent evidence set.
Review the matter →The Team Delivering This Service
With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

Mehmet Köksal
Founder and Managing PartnerIstanbul · Berlin · KyreniaProfile →
Kübra Köksal-Yılmaz
PartnerBerlin · İstanbulProfile →
Herdem Belen
Of CounselİstanbulProfile →
Sven Köksal
Legal EngineerBerlin · İstanbulProfile →
Batuhan Halim
Of CounselKyreniaProfile →Related Publications
Fresh perspectives and guides from the Knowledge Centre.
Caps can be overcome through gross fault, intent and, in some legal systems, mandatory rules. Moreover, the cap itself may be invalid depending on how it was negotiated — we test this case by case.
Some policies cover it under specific conditions; however, sanctions lists and approval requirements are strict. The payment decision must run in parallel with insurer approval and legal assessment.
The scope of the representation, its materiality, and its causal link to the incident are all open to challenge — not every incomplete representation is a ground for refusal. Legal analysis is essential before accepting the refusal letter.
Cyber Insurance & Recourse — get the right legal support.
Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.
