Investigative & Forensic Accounting Blog | Meaden & Moore

Five Recurring Damage Measurement Debates in Cyber Business Interruption Claims | Meaden & Moore

Written by Michael G. Milne, CPA, CFE | Sep 10, 2026, 3:45:00 PM

Meaden & Moore’s Perspective on the Quantum Debates Defining Modern Cyber Losses

Cyber incidents may generate exposure across several coverage components, but the interruption of revenue-producing operations can materially exceed the direct cost of technical investigation and system repair. Business interruption continues to dominate the conversation around claim severity, while dependent business interruption exposures associated with technology vendors, cloud providers, and software platforms are attracting increasing attention from insurers and reinsurers.

As cyber business interruption claims have become larger and more complex, disputes have evolved. The debate is no longer solely about whether coverage exists. Instead, insurers, adjusters, brokers, and policyholders are increasingly focused on how losses should be measured.

From a forensic accountant's perspective, five topics consistently emerge at the centre of cyber business interruption discussions: (1) make-up sales, (2) period of restoration, (3) continuing expenses, (4) payroll treatment, and (5) the reasonableness of extra expenses claimed.

1. Make-Up Sales: Lost or Delayed?

One of the first questions in any cyber business interruption claim is whether revenue was permanently lost during the outage or deferred until a later date. Insureds frequently take the position that customers were unable to transact during the interruption and permanently took their business elsewhere.

This issue has become increasingly important in cyber claims because many businesses are able to retain customer demand despite suffering technological disruptions. Unlike a manufacturing plant destroyed by a fire, a business affected by a cyber incident may still retain its inventory, workforce, customers, and production capacity once systems return (and sometimes, while certain systems are impacted). Like the face of a clock, an insured’s revenue-generating operations may appear calm and orderly, while behind the dial a complex system of recovery efforts, unexpected obligations, and manual workarounds is constantly turning to keep the business moving.

The widespread disruption caused by the CDK Global incident provides a useful example, as many automotive dealerships experienced difficulties processing transactions, servicing vehicles, and managing sales activity during the outage. Once systems resumed, many businesses worked through accumulated customer demand and deferred transactions. The resulting question for forensic accountants becomes straightforward:

Were sales truly lost, or were they delayed?

Answering this question requires detailed analysis of transaction-level data, backlog fulfilment, recovery-period revenues, and production or service capacity constraints. The dispute often centres not on accounting methodology, but on what actually happened in the marketplace.

2. Period of Restoration: When Is the Business Really Back?

Cyber business interruption claims frequently involve debates regarding the end of the indemnity period.

Policyholders often argue that business interruption continues long after systems become operational. Insurers may contend that the covered loss period ends once systems have been reasonably restored and the business has the ability to resume normal activities.

This distinction is particularly relevant in cyber claims because restoration is rarely a single event. Systems are generally reconstituted incrementally, with certain applications remaining unavailable until the final switch is turned back on. All the while, manual workarounds may continue and employees sometimes need to overcome significant inefficiencies while backlogs are addressed.

A recent Willis report based on 5,500 insureds indicated that the severity of ransomware losses was driven predominantly by the disrupted productivity and prolonged downtime that followed an incident, with business interruption representing one of the largest components of ransomware-related costs.

The Change Healthcare incident illustrates this challenge. Many healthcare providers regained access to core systems before billing processes, claims administration functions, and cash collection cycles fully normalised. The question therefore becomes:

Where does recovery end and ordinary business friction begin, and who bears the cost of the difference?

Answering this question requires analysis of operational metrics, productivity analyses, and financial performance indicators.

3. Continuing versus Non-Continuing Expenses

Another recurring source of debate involves the treatment of expenses during the interruption period.

Many cyber business interruption calculations require identification and separation of costs that continued during the outage from costs that ceased or were avoided. This determination directly affects the amount of lost profit being claimed by insureds and measured by forensic accountants.

Insureds often maintain that most operating expenses continued despite the interruption. Employees remained employed, facilities remained open, and contractual commitments remained in force. The challenge is that cost behaviour is rarely uncomplicated during a cyber event. Some expenses continue entirely and others cease entirely, while most fall somewhere in between. As a result, forensic accountants spend significant time analysing expense behaviour at a granular level. Items such as payroll, IT costs, marketing expenditures, outsourced services, freight costs, and production-related expenses may all behave differently during the interruption period for enough reasons to warrant a separate article.

The Co-op and M&S cyber incidents highlighted how operational disruption can extend across multiple business functions simultaneously, creating complexity when determining which costs remained necessary compared to those effectively avoided.

Ultimately, this question is less about accounting and more about understanding how the business actually operated during the disruption.

4. Payroll Treatment: For Many Operations, The Largest Expense Category

Few topics generate more discussion than payroll.

In many organisations, payroll represents the single largest operating expense. Unsurprisingly, disagreements regarding payroll treatment can materially affect claim outcomes.

Policyholders often argue that payroll continued throughout the interruption and should therefore be treated as a continuing expense. That is, employees remained employed and continued receiving compensation despite the disruption.

Additional complexity arises when distinguishing between:

    • salary labour,
    • hourly labour,
    • temporary staff,
    • overtime,
    • contract workers, and
    • employees dedicated to recovery efforts.

Cyber events make this issue particularly difficult because employees are often reassigned to manual processing activities, workaround procedures, or recovery efforts. In these situations, labour may continue but serve a different purpose than before the incident. Many times, this arises in the form of a discussion surrounding labour efficiency which, to the extent it does not result in increased payroll obligations, would not constitute additional expenses.

The key questions become:

Did payroll support normal operations, recovery efforts, or both?

Did the business take on more payroll obligations during the impact period than it would have, but for the cyber event?

5. Extra Expense Reasonableness

Many organisations incur additional costs following a cyber event. External consultants may be retained, emergency technology solutions may be implemented, additional labour may be required, and manual workarounds may need to be established immediately, and sometimes, for a prolonged period after systems have resumed.

The debate generally revolves around whether these expenditures were necessary to minimise larger business interruption losses. This discussion generally focuses on whether the expenditures were reasonable, proportionate, and economically justified.

Extra expense questions have become more prominent because affected businesses increasingly rely on specialist vendors, temporary systems, and labour-intensive workarounds to maintain critical functions while permanent repairs are completed. The way in which an insured is poised to salvage impacted systems and processes following a cyber event is one of the biggest hints at valuing exposure with respect to unforeseen expenditure.

Forensic accountants frequently evaluate these questions through cost-benefit analyses, comparing mitigation expenditures against avoided business interruption losses.

The issue is complex, but the question is clear:

How much mitigation spending is reasonable before it becomes excessive?

Path Forward

Although cyber incidents originate in technology, cyber business interruption claims are increasingly resolved through economics, accounting, and evidence.

Across industries and claim types, the same five debates consistently reappear:

  1. make-up sales,

  2. period of restoration, 

  3. continuing vs. non-continuing expenses, 

  4. payroll treatment, and 

  5. the reasonableness of extra expenses claimed

As cyber losses grow in sophistication and financial significance, the role of the forensic accountant continues to expand. Greater reliance on third-party technology also creates additional measurement challenges, particularly where the insured must separate the effect of a vendor outage from unrelated trading conditions and determine whether interrupted transactions were lost, deferred, or recovered elsewhere.

The most successful claim outcomes are often achieved through rigorous financial analysis, appropriate methodologies, clear evidence, and collaboration. For insurers and insureds alike, the future of cyber business interruption claims will increasingly depend on the ability to distinguish operational disruption from genuine economic loss.