Cyber Insurance for Ransomware: What's Actually Covered
What's actually covered, what isn't, and how to choose a policy that pays when it matters — not just one that's cheap at renewal.
11 min read
Ransomware coverage is not one line item
Cyber policies bundle together several distinct coverages that all matter in a ransomware event, and it's common for buyers to discover — during a live incident — that they assumed coverage existed where it didn't. Understanding the separate pieces before you buy (or renew) is the difference between a policy that pays and one that argues.
- Incident response costs — forensics, breach counsel, negotiation services, often subject to a panel-firm requirement.
- Business interruption — lost income and extra expense during downtime, usually with a waiting-period deductible measured in hours.
- Ransom payment & related costs — often a sub-limit, and increasingly restricted or excluded in some jurisdictions and industries.
- Data restoration — cost to rebuild or recover data and systems, distinct from business interruption.
- Regulatory & liability — fines, penalties, and third-party claims arising from a breach connected to the incident.
The panel-firm trap
Most carriers require you to use their pre-approved panel of incident response firms, forensics providers, and breach counsel to be reimbursed — engaging your own preferred vendor outside the panel can mean paying out of pocket even with an otherwise valid claim.
Confirm your panel firms before you buy, and consider carriers whose panel includes a firm you already trust or can pre-negotiate a retainer with.
Underwriting is now a security audit
Insurers have tightened underwriting substantially in response to ransomware losses. Expect detailed questionnaires — and increasingly, technical scans — covering MFA coverage, EDR deployment, backup architecture, and privileged access management. Weak answers here now translate directly into higher premiums, larger sub-limits, or declined coverage, not just a rubber-stamp renewal.
This is precisely why the readiness practices in our Defense Playbook matter for your insurance economics, not just your security posture — insurers are underwriting against the same controls.
Questions to ask before you sign
- Is there a sub-limit specifically on ransomware payments, separate from the overall policy limit?
- Does the policy require MFA, EDR, or offline backups as a condition of coverage — and could a gap void a claim after the fact?
- What is the waiting period before business interruption coverage triggers?
- Are panel IR firms and breach counsel ones you'd actually choose, or can you negotiate an endorsement to use your own?
- Does coverage extend to contingent business interruption — i.e., an attack on a critical vendor or MSP, not just you directly?