Cyber insurance and ransomware: what's actually covered (and what voids it)
Key takeaways
- Coverage typically spans incident response, business interruption, and sometimes ransom payment — but each has conditions and sub-limits.
- Insurers now require specific controls (MFA, EDR, tested backups); misrepresenting them on the application can void a claim.
- Read the notification and panel-vendor requirements before an incident — using your own IR firm without approval can forfeit coverage.
What a ransomware policy usually covers
A typical cyber policy addressing ransomware covers several buckets: incident response costs (forensics, legal, negotiation), business interruption losses from the outage, data-recovery expenses, and in some policies the ransom payment itself — often subject to sub-limits and to sanctions-compliance checks. Notification and credit-monitoring costs for affected individuals frequently fall under a separate privacy-liability section. Knowing which bucket pays for what, and where the sub-limits sit, is the difference between a claim that covers the incident and one that covers a fraction of it.
The control requirements that gate coverage
Insurers spent the last few years tightening underwriting, and policies now come with control requirements: multi-factor authentication on remote access and email, endpoint detection, tested and segregated backups, and privileged-access controls. These aren't suggestions — they're often warranties. If you attested to having MFA everywhere on the application and the breach traced to an account that didn't, the insurer can dispute or deny the claim on the grounds that the risk they priced wasn't the risk they insured. Your application answers need to be true at renewal and stay true.
The process conditions that quietly forfeit claims
Beyond controls, policies impose process conditions that surprise victims mid-incident. Many require notification within a short window, and many require you to use the insurer's approved panel of IR firms, negotiators, and counsel — engaging your own trusted vendor without pre-approval can forfeit reimbursement for that work. Ransom payments almost always require insurer sign-off and sanctions screening beforehand. Read these clauses before an incident and pre-clear your preferred vendors onto the panel, so a 2am decision doesn't accidentally void the coverage you're paying for.
Treat the policy as a control document
The most useful reframe is to read your policy not as a financial backstop but as a checklist of controls your insurer believes prevent claims — because they've seen the data. The requirements they impose are a decent baseline security program in disguise. Aligning to them does double duty: it keeps your coverage valid and it reduces the odds you ever file a claim. The firms that struggle at claim time are almost always the ones who treated the application as paperwork rather than as promises they had to keep.