Servers encrypted, ransom demanded?

Does Business Insurance Cover Ransomware Payments? (US)

Only cyber insurance covers ransom. General liability and property policies exclude cyber. Payments now face OFAC sanctions review.

Your policy is the only source of truth

Get a precise answer for your exact policy

Generic answers don't pay claims. PolicyPal reads your policy wording in seconds and tells you, in one sentence, whether you're covered.

Upload your policy$3 per analysis · $9 for all 4 tools · No subscription

Is your situation covered?

ScenarioTypical verdictWhy
Standalone cyber policy with cyber extortion coverageUsually coveredRansom, negotiator fees, and forensics all pay, subject to sub-limits.
General liability policy onlyUsually notGL excludes electronic data and cyber peril outright.
Property policy with 'business interruption'Usually notRequires physical damage — cyber is not physical.
Ransom to an OFAC-sanctioned groupDepends on wordingInsurers must obtain OFAC guidance; unauthorized payments risk penalties.
Data restoration costs after refusing to payUsually coveredCyber policy pays incident response and recovery even without ransom paid.

General industry patterns. Your actual cover lives in your policy wording — PolicyPal reads it for you.

The short answer

Ransomware is only covered under a standalone cyber insurance policy — general liability, property, and standard BOP policies exclude cyber events. Cyber policies typically cover the ransom payment itself, forensic investigation, legal counsel, data restoration, business interruption, and breach notification. Sub-limits for cyber extortion are usually $250K–$5M inside a larger $1M–$10M aggregate.

The OFAC problem

US Treasury's OFAC has designated several ransomware groups (Conti, LockBit affiliates, DarkSide successors). Paying a sanctioned group without OFAC authorization is a federal violation. Cyber insurers now require OFAC clearance before paying — a claim can stall days while attribution is confirmed.

  • OFAC screening required before payment
  • Insurer-approved negotiator usually mandatory
  • Silent-cyber exclusions on non-cyber policies
  • War exclusion invoked for nation-state actors

What PolicyPal checks

We identify the cyber extortion sub-limit, waiting period for business interruption, whether social engineering fraud is included, and the war/nation-state exclusion wording. We flag policies with unusually low incident response caps ($25K forensic budget vanishes in 48 hours) and warranty questions on the application that create rescission risk.

What triggers denial

Insurers rescind or deny when the application misrepresented MFA coverage, endpoint detection, or backup posture. Any 'no' answer to a security control the insurer relied on can void the policy. Failing to notify within the required window (usually 24–72 hours) is another common denial.

Business interruption in a cyber loss

Cyber BI pays lost income during the outage after a waiting period (8–12 hours typical). Contingent BI covers your loss when a critical vendor is hit. Both usually cap at 90–180 days of restoration — longer outages leave a coverage cliff.

Frequently asked

Can I pay the ransom myself and get reimbursed?
Only if your insurer pre-approves. Unauthorized payments are usually denied and may violate OFAC.
Does the war exclusion apply to nation-state ransomware?
Increasingly yes — 2024+ policies invoke 'hostile act' for state-sponsored attacks. Read the exclusion carefully.
Are backups required?
Immutable, offline backups are now a standard warranty question. 'No' voids many policies — check what you attested to.
Does cyber cover regulatory fines?
Some cover fines to the extent insurable by law. HIPAA and PCI penalties are commonly covered; GDPR fines vary by state.
What's a 'panel counsel' requirement?
Insurers require using their approved incident response firm and law firm. Using your own outside counsel without approval often means paying yourself.
Should I have a retainer with an IR firm?
Yes — an IR retainer + tabletop exercise typically reduces cyber premium 10–20% and shortens response time.

Your policy is the only source of truth

Stop guessing. Check your actual policy.

Generic answers don't pay claims. PolicyPal reads your policy wording in seconds and tells you, in one sentence, whether you're covered.

Upload your policy$3 per analysis · $9 for all 4 tools · No subscription