Is your situation covered?
| Scenario | Typical verdict | Why |
|---|---|---|
| Standalone cyber policy with cyber extortion coverage | Usually covered | Ransom, negotiator fees, and forensics all pay, subject to sub-limits. |
| General liability policy only | Usually not | GL excludes electronic data and cyber peril outright. |
| Property policy with 'business interruption' | Usually not | Requires physical damage — cyber is not physical. |
| Ransom to an OFAC-sanctioned group | Depends on wording | Insurers must obtain OFAC guidance; unauthorized payments risk penalties. |
| Data restoration costs after refusing to pay | Usually covered | Cyber policy pays incident response and recovery even without ransom paid. |
General industry patterns. Your actual cover lives in your policy wording — PolicyPal reads it for you.
The short answer
Ransomware is only covered under a standalone cyber insurance policy — general liability, property, and standard BOP policies exclude cyber events. Cyber policies typically cover the ransom payment itself, forensic investigation, legal counsel, data restoration, business interruption, and breach notification. Sub-limits for cyber extortion are usually $250K–$5M inside a larger $1M–$10M aggregate.
The OFAC problem
US Treasury's OFAC has designated several ransomware groups (Conti, LockBit affiliates, DarkSide successors). Paying a sanctioned group without OFAC authorization is a federal violation. Cyber insurers now require OFAC clearance before paying — a claim can stall days while attribution is confirmed.
- OFAC screening required before payment
- Insurer-approved negotiator usually mandatory
- Silent-cyber exclusions on non-cyber policies
- War exclusion invoked for nation-state actors
What PolicyPal checks
We identify the cyber extortion sub-limit, waiting period for business interruption, whether social engineering fraud is included, and the war/nation-state exclusion wording. We flag policies with unusually low incident response caps ($25K forensic budget vanishes in 48 hours) and warranty questions on the application that create rescission risk.
What triggers denial
Insurers rescind or deny when the application misrepresented MFA coverage, endpoint detection, or backup posture. Any 'no' answer to a security control the insurer relied on can void the policy. Failing to notify within the required window (usually 24–72 hours) is another common denial.
Business interruption in a cyber loss
Cyber BI pays lost income during the outage after a waiting period (8–12 hours typical). Contingent BI covers your loss when a critical vendor is hit. Both usually cap at 90–180 days of restoration — longer outages leave a coverage cliff.
Frequently asked
- Can I pay the ransom myself and get reimbursed?
- Only if your insurer pre-approves. Unauthorized payments are usually denied and may violate OFAC.
- Does the war exclusion apply to nation-state ransomware?
- Increasingly yes — 2024+ policies invoke 'hostile act' for state-sponsored attacks. Read the exclusion carefully.
- Are backups required?
- Immutable, offline backups are now a standard warranty question. 'No' voids many policies — check what you attested to.
- Does cyber cover regulatory fines?
- Some cover fines to the extent insurable by law. HIPAA and PCI penalties are commonly covered; GDPR fines vary by state.
- What's a 'panel counsel' requirement?
- Insurers require using their approved incident response firm and law firm. Using your own outside counsel without approval often means paying yourself.
- Should I have a retainer with an IR firm?
- Yes — an IR retainer + tabletop exercise typically reduces cyber premium 10–20% and shortens response time.
Your policy is the only source of truth
Stop guessing. Check your actual policy.
Generic answers don't pay claims. PolicyPal reads your policy wording in seconds and tells you, in one sentence, whether you're covered.
