Does General Liability Cover Ransomware?
Generally no for ransom payments, incident response, data recovery, or resulting downtime. Review cyber coverage and its extortion terms, triggers, and exclusions.
Ransomware may encrypt or steal data and disrupt operations, creating costs that differ from third-party bodily injury or physical property-damage liability. The ISO specimen’s electronic-data exclusion addresses damages from data loss, corruption, or inability to access information. It does not establish coverage for ransom demands, forensic investigation, data restoration, business interruption, or crisis services. A CGL policy should not be treated as ransomware insurance.
A cyber policy may address some extortion and response expenses, but the quoted wording controls. Ask about covered extortion events, insurer consent before payment, sanctions and legal restrictions, waiting periods, incident-response vendors, recovery costs, and interruption sublimits. Report the incident according to the policy’s notice requirements. Compare the CGL and cyber forms, including endorsements, rather than relying on a general statement that cyber liability is included.
Related Coverage
Sources
- Commercial general liability insurance. Insurance Information Institute; What commercial general liability insurance covers; Coverage A, B and C; Additional liability coverages to consider. Accessed 2026-09-25.
- Commercial Insurance Guide. California Department of Insurance; Commercial General Liability; Commercial Automobile; Workers Compensation; Commercial Property. Accessed 2026-09-25.
- Commercial General Liability Coverage Form, CG 00 01 12 07. ISO; specimen hosted by Hiscox; Coverage A I.A pp.1–5; Coverage B I.B pp.6–7; Who Is An Insured II pp.9–10; Limits III p.10; Conditions IV pp.10–12; Definitions V pp.12–16. Accessed 2026-09-25.



