What Insurance Covers Ransomware?
Cyber insurance may cover specified ransomware response costs, data restoration, business interruption, or cyber-extortion loss. Ransom payments and related expenses depend on the policy’s grant, consent requirements, exclusions, and sublimits.
Cyber insurance is the main line to examine after a ransomware attack, but the policy may divide the losses among several coverage sections. FTC guidance describes first-party cyber cover as potentially including data recovery, lost income, forensic services, and cyber extortion. An AIG specimen has a separate cyber-extortion section for defined security or privacy threats and requires prior written insurer consent for money paid to end a threat. That is one carrier’s dated specimen, not a universal rule.
A ransomware event can involve encrypted data, a threat to publish stolen information, interrupted operations, response consultants, restoration costs, and a demanded payment. One policy may cover some of these and exclude or sublimit others. For example, payment may require the insurer’s prior approval, the loss may be subject to a retention, and the covered threat must meet the policy definition and be reported within the required period. The policy may also restrict payments prohibited by law.
Before relying on a quote, check whether extortion is included, who authorizes or arranges any payment, whether restoration and interruption have separate limits or waiting periods, what vendors must be used, and how notice works. Confirm that your backups and cloud dependencies fit the wording and that the overall limits match your recovery needs.
Related Coverage
Sources
- Cyber Insurance. Federal Trade Commission; First-Party Coverage; Third-Party Coverage; What Should Your Cyber Insurance Policy Cover. Accessed 2026-09-25.
- CyberEdge specimen policy. AIG; Security and Privacy Coverage Section, PDF pp.11–18, especially exclusions p.18; Cyber Extortion Coverage Section, pp.29–31. Accessed 2026-09-25.



