Ransomware and Cyber Insurance: What It Pays For, Including the Ransom

Most cyber policies cover ransomware through several coverage parts: cyber extortion for negotiators and, where lawful and approved in advance, the ransom; breach response for forensics and notification; data restoration for rebuilding systems; and business interruption for lost income. Paying a sanctioned group is illegal, so the insurer controls the process. In Washington, 58% of recent reported cyberattacks were ransomware.

By Trella Commercial · Updated October 4, 2026

The short version

  • Ransomware is the dominant cyberattack in Washington's breach records. It made up 58% of cyberattacks reported to the Attorney General from July 2023 to July 2026, and businesses filed 231 of the 592 ransomware notices on record, more than any other sector.
  • One attack, five coverage parts. Extortion, breach response, data restoration, business interruption, and often privacy liability all respond.
  • The ransom is the smaller question. Downtime, restoration, and notification usually matter more, and attackers increasingly steal data as well as encrypting it.
  • Paying is not automatic. Federal sanctions rules prohibit payments to sanctioned groups, and insurers require their approval and their advisors.
  • Coverage depends on controls. Insurers may decline, exclude, or limit ransomware without multifactor authentication and separated backups.

How a ransomware attack unfolds, and what pays for it

StageWhat happensCoverage part
DiscoveryFiles are encrypted and a ransom note appears, often overnight or on a weekendBreach response (hotline, breach attorney)
InvestigationForensic investigators find how attackers got in and what they tookBreach response (forensics)
NegotiationSpecialists contact the attackers, verify claims, and check sanctions listsCyber extortion
DecisionRestore from backups, or pay for a decryption key if lawful and approvedData restoration, or cyber extortion
RecoverySystems are rebuilt and cleaned, sometimes over days or weeksData restoration; business interruption for lost income
NotificationIf data was accessed or stolen, affected people and regulators must be toldBreach response (notification, call center, monitoring)
ClaimsCustomers, patients, or clients sue over exposed dataPrivacy liability; regulatory defense

Double extortion: why ransomware is usually a breach too

Many ransomware groups copy data before encrypting it, then threaten to publish it unless paid. That changes the response:

  • Restoring from backups does not end it. The data is already out.
  • Breach notice may be required. In Washington, unauthorized acquisition of personal information triggers notice within 30 days of discovery unless the breach is not reasonably likely to cause harm. See Washington data breach notification law.
  • Liability exposure rises. People whose data was taken can bring claims.

Forensic investigators determine whether data left your network, which is one reason to engage them immediately through your insurer.

The ransom question

ConsiderationWhat it means for you
SanctionsThe U.S. Treasury's Office of Foreign Assets Control warns that ransom payments to sanctioned persons or groups can violate federal law, regardless of whether the victim knew
Insurer approvalMost policies cover a ransom only with the insurer's prior written consent
Law enforcementThe FBI and CISA discourage paying, and OFAC treats prompt reporting and cooperation with law enforcement as mitigating factors
No guaranteePaying may not produce a working key, and does not ensure stolen data is deleted
Coinsurance and sublimitsSome policies make you share a percentage of ransom and extortion costs

In practice, the decision is made with the breach attorney, the insurer, and its negotiators. Businesses with good, separated backups often restore without paying.

What the FBI sees

The FBI's Internet Crime Complaint Center received 3,156 ransomware complaints in 2024. The FBI notes that the reported losses do not include lost business, time, wages, files, or equipment, or the cost of outside remediation, and that many victims do not report a loss amount at all. For a small business, those excluded costs, especially downtime, are usually the largest part of the bill.

Where Washington ransomware notices come from

From Trella Commercial's analysis of Washington Attorney General breach notices, 2015 to 2026:

SectorRansomware notices filed
Businesses231
Health care114
Nonprofits and charities85
Finance74
Education73

Only breaches affecting more than 500 Washington residents are filed, so smaller incidents do not appear.

What insurers require for ransomware coverage

Because ransomware drives so many claims, insurers focus on the controls that stop it:

  • Multifactor authentication on email, remote access, and administrator accounts
  • Backups that are offline, immutable, or otherwise separated, and tested by restoring
  • Endpoint detection and response on every computer and server
  • No remote desktop exposed to the internet, and prompt patching of known vulnerabilities
  • Separate administrator accounts used only for admin work

Missing controls can mean a declined application, a ransomware exclusion, a lower sublimit, or coinsurance. See what a cyber insurance application asks.

The first steps if you are hit

  1. Disconnect affected devices from the network, but do not turn them off or wipe them; forensics needs them.
  2. Call your insurer's breach hotline or your broker before contacting the attackers or hiring vendors.
  3. Do not pay or negotiate on your own. Let the insurer's negotiators and breach attorney handle contact.
  4. Report to the FBI through ic3.gov or your local field office, as your advisors direct.
  5. Check your backups without connecting them to infected systems.
  6. Start the clock. If personal information was accessed, Washington's 30-day notice period runs from discovery.

Common questions

Does cyber insurance pay the ransom?

Many cyber policies cover ransom payments under cyber extortion coverage, but only when the payment is lawful and the insurer approves it in advance. The insurer's negotiators check that the attackers are not sanctioned, and some policies require you to share part of the cost.

Is it illegal to pay a ransomware demand?

Paying is not illegal in general, but paying a sanctioned person or group can violate U.S. sanctions law even if you did not know. OFAC considers reporting to and cooperating with law enforcement a mitigating factor. This is why insurers and their advisors control the payment process.

What does cyber insurance cover after a ransomware attack besides the ransom?

Forensic investigation, a breach attorney, negotiation, data and system restoration, lost income while systems are down, notification and credit monitoring if data was accessed, and liability and regulatory defense if people whose data was exposed bring claims.

Do I have to report a ransomware attack in Washington?

If personal information of Washington residents was accessed or acquired, Washington's breach law generally requires notice to affected residents within 30 days of discovery, and to the Attorney General if more than 500 residents are affected. Encrypted-only attacks with no data access may not trigger notice; forensic findings decide it.

Can I get ransomware coverage without backups and MFA?

It is increasingly difficult. Many insurers decline, exclude ransomware, or reduce coverage without multifactor authentication on email and remote access and backups separated from the network.

Sources

This page is general information, not legal advice. Decisions about ransom payments should be made with your insurer, breach attorney, and law enforcement. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.