Ransomware is the main reason UK businesses buy cyber insurance. An attacker encrypts your files and demands payment to release them. Your policy can pay the ransom, the recovery costs, and the business income you lose while systems are down, but it will not help if you ignored the basic controls the insurer required.
How a ransomware attack unfolds
The attacker usually enters through a phishing email, a stolen password, or an unpatched system. They move through your network, encrypt your data, and leave a note demanding payment. In many cases they also steal data first and threaten to publish it if you do not pay.
Your response has three clock-driven steps:
- Contain the spread by isolating affected systems.
- Decide whether to pay, based on law, ethics, and whether you hold usable backups.
- Recover from tested backups and rebuild the gaps the attacker used.
What the policy covers
A cyber policy responds to ransomware through several parts at once.
- Ransom payment, where paying is legal and the insurer’s panel firm manages it.
- Negotiation and forensic fees from specialist firms.
- Data restoration from backups and the cost of rebuilding systems.
- Business interruption while trading is impaired.
- Breach notification and credit monitoring if customer data was taken.
Paying a ransom is legal in the UK in most cases, but it is regulated. You must avoid paying sanctioned entities, and insurers route payment through vetted channels. Do not pay from your own account first and expect to be reimbursed without prior agreement.
What the policy excludes
Insurers will not pay where you failed the security conditions in the wording. Typical exclusions:
- No multifactor authentication on email or remote access where the policy required it.
- Known unpatched systems the insurer flagged.
- Losses from war or state-sponsored attack.
- A weakness you knew about and chose not to fix.
The claim often turns on evidence. Insurers ask for logs, backup tests, and proof of the controls you stated at renewal. A business that cannot show it met the conditions may find the claim reduced or declined.
How to reduce the chance you need the cover
Strong controls are cheaper than a ransomware event. Enforce multifactor authentication, keep tested offline backups, patch promptly, and train staff to spot phishing. The National Cyber Security Centre publishes free guidance on each of these.
If a dispute arises over a declined claim, the Financial Ombudsman Service can review it where you are an eligible consumer or small business. Read our guide to how the Ombudsman resolves insurance disputes.
Sources
- Financial Conduct Authority (FCA) — operational resilience expectations for firms.
- Financial Ombudsman Service — how insurance disputes are resolved.
- National Cyber Security Centre (NCSC) — ransomware and phishing guidance.
- Association of British Insurers (ABI) — cyber claims and market data.