By Nick McCammon
A company I worked with was hit by ransomware. When critical data became inaccessible, the incident stopped being an IT problem and became a business survival decision. The company ultimately paid approximately $3 million to the threat actor in an effort to regain access.
That number gets attention. What stayed with me, though, was everything around it: the pressure, the uncertainty, the outside specialists, the operational disruption, and the reality that sending money to a criminal does not create a normal vendor relationship. What the attackers provided afterward amounted to their own version of a root-cause analysis. A ransom bought the company a chance to recover. It did not buy certainty, trust, or a clean ending.
I have also seen the other side of the story. An import-export company experienced malicious activity, but appropriate endpoint security detected it early enough for us to contain the incident before it created the same kind of financial damage. Insurance can help finance recovery. Early detection can change how much recovery is needed in the first place.
The FBI does not support paying ransoms because payment does not guarantee data recovery and encourages more attacks (Federal Bureau of Investigation [FBI], n.d.). The U.S. Treasury also warns that a payment involving a sanctioned actor may create sanctions risk (Office of Foreign Assets Control [OFAC], 2021). Those are reasons to involve legal counsel, law enforcement, and the insurer before any payment decision—not reasons to improvise under pressure.
So, does your company need cyber insurance?
If a cyber incident could interrupt revenue, expose sensitive information, trigger contractual obligations, or force you to spend more than the business can comfortably absorb, cyber insurance deserves serious evaluation. It is financial risk transfer, not a substitute for cybersecurity.
Cyber Insurance Is About More Than a Ransom
Ransomware is dramatic, but the payment demand is only one possible cost. A serious incident can require digital forensics, specialized legal counsel, data restoration, customer notification, public relations, business-interruption analysis, and defense against claims or regulatory inquiries. The Federal Trade Commission (FTC) identifies many of these as costs that first-party or third-party cyber coverage may address, depending on the policy (FTC, n.d.).
The newest FBI annual report illustrates why published ransom-loss totals can be misleading. IC3 received more than 3,600 ransomware complaints in 2025 with reported losses exceeding $32 million, but the FBI notes that those figures normally exclude lost business, time, wages, files, equipment, and third-party remediation services (FBI, 2026). In other words, the visible payment is not the same as the total business impact.
What a Cyber Policy May Cover
Cyber policies vary. The exact wording, endorsements, exclusions, sublimits, retention, and facts of a claim control the outcome. Still, it helps to understand the two broad coverage categories.
Coverage examples summarized from FTC guidance; policy language and claim facts govern (FTC, n.d.).
Do not assume a standard business owner, property, crime, or general liability policy will respond the same way. Ask whether the cyber coverage is affirmative and explicit. The National Association of Insurance Commissioners (NAIC) notes that cyber insurance can offset ransomware-related costs, while insurers may require prior notification, stronger controls, and specific limits on ransom coverage (NAIC, 2025).
Five Signs Your Company Should Take Cyber Insurance Seriously
- Operations depend on technology. If email, cloud applications, scheduling, payments, production, or customer systems go down, revenue and service can stop with them.
- You hold information people would care about losing. Employee records, customer data, payment details, health information, credentials, contracts, and confidential business data can create response and liability costs.
- A customer or contract expects it. Lenders, customers, landlords, vendors, and public-sector contracts may require cyber coverage, specific limits, or proof of controls.
- Your vendors are part of your operating model. A cloud, software, payroll, or managed-service provider can become part of your risk even when the incident starts outside your network.
- You could not comfortably self-fund the response. Compare the deductible and premium with a realistic incident budget: legal counsel, forensics, restoration, interruption, notification, communications, and possible claims—not only a ransom demand.
Where Cyber Insurance Can Disappoint
The worst time to learn how a policy works is during an active incident. Review these areas before purchase or renewal:
Prior consent and notice
Some policies require immediate use of a breach hotline or approval before retaining vendors, making payments, or incurring major costs.
Ransomware sublimits
Extortion coverage may have a limit below the main policy limit, a separate retention, or conditions that must be satisfied.
Business interruption details
Confirm the waiting period, how income loss is calculated, whether extra expense is included, and when the restoration period ends.
Vendor and cloud events
Look for dependent business interruption and coverage for data held by third parties, not only events inside your own network.
Social engineering and funds transfer fraud
These losses may sit under a separate endorsement with a lower limit or may belong under a crime policy.
Security representations
Answers on the application about MFA, backups, endpoint protection, patching, and training must match reality. Some policies also contain failure-to-maintain-security exclusions (NAIC, 2024).
Sanctions and attribution
A payment may be restricted if the recipient has a sanctions nexus; the insurer, counsel, law enforcement, and experienced response specialists should be involved early (OFAC, 2021).
Ten Questions to Ask Before You Buy or Renew
- What loss scenario did we use to select the limit? Model a plausible outage and data event instead of selecting a round number by instinct.
- Which first-party costs are covered? Verify forensics, breach counsel, restoration, interruption, extra expense, notification, crisis communications, and extortion.
- Which third-party claims are covered? Confirm privacy, network-security, regulatory-defense, contractual, and media-liability language that fits your exposures.
- What limits, sublimits, retentions, and waiting periods apply? Put the numbers for ransomware, social engineering, interruption, and dependent losses on one page.
- What must happen before we spend money? Know the notice requirements, hotline, consent rules, insurer panel, and documentation process.
- Are our cloud providers and critical vendors included? Ask how contingent or dependent losses are defined and whether named providers need to be scheduled.
- How are restoration and business income measured? Clarify betterment, data recreation, system replacement, forensic accounting, and the end of the restoration period.
- What exclusions could affect our most likely incident? Review prior acts, known events, contractual liability, infrastructure failure, war or hostile acts, and failure-to-maintain-security wording.
- Which security controls did we represent as active? Validate every application answer with the IT team or managed provider and preserve evidence.
- Who has authority during an incident? Document who contacts the insurer, counsel, law enforcement, executives, IT, communications, and affected partners.
Insurance Works Better When the Controls Are Real
Insurers increasingly look for evidence that a company is reducing avoidable risk. That should not be treated as paperwork theater. The same controls that support insurability can also reduce the likelihood or impact of an incident.
- Require multi-factor authentication, especially for email, remote access, administrative accounts, and critical systems.
- Maintain encrypted, offline or immutable backups and test restoration, not merely backup completion.
- Use endpoint detection and response, centralized logging, and active monitoring.
- Patch internet-facing systems promptly and manage known vulnerabilities.
- Limit administrative access, remove stale accounts, and segment critical systems.
- Create and exercise an incident-response and business-continuity plan that includes the insurer.
These recommendations align with current FBI and CISA ransomware guidance, which emphasizes offline or immutable backups, MFA, least privilege, endpoint visibility, segmentation, patching, and rehearsed response (Cybersecurity and Infrastructure Security Agency [CISA], 2023; FBI, 2026).
The Practical Answer for Colorado Businesses
Cyber insurance is not automatically right at every price, limit, or set of terms. A very small company with little data and a high tolerance for downtime may make a different decision than an organization with sensitive information, complex operations, contractual requirements, or multiple locations. The right question is not simply, “Do companies our size buy cyber insurance?”
Ask instead: “What could a realistic cyber event cost us, which portion can we reduce, which portion can we absorb, and which portion should we transfer?”
The company in my story faced an approximately $3 million ransom decision while its data and operations were already under pressure. That is the moment every business wants to avoid. The work should happen earlier: understand the exposure, improve the controls, test recovery, choose coverage intentionally, and know who to call.
Cyber insurance can help a company recover financially. It cannot detect an attacker already moving through the environment. In our next article, we will look at how Colorado businesses should choose a security information and event management (SIEM) solution that delivers useful visibility instead of more alerts and another unattended dashboard.
ProvenIT can help your organization review the technology side of cyber-insurance readiness: current controls, backup and recovery, identity protection, endpoint visibility, vendor dependencies, and incident-response roles. The goal is to give your leadership team and insurance advisor clearer evidence before renewal.
Talk with ProvenIT about a cyber-insurance readiness review for your Colorado business.
Important note: This article provides general business and technology information, not legal, insurance, or sanctions advice. Coverage depends on policy language and claim facts. Work with a qualified insurance broker or advisor and legal counsel.
References
- Cybersecurity and Infrastructure Security Agency. (2023). #StopRansomware guide. https://www.cisa.gov/stopransomware/ransomware-guide
- Federal Bureau of Investigation. (2026). 2025 IC3 annual report. https://www.fbi.gov/file-repository/2025_ic3report.pdf
- Federal Bureau of Investigation. (n.d.). Ransomware. Retrieved August 23, 2026, from https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/ransomware
- Federal Trade Commission. (n.d.). Cyber insurance. Retrieved August 23, 2026, from https://www.ftc.gov/business-guidance/small-businesses/cybersecurity/cyber-insurance
- National Association of Insurance Commissioners. (2024). Cyber insurance report. https://content.naic.org/sites/default/files/cmte-h-cyber-wg-2024-cyber-ins-report.pdf
- National Association of Insurance Commissioners. (2025, December 19). Ransomware. https://content.naic.org/insurance-topics/ransomware
- Office of Foreign Assets Control. (2021, September 21). Updated advisory on potential sanctions risks for facilitating ransomware payments. https://ofac.treasury.gov/media/912981/download?inline=
