Ransomware Insurance? Check The Fine Print

Share post:

Ransomware insurance is slowly gaining prominence in the market as a means to enhance protection against the devastating effects of a ransomware attack. 

Depending on the vendor, a ransomware policy may cover loss of income if the attack disrupts operations, or loss of valuable data. Other policies may also cover extortion by refunding the ransom paid to cybercriminals.

The exact payout and terms are stated in the policy document, or the “fine print.” Fine prints also contain exclusions, which are circumstances under which the policy won’t pay out. This is where the problem lies.

For instance, a policy may require that its customer complies to minimum efforts to protect their systems against ransomware. Moreover, a notification clause is usually included in the contract that requires users to notify their insurance vendor about the attack at the soonest possible time.

Another common exclusion is war-related, where insurers refuse to pay out on a claim if the damage was because of war, or war-like actions. Currently, this is the most controversial item in the pipeline.

The first matter for discussion is to agree on the definition of war.  When does an act of aggression qualify as a war-related activity? Another issue is attribution because cyber attackers tend to disguise themselves and do not openly admit their involvement in an attack.

Also, in the event of a ransomware attack, how does the insurer – or the claimant – prove the organization responsible for the attack and their motivation? Can that be found out at all? 

Furthermore, ransom demands come in the millions, while damages could be as high as a billion dollars. Out of self-interest, insurance vendors will try to find any possible reason to refuse to pay a claim. In fact, most of these claims are commonly contested in court.

The outcome of these cases are uncertain and may take very long to resolve.

For more information, read the original story in Thehackernews.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways