Coverage for ransomware payments is an integral part of cyber liability insurance coverage and subject to policies’ full limits, but as ransomware claims increase, more insurers may introduce sublimits, observers say.
“Cyber extortion events have been routinely covered by the cyber insurance industry for more than a decade, and continue to be,” said Matthew McCabe, general counsel on cyber policy for Marsh Inc.
Insurers cover the demand payment, expenses associated with forensic analyses and consulting fees, he said.
There has been discussion in the market concerning ransomware sublimits, but so far they have not been widely introduced, observers say.
“There has not been, in my view, a commitment to sublimit the insurance, but it sure is being discussed,” said Kelly Castriotta, Chicago-based head of product development and North American cyber underwriting lead for Allianz Global Corporate & Specialty SE, financial lines, North America.
The market is “still very competitive,” and if one insurer were to offer a ransomware sublimit, it would be very easy to find three others who offer full limits, said Robert Horn, New York-based vice president, management professional and cyber solutions, for Alliant Insurance Services Inc.
Ransomware payments “are just part of the larger losses we’re seeing,” including business interruption expenses, said Marcin Weryk, New York-based head of cyber-West and South at Axa XL, a unit of Axa SA.
Ransomware payments may become more commoditized, much like kidnap and ransom insurance, so that both insurers and the criminals “will get to this place where everyone understands how it works, so it will be relatively predictable,” said Michael Born, senior vice president and cyber liability product leader at Berkley Re Solutions, a W.R. Berkley Corp. unit, in Overland Park, Kansas.
“This process has already been streamlined,” said Mr. Weryk, adding that the insurer has vendors on its panels who specialize in negotiating with criminals. “There’s almost this language that our negotiators speak to the hackers” because they do it so often, he said.