Most cyber policies do not pay ransomware losses up to the headline limit. Many carve the exposure down with a ransomware sublimit, shift part of the loss back to the insured through coinsurance, and carry exclusions — security-maintenance conditions, end-of-life software, state-sponsored-attack language — that can shrink or erase recovery entirely.
A business that buys a $1 million cyber policy reasonably assumes it has $1 million of ransomware protection. Often it does not. When the cyber market hardened, carriers responded to ransomware losses not by leaving the market but by quietly restructuring it — sublimits on extortion loss, coinsurance percentages on ransomware events, and a new generation of exclusions tied to the insured’s own security posture. The result is a policy that reads fine on the declarations page and delivers a fraction of its limit in the one event most buyers bought it for. This article walks through why ransomware gets sublimited, what those sublimits actually apply to, how cyber coinsurance works, which exclusions surface in real claims, and what underwriters now expect before offering full limits.

- Why do cyber policies sublimit ransomware in the first place?
- What does a ransomware sublimit actually apply to?
- How does cyber coinsurance shift the loss back to you?
- Which exclusions surface in a ransomware claim?
- What happens to your income while the systems are down?
- What do underwriters need to offer full ransomware limits?
- How does Avanti Group approach ransomware coverage?
Why do cyber policies sublimit ransomware in the first place?
Because ransomware broke the pricing model. Cyber insurance was originally priced around data breaches — notification costs, credit monitoring, regulatory defense — losses that scale with the number of records held. Ransomware changed the shape of the loss: extortion demands, forensics, restoration, and weeks of downtime, hitting businesses of every size regardless of how much data they store. During the hard years that followed, carriers absorbed loss ratios the line was never built for, and their correction shows up in the structure of the commercial insurance program itself rather than in the premium alone. Some carriers restrict ransomware with a sublimit. Some apply coinsurance. Some do both on the same form. The market has since softened substantially — Avanti Group’s read as of mid-2026 is that nearly every cyber buyer should be remarketed, because better terms at the same or better rate are now the norm — but the sublimit and coinsurance architecture built during the hard years is still sitting in force on policies that have simply auto-renewed. That is the first gap: not a coverage a business declined, but a restriction it never noticed. A cyber liability program placed three renewals ago may bear little resemblance to what the same premium buys today.
What does a ransomware sublimit actually apply to?
A sublimit is a lower cap, inside the policy, that applies to a specific category of loss — and a ransomware or cyber extortion sublimit typically aggregates every cost the event generates under that single reduced number. That aggregation is what buyers miss. The sublimit does not just cap the ransom payment. On many forms it caps the extortion payment, the specialist negotiator, the forensics investigation, the data restoration, and sometimes the business income loss attributable to the extortion event — all drawing down one pool that may be a quarter or a tenth of the headline limit. A $1 million policy with a $250,000 ransomware sublimit is, for the most likely severe event the insured faces, a $250,000 policy. The declarations page will not make that obvious; the sublimit schedule and the definitions section will. This is the same discipline that applies across every line: the sublimits, exclusions, and conditions are the policy, not the number in the top corner. A business that has never read its cyber form’s sublimit schedule has not yet decided what risk it is keeping and what risk it is transferring — the form has decided quietly on its behalf.
How does cyber coinsurance shift the loss back to you?
Cyber coinsurance is a percentage of every covered ransomware loss that the insured must pay out of pocket — a coverage-sharing mechanism, not a penalty for underinsuring a building. The property-side 80% coinsurance rule punishes an insured who bought too little limit; cyber coinsurance applies no matter how much limit was purchased. A form with 50% ransomware coinsurance means the carrier pays half of the extortion loss and the insured pays the other half — after the retention, and still subject to the sublimit. Stack the mechanisms and the arithmetic turns stark: a $1 million policy with a $250,000 ransomware sublimit and 50% coinsurance delivers at most $125,000 of carrier money against the event, with the business funding everything else. Coverage that looked fine on paper and failed when it actually mattered. None of this makes a coinsured policy a bad purchase — insurance is just risk tolerance, and a business that understands the split may accept it knowingly for the premium savings. The failure mode is the business that discovers the percentage for the first time inside a claim, when the risk it thought it transferred turns out to have been kept.
Which exclusions surface in a ransomware claim?
Three families do most of the damage. First, the security-maintenance conditions: some forms exclude or restrict loss where the insured failed to maintain the controls it attested to in the application — multi-factor authentication, patching cadence, backup procedures. The application becomes part of the contract, and an MFA answer that was aspirational rather than accurate can surface as a coverage defense after the event. Second, the software and systems exclusions: unsupported or end-of-life operating systems, unpatched known vulnerabilities beyond a stated window, and betterment language that pays to restore systems but not to improve them. Third, the war and state-sponsored-actor exclusions: language that has been rewritten across the market in recent years and litigated in high-profile disputes, because attributing a ransomware strain to a state-linked group is exactly the kind of argument a business cannot afford to have while its systems are down. There is a fourth seam worth naming: extortion coverage pays for the ransom event, but if the same intrusion is used to divert payments or trick an employee into wiring funds, the loss crosses into crime and social engineering territory — a different policy, a different sublimit, and a different set of conditions. And one legal reality sits over the payment itself: ransom payments to sanctioned entities are prohibited under U.S. sanctions law, which is why carriers and their negotiators screen every payment before it moves — a covered demand can still be an unpayable one.
What happens to your income while the systems are down?
For many businesses the downtime, not the ransom, is the largest number in the event. Cyber business interruption works like its property-side counterpart with two critical differences. The waiting period is measured in hours — commonly eight to twelve — and functions as a time deductible: an outage resolved inside the window pays nothing, and a longer outage typically pays only from the end of the waiting period forward. And the period of restoration for a ransomware event is genuinely uncertain, because restoration is not rebuilding a wall — it is forensics, rebuilding systems from backups of unknown integrity, and re-earning the confidence to reconnect. For an Iowa business there is a further clock running alongside the technical one: modern ransomware operators routinely exfiltrate data before encrypting it, and once personal information has been taken, Iowa’s security breach notification statute (Iowa Code chapter 715C) — and the equivalent statutes of every other state where customers live — imposes notification duties with their own costs and deadlines. Double extortion turns one event into two coverage conversations: the extortion loss under its sublimit, and a breach-response loss under separate insuring agreements. Whether the business income piece sits inside the ransomware sublimit or outside it is a form-by-form question — and one of the most consequential answers in the entire policy.
What do underwriters need to offer full ransomware limits?
The controls are no longer negotiable, but they now buy something. Carriers offering full limits without ransomware coinsurance want to see multi-factor authentication on remote access, email, and privileged accounts; endpoint detection and response on the fleet; backups that are offline or immutable, segmented from the production network, and actually tested; a patching cadence with a defined window for critical vulnerabilities; and an incident response plan someone has rehearsed. Businesses that can evidence those controls are exactly the accounts carriers are competing for in the current market — and this is where the mid-2026 softening becomes an action item rather than trivia. A business that implemented MFA and hardened its backups two years ago to keep its renewal is likely still paying for a policy structured in the hard market: sublimited, coinsured, or both. The same security posture, positioned properly to the market today, can frequently buy full limits with no coinsurance at comparable premium. Cheap insurance is expensive — but so is diligence the market never got told about. Account positioning is the work: packaging the controls, the backup architecture, and the loss history so an underwriter wants the risk, rather than mailing last year’s application to last year’s carrier.
How does Avanti Group approach ransomware coverage?
Avanti Group treats a cyber placement as a diagnostic exercise, not a quote request. That starts with a Business Risk Diagnostic™ — what a realistic ransomware event costs this specific business by day of downtime, where the current form’s ransomware sublimit and coinsurance actually leave the balance, whether the application’s security answers still match reality, and how the cyber program coordinates with the crime policy so a funds-transfer loss does not fall in the seam between them. Then the program gets built deliberately: sublimits negotiated toward full limits where the controls support it, coinsurance removed or knowingly accepted, waiting periods and restoration language matched to how the business actually recovers. Most agents will renew the incumbent form without reading it; the industry trained agents to quote fast and move on. A business that knows exactly what its policy pays on day one of an encryption event — and what it doesn’t — is the one whose insurance program was built before the loss instead of discovered during it.
Frequently Asked Questions
Does cyber insurance actually pay the ransom itself?
Cyber extortion coverage can reimburse a ransom payment, along with the negotiator and forensics costs around it — subject to the sublimit, any coinsurance, and the carrier’s consent requirements. One hard boundary applies regardless of policy language: payments to sanctioned entities are prohibited under U.S. sanctions law, so carriers and their negotiation firms screen every payment first. A demand from a sanctioned group can be covered in theory and unpayable in practice.
What is a typical ransomware sublimit?
There is no single standard — that is the point of reading the form. Hard-market placements commonly carried ransomware sublimits at 50%, 25%, or even 10% of the aggregate limit, sometimes with coinsurance stacked on top. In the current softer market, full-limit ransomware coverage without coinsurance is achievable for businesses with strong controls. The sublimit on a policy that has auto-renewed since the hard market deserves a fresh look.
How is cyber coinsurance different from property coinsurance?
Property coinsurance is a penalty mechanism — insure your building to at least the stated percentage of its value or claims get reduced proportionally. Cyber ransomware coinsurance is a sharing mechanism — the insured pays a stated percentage of every covered extortion loss no matter how much limit was purchased. You cannot cure cyber coinsurance by buying a higher limit; it can only be negotiated off the form or knowingly accepted.
Is downtime from ransomware covered even if we never pay the ransom?
Generally yes — cyber business interruption responds to the network outage, not the payment decision. But the waiting period (often eight to twelve hours) applies first, the recovery is measured against the period of restoration, and on some forms extortion-driven downtime draws from the ransomware sublimit rather than the full business interruption limit. Whether restoring from backups instead of paying changes which insuring agreement responds is a form-specific question worth answering before the event.
What security controls do carriers require for full ransomware limits?
The consistent short list: multi-factor authentication on remote access, email, and privileged accounts; endpoint detection and response; offline or immutable backups that are segmented and tested; a defined patching window for critical vulnerabilities; and an incident response plan. These are now underwriting table stakes — and because the application’s answers can operate as conditions of coverage, they need to be accurate on the day of the loss, not just the day of the signature.
Related reading
Other articles in the Commercial Foundations series:
- Social Engineering and Wire Fraud: Why Most Cyber Policies Sublimit It — Social engineering losses leave through channels that look legitimate — an authorized wire, an approved vendor, a routine payment run — which is why cyber policies cap them at a sublimit far below the headline limit and make verification procedures a condition of coverage; UCC Article 4A (Iowa Code ch. 554) allocates fraudulent-wire losses to the business rather than the bank, and the controls that persuade underwriters to raise the cap — callback verification, dual authorization, banking-change waiting periods — are the same ones that prevent the loss. Second article in the Cyber Liability cluster.
- Business Email Compromise: Anatomy of a Six-Figure Loss — A BEC loss is an authorized payment procured by deception — assembled from weeks of reconnaissance inside a compromised vendor mailbox, executed through a routine payment run where every indicator reads normal — and the coverage analysis turns on deception and verification rather than network intrusion: cyber social engineering sublimits, crime endorsements, breach-response coverage when a mailbox is compromised (including Iowa Code chapter 715C notification duties), and the verification controls that both prevent the loss and preserve the coverage. Third article in the Cyber Liability cluster.
- Cyber Insurance for Healthcare: HIPAA-Aligned Policy Structure — Healthcare cyber coverage has to be engineered around HIPAA’s fixed obligations from the start: the Breach Notification Rule’s 60-day machinery mapped to specific insuring agreements, regulatory proceedings coverage for OCR investigations and the insurability of fines, business associate agreement (BAA) vendor exposure and Iowa Code chapter 715C’s parallel state notification track, and the patient-harm seam between cyber and medical malpractice coverage. Fourth article in the Cyber Liability cluster, first vertical piece (healthcare).
- Cyber Insurance for Manufacturers: OT, IoT, and Downtime — A manufacturer’s cyber loss lands on the production floor, not the front office: operational technology (PLCs, SCADA, industrial control systems) that the eroding ‘air gap’ no longer protects, cyber business interruption terms — waiting period, period of restoration, how lost production is measured — that decide whether a stopped line is actually covered, bricking coverage for equipment rendered functionally dead, and the physical-damage seam where cyber policies exclude tangible property and property policies never contemplated an electronic cause of loss. Fifth article in the Cyber Liability cluster, second vertical piece (manufacturing).
- Cyber for SaaS and Tech Companies: What Underwriters Expect — Cyber underwriters read a SaaS company’s controls before its revenue — a tech E&O and cyber program structured as one placement (one carrier, one form, one set of definitions) so a single outage can’t be split into two partial denials; customer-contract data promises and indemnities read against the policy’s contractual liability language; and documented controls — MFA on email, remote access, and privileged accounts, tested segregated backups, EDR, and a rehearsed incident response plan — that now move terms, retentions, sublimits, and insurability itself, while a SOC 2 report corroborates the underwriting file without replacing it, and the softened mid-2026 cyber market rewards exactly the documentation discipline the hard market demanded. Sixth article in the Cyber Liability cluster — the cluster’s underwriter-expectations piece.
