Ransomware and Cyber Insurance: What's Covered (and What Isn't)

Reviewed by IT Cares certified technicians · Updated July 2026

Canadian business owner reviewing a ransomware cyber insurance policy document alongside a laptop showing an incident response timeline
Knowing exactly what your ransomware coverage includes — and where the exclusions sit — matters most before an attack, not during one.
🛡️
Mid-attack right now? Jump to the first-24-hours checklist, or call our emergency line below.

Cyber insurance is not a blank cheque for a ransomware attack — it's a contract with specific covered costs and specific, sometimes narrow, exclusions, and the gap between what policyholders assume is covered and what actually is covered tends to surface at the worst possible moment: mid-incident, under pressure, with a countdown clock on the attacker's ransom note. A typical Canadian small or mid-sized business cyber policy will pay for a real, substantial slice of what a ransomware incident costs — forensics, a professional negotiator, data restoration, lost income while systems are down, and the notification and legal costs that follow. But every one of those coverages sits inside conditions, sublimits, and exclusions that most business owners have never actually read until they're staring at a claim decision letter.

This guide walks through exactly what's typically covered, the exclusions that most often catch Canadian policyholders off guard, how a real ransomware claim unfolds from the moment IT notices something is wrong through to claim closeout, the real considerations around paying or not paying a ransom, the role your insurer's appointed incident response firm plays (and why using them usually isn't optional), three fictional but realistic Canadian case studies showing how differently these claims can play out, and concrete Canadian-dollar figures for what all of this typically costs. It's written for the person who will actually be making decisions during an incident — an owner, controller, or IT manager — not for an insurance underwriter.

Not legal, financial, or insurance advice

This article is educational information based on general market patterns Canadian brokers, insurers, and incident responders commonly report. It isn't a substitute for reading your actual policy wording or for advice from a licensed insurance broker or lawyer about your specific situation. Coverage, exclusions, sublimits, and definitions vary meaningfully between carriers and even between policy versions from the same carrier — always confirm the specifics of your own policy with your broker before making decisions based on this article.

How a Ransomware Claim Actually Unfolds, Start to Finish

Most business owners have never been through a ransomware claim, so the process feels abstract until it isn't. In practice, it follows a fairly consistent sequence across Canadian carriers, even though the specific vendors and timelines differ policy to policy. Understanding this sequence before an incident happens is one of the single most useful things you can do — it removes decision paralysis at the exact moment you can least afford it.

1

Detection

Someone notices — a ransom note on desktops, files with a strange new extension, an EDR alert, or simply systems that stop responding. In a genuine ransomware event, this is usually fast and unmistakable, though the initial intrusion that led to it may have happened days or weeks earlier and gone unnoticed.

2

Immediate containment, then the breach hotline call

Before anything else, affected systems get isolated from the network — pulling network cables, disabling Wi-Fi, or powering down unaffected systems to stop the spread. Then comes the call to the insurer's 24/7 breach hotline number, printed on your policy declarations page. This call should happen within hours, not days — most policies require prompt notification, and delay can itself become grounds for a coverage dispute later.

3

Insurer-appointed forensics firm engaged

The insurer, usually through a breach coach (a specialized lawyer who quarterbacks the response) assigns a panel digital forensics and incident response (DFIR) firm. This firm determines how the attacker got in, what was accessed or exfiltrated, whether the encryption can be reversed without paying, and what needs to be rebuilt. This step typically starts within 24-48 hours of the hotline call.

4

Negotiation decision

In parallel with forensics, if a ransom demand exists, the insurer's panel negotiator makes contact with the threat actor — first to establish proof of ability to decrypt, then to negotiate the amount if the business and insurer decide to pursue payment as an option. This is a distinct decision point: engaging a negotiator to understand options is not the same as committing to pay.

5

Recovery

Whether or not a ransom is paid, recovery typically combines restoring from clean backups where possible, rebuilding compromised systems from scratch rather than trusting a "cleaned" but previously compromised machine, and testing any decryption tool obtained through payment on sample files before relying on it broadly.

6

Business interruption calculation

A forensic accountant, often also insurer-appointed, calculates the income the business lost while systems were down, using historical financial records to establish what revenue would have looked like absent the incident, compared against what actually happened during the outage period.

7

Claim closeout

Once forensics, recovery, notification obligations, and business interruption calculations are finalized, the insurer issues payment against each covered cost category, applying the relevant deductibles and any sublimits — and the claim is formally closed, sometimes months after the initial incident for larger, more complex cases.

📊 IT Cares field note: The businesses that come through a ransomware claim with the least friction are almost always the ones that had the breach hotline number posted somewhere physical — not buried in a PDF on a server that's now encrypted. If your incident response plan lives only on the network that just got hit, it isn't much of a plan during the two hours that matter most.

In the middle of a ransomware incident right now?

IT Cares provides emergency ransomware removal and containment support while your insurer's process gets underway — call now, day or night.

What's Typically COVERED Under a Ransomware Cyber Insurance Policy

Coverage varies by carrier and policy tier, but the following cost categories appear, in some form, on the large majority of Canadian cyber policies that include ransomware/cyber extortion coverage. Reading your own declarations page against this list is the fastest way to spot a gap before you need it.

Incident response and forensics costs

The cost of the DFIR firm's investigation — determining the attack's entry point, scope, whether data was exfiltrated, and what needs to be rebuilt — is one of the most consistently covered line items. This work is billed hourly by specialized forensic investigators and can add up quickly, which is exactly why this coverage matters; a moderately complex investigation for a 40-50 person business commonly runs into the tens of thousands of dollars before recovery work even begins.

Ransom negotiation and, where legal, the ransom payment itself

Most policies with cyber extortion coverage will pay a professional negotiator's fees to engage the threat actor, and will reimburse the ransom payment itself, subject to a specific extortion sublimit (often lower than the overall policy limit — more on that below) and subject to sanctions screening clearing the payment as legal.

Data restoration costs

The cost of restoring data and rebuilding systems — whether from clean backups, from a decryption tool obtained through payment, or a combination of both — is typically covered, including the technical labour involved in verifying restored data integrity.

Business interruption and lost income

Income the business lost while systems were down or degraded, calculated against a documented historical baseline, is a standard covered category, usually subject to a waiting period (commonly 6-12 hours) before the clock on covered losses starts running.

Breach notification costs

The cost of notifying affected individuals as required under PIPEDA and applicable provincial privacy legislation — printing, mailing, call centre setup for inbound questions — is typically covered, since these costs are a direct, predictable consequence of most ransomware incidents that involve data exposure.

Credit monitoring for affected individuals

Where personal information was exposed, many policies cover the cost of offering affected individuals a period (commonly 12-24 months) of credit monitoring or identity theft protection services, which has become close to a market-standard response following a breach involving personal data.

Legal costs

Breach coach and legal counsel fees — for navigating notification obligations, regulator communication, and any resulting liability exposure — are typically covered as part of the incident response process, and in fact the breach coach is often the one coordinating the entire response on the insurer's behalf.

PR and crisis communications

Many policies include coverage for a crisis communications consultant to help manage public-facing and client-facing messaging during and after an incident, recognizing that how a business communicates about a breach materially affects client retention and reputational damage afterward.

Hardware "bricking" in some newer policies

A small but growing number of policies now include limited coverage for hardware that is rendered permanently unusable ("bricked") by certain forms of malware — historically a grey area, since older policies were written before this specific damage pattern became common. If hardware replacement matters to your risk profile, it's worth asking your broker directly whether your policy addresses bricking explicitly, since silence in the policy wording often means it isn't covered.

Exclusions That Catch Policyholders Off Guard

This is the section most cyber insurance guides skip, and it's arguably the most important one. Coverage lists look reassuring right up until a specific exclusion clause is the reason a claim gets denied or reduced. These are the exclusions Canadian businesses run into most often.

The war / nation-state exclusion clause

Most commercial insurance policies, cyber included, have historically excluded losses arising from acts of war. As ransomware and destructive cyberattacks have increasingly been attributed by governments and threat intelligence firms to state-linked or state-sponsored actors, insurers have leaned more heavily on this clause — and it has become genuinely contested territory. Some carriers now use narrower "cyber war" endorsements with specific carve-backs for ransomware regardless of attribution, while others retain broader war exclusion language that could, in theory, be invoked if an attack is later attributed to a nation-state-linked group, even when the attack itself looked like ordinary criminal ransomware at the time it happened. This is one of the clauses most worth having your broker walk you through line by line, because the practical difference between policies here can be significant.

Pre-existing or known unpatched vulnerabilities

If an insurer's forensic investigation determines that the attacker exploited a vulnerability your organization already knew about — flagged in a prior security assessment, a vendor advisory, or an internal ticket — and had not remediated within a reasonable window, some policies exclude or limit coverage for that specific incident, treating it as a known, unaddressed risk rather than a covered fortuitous event.

Failure to maintain warranted minimum security controls

Many policies are written with specific "warranties" — attestations you made on the application about MFA, EDR, or backup practices — that become conditions of coverage. If forensics later determines a warranted control wasn't actually in place at the time of the attack, the insurer can void coverage for the claim, even where that specific missing control wasn't the entry point the attacker used. This is one of the single most common causes of denied or reduced ransomware claims in the Canadian market today.

Acts by a current or former employee

Insider-driven incidents — a disgruntled current employee, or a former employee whose access wasn't fully revoked — are frequently subject to a separate carve-out or reduced sublimit distinct from external-attacker ransomware coverage, since the risk profile and preventability are treated differently by underwriters.

Contractual liability assumed beyond what the law would otherwise require

If your business signed a client or vendor contract promising security obligations, breach notification timelines, or liability terms stricter than what Canadian law would otherwise impose, most cyber policies exclude the incremental liability created by that contract — coverage generally responds to your legal obligations, not to obligations you voluntarily agreed to that go beyond them.

Prior known incidents not disclosed at application

If your business experienced a prior cyber incident — even a minor one — and didn't disclose it when applying for or renewing the policy, a subsequent related claim can be denied on grounds of material non-disclosure, regardless of whether the earlier incident seemed insignificant at the time.

Betterment

Coverage generally restores you to your pre-incident state, not beyond it. If your forensics firm recommends replacing an entire legacy server environment as part of recovery rather than simply rebuilding what was there, the incremental cost of that upgrade — the "betterment" — is typically excluded unless you've purchased a specific betterment endorsement.

Ransomware/extortion sublimits lower than the overall policy limit

This is one of the most frequently misunderstood parts of a cyber policy. A business might carry $2 million in overall cyber coverage but discover, only when it matters, that the ransomware/cyber extortion sublimit is capped at $250,000 or $500,000 — a fraction of the headline number quoted at renewal. Always ask specifically for the extortion sublimit figure, not just the overall policy limit, since these are frequently two very different numbers.

Coverage Scenario Comparison

ScenarioTypically Covered?Typical Reason
Standard ransomware attack via phishing email, no prior warnings Yes Core covered peril; forensics, negotiation, restoration, and business interruption all typically apply
Ransom payment to a wallet later linked to a sanctioned entity No / payment blocked Sanctions screening prevents facilitation regardless of insurance; payment itself may be unlawful
Attack exploiting a VPN vulnerability flagged 6 months earlier, unpatched Often denied or reduced Known, unremediated vulnerability exclusion
MFA claimed on application but not actually enforced at time of attack Often denied Material misrepresentation / breached warranty
Attack traced to a former employee's un-revoked VPN credentials Reduced / separate sublimit Insider-threat carve-out applies
Business interruption during the policy's waiting period (first 6-12 hrs) Not covered for that window Standard waiting period before business interruption coverage begins
Full server replacement recommended instead of simple rebuild Partial — incremental cost excluded Betterment exclusion applies to the upgrade portion
Ransom demand of $800,000 against a $250,000 extortion sublimit Partial — capped Extortion sublimit lower than overall policy limit
Prior minor incident 18 months ago, undisclosed at renewal Denied Material non-disclosure at application

Outcomes vary by carrier, policy wording, and jurisdiction. This table illustrates general patterns commonly reported by Canadian brokers and incident responders, not a guarantee of how any specific claim will be adjudicated.

Ransom Paid or Not: The Real Considerations

Whether to pay a ransom is, legally, the policyholder's decision — not the insurer's — even though the insurer's panel negotiator and forensics findings heavily inform it. Several factors matter more than most business owners expect going in.

Sanctions screening can make payment illegal regardless of insurance

Canadian economic sanctions, administered under the Special Economic Measures Act and related regulations, prohibit dealing with designated persons and entities. Many ransomware groups have documented or suspected links to sanctioned states or organizations, and both Canadian and U.S. regulators — including the U.S. Treasury's Office of Foreign Assets Control (OFAC), whose guidance Canadian insurers and their payment facilitators also screen against given the cross-border nature of cyber insurance underwriting — treat facilitating payment to a sanctioned party as a serious compliance violation. In practice, this means your insurer's negotiator runs sanctions and threat-actor attribution screening before facilitating any payment, and a payment can be blocked entirely if that screening can't clear the receiving wallet address, regardless of how much you want to pay to get your data back.

Canadian law enforcement guidance discourages payment but doesn't ban it

The RCMP and the Canadian Centre for Cyber Security both consistently advise against paying ransoms, on the grounds that payment funds further criminal activity and provides no guarantee of full recovery. Neither body prohibits payment outright for private businesses, and this remains a business decision rather than a legal requirement — but their guidance is a factor most insurers and breach coaches will raise explicitly during the negotiation-decision conversation, and it's worth taking seriously rather than treating as boilerplate caution.

Decryption doesn't guarantee full data integrity

Even a legitimate, working decryption key provided after payment frequently produces incomplete or corrupted results, particularly for databases, large file structures, and applications with complex internal file relationships. Forensics firms typically test decryption against a representative sample before relying on it across the full environment, and it's common for a percentage of files — sometimes a meaningful percentage — to remain unrecoverable even after a "successful" payment and decryption.

No guarantee the data won't be leaked anyway (double extortion)

Modern ransomware groups overwhelmingly run double-extortion attacks: encrypting data on-site while also exfiltrating a copy before encryption, then threatening to publish the stolen data separately from the decryption demand. Paying for decryption is a different transaction from any promise not to leak stolen data, and there's no reliable enforcement mechanism for a criminal group's word on the second point. This is precisely why Canadian privacy guidance treats exfiltrated data as compromised regardless of whether a ransom was paid — notification obligations under PIPEDA typically apply either way.

The Insurer-Appointed Negotiator and Incident Response Firm

Most Canadian cyber policies require that incident response, forensics, and negotiation be handled through the insurer's approved panel of vendors — pre-vetted firms the carrier has an existing relationship and fee structure with — rather than a vendor of your own choosing, and using an outside provider instead can mean those costs aren't reimbursed, or are only reimbursed up to what the panel firm would have charged for equivalent work.

This isn't simply a bureaucratic hurdle. Panel firms specialize in exactly this work, have existing relationships with ransomware negotiation intermediaries, and know which threat actor groups have historically honoured decryption promises versus which have taken payment and disappeared or re-attacked. That specialized knowledge genuinely affects outcomes — a negotiator who has dealt with a specific ransomware group's affiliate program before knows roughly what discount off the initial demand is realistic and how the group typically behaves post-payment, information a generalist IT provider simply doesn't have.

Negotiation itself typically follows a pattern: initial contact establishes proof of decryption capability (the attacker decrypts a small sample of files to demonstrate the key works), then negotiation on price follows, often achieving a meaningful reduction from the initial demand — industry reporting has repeatedly shown initial demands reduced by 40-60% or more through skilled negotiation, though outcomes vary considerably by threat actor group and case specifics. Panel negotiator fees are typically billed either as a flat engagement fee in the range of a few thousand dollars, a percentage of the negotiated reduction (commonly 10-20%), or some hybrid of the two, and this fee is itself usually a covered cost under the policy separate from the ransom payment itself.

Your own IT provider doesn't get shut out of this process entirely — in practice, they typically remain closely involved supporting the panel firm, handling day-to-day operational continuity, and providing environment-specific context the outside forensics team doesn't have. But the lead investigative and negotiation role usually needs to run through the insurer's approved vendor for those specific costs to be reimbursed under the policy.

Three Canadian Business Case Studies

Case Study 1 — Precision Components Manufacturer, Winnipeg, Manitoba

A 48-employee precision parts manufacturer near Winnipeg was hit by a ransomware attack that encrypted its production scheduling system and financial records, with a ransom demand of $340,000 CAD. The company notified its insurer's breach hotline within three hours of detection. The insurer's panel forensics firm confirmed the attacker's initial access came through a phishing email with no prior known-vulnerability exposure, clearing the way for full coverage. The panel negotiator engaged the threat actor, confirmed the demand wasn't linked to a sanctioned entity, and negotiated the payment down to $142,000 CAD. Total claim breakdown: forensics investigation $38,000 CAD, negotiator fee $21,000 CAD, negotiated ransom payment $142,000 CAD, data restoration and system rebuild $54,000 CAD, business interruption for six days of reduced production $96,000 CAD, breach notification and credit monitoring for 1,400 affected individuals $31,000 CAD — a total incident cost of roughly $382,000 CAD, of which the company's out-of-pocket exposure after its $25,000 deductible was limited to the deductible itself, since the claim fell within policy limits.

Case Study 2 — Accounting Firm, Montreal, Quebec

A 30-person accounting firm in Montreal suffered a ransomware attack that encrypted client tax files and internal financial records. The insurer's forensics investigation determined the attacker had exploited a known vulnerability in the firm's VPN appliance — a vulnerability a security assessment commissioned by the firm eight months earlier had specifically flagged as needing an urgent patch, which had not been applied. Under the policy's known-vulnerability exclusion, the insurer denied coverage for the ransom negotiation and payment portion of the claim entirely, while still covering forensics investigation costs (which the policy treated as a covered cost regardless of cause) and a portion of the breach notification costs required under PIPEDA and Quebec's Law 25. The firm ultimately paid a negotiated ransom of $95,000 CAD entirely out of pocket, on top of the roughly $60,000 CAD in partially covered response costs, turning what should have been a largely insured event into a costly lesson about closing flagged vulnerabilities before, not after, renewal.

Case Study 3 — Small Municipal Recreation Authority, Ontario

A small, arms-length recreation and community facilities authority serving a rural Ontario township, with 19 staff and no standalone cyber insurance policy — the board had deferred the purchase decision two years running as a discretionary line-item cut — was hit by ransomware that encrypted its registration, billing, and facility-booking systems just before the start of summer program registration. With no insurer, no breach hotline, and no panel forensics firm, the authority's part-time IT contractor worked with a local firm found through an emergency web search, at an hourly rate roughly 40% higher than typical panel rates due to the rushed, non-negotiated engagement. Recovery took eighteen days rather than the five to seven typical of an insured, panel-supported incident, during which the authority could not process online registrations or payments, losing an estimated $58,000 CAD in program revenue during peak sign-up season. Total self-funded recovery cost, including emergency IT contractor fees, a rebuilt server environment, and a manual, paper-based registration workaround staffed by overtime hours, came to approximately $187,000 CAD — funded through an emergency reserve fund draw that left the authority's capital reserve depleted for planned facility maintenance the following year. The contrast with Case Studies 1 and 2 is stark: even the accounting firm's partially denied claim still had forensics and part of its notification costs covered and a structured, panel-supported process to follow; the recreation authority had neither, and paid the difference in both dollars and elapsed downtime.

Checklist: First 24 Hours of a Ransomware Attack While a Claim Is Open

Quick Checklist: First 24 Hours

  • ☐ Isolate affected systems immediately — disconnect network cables, disable Wi-Fi, do not power off encrypted machines (memory can hold forensic evidence)
  • ☐ Call your cyber insurer's 24/7 breach hotline number — find it now, before an incident, and keep it somewhere outside your network
  • ☐ Do not attempt to negotiate with or pay the attacker directly before speaking with your insurer and panel negotiator
  • ☐ Do not wipe or reimage any system before the forensics firm has had a chance to preserve evidence
  • ☐ Photograph or screenshot the ransom note and any attacker communication before it's lost
  • ☐ Preserve firewall, VPN, and authentication logs — do not let automatic log rotation overwrite them
  • ☐ Identify and isolate your backups; confirm whether they were also encrypted or remain clean
  • ☐ Notify your internal incident response team using the pre-written plan (not from memory, not improvised)
  • ☐ Loop in legal counsel or your insurer's breach coach before making any public or client-facing statement
  • ☐ Begin a written incident timeline log — who was notified, when, and what actions were taken — for the claim file
  • ☐ Do not discuss specific dollar figures or negotiation strategy on channels the attacker might still have access to (compromised email, chat systems)

Budget & Pricing: What a Ransomware Claim Actually Costs in Canada

Concrete numbers help set realistic expectations, both for what an incident costs and for how ransomware/extortion sublimits are typically priced relative to the overall policy.

Ransomware/extortion sublimits are typically priced and structured as a defined percentage of the overall cyber policy limit — commonly somewhere in the 25%-100% range depending on carrier and industry — rather than matching the headline limit automatically. A business carrying $1 million in overall cyber coverage might find its extortion sublimit set anywhere from $250,000 to the full $1 million, and that specific figure is negotiable at renewal in many cases, particularly for businesses that can demonstrate strong preventive controls. Because the extortion sublimit is so often lower than assumed, it's worth asking your broker for that specific number in writing every renewal cycle rather than relying on last year's understanding.

Deductibles for cyber policies with ransomware coverage typically range from $5,000 CAD for a small business with a modest coverage limit up to $50,000-$100,000 CAD or more for larger mid-market accounts, and — as illustrated in the Winnipeg case study above — the deductible, not the full incident cost, is usually the actual number a well-insured business ends up paying out of pocket when a claim is fully covered.

Canadian Government & Regulatory Resources

Several federal bodies play a direct role during and after a ransomware incident, independent of your insurance claim, and understanding their roles ahead of time removes friction during an actual event.

If you'd like a professional assessment of where your current defenses stand against exactly what insurers now expect — or if you're dealing with an active infection and need it removed and contained properly — our ransomware and virus removal service and our security audit service are built specifically around these situations, and our cybersecurity services page covers ongoing protection so you're less likely to need either one again.

Frequently Asked Questions

Is paying a ransom illegal in Canada?
Paying a ransom is not, by itself, a crime under Canadian federal law the way it can be treated in some other jurisdictions. However, it can become illegal in specific circumstances — most notably if the payment ends up in the hands of an individual, group, or wallet address that is subject to Canadian economic sanctions (administered under the Special Economic Measures Act and related regulations) or that appears on comparable United States OFAC sanctions lists that Canadian insurers and their payment facilitators also screen against. Because attackers rarely announce their affiliations, insurers and their panel negotiators run sanctions screening before facilitating any payment, and a payment can be refused or delayed specifically because that screening cannot clear the receiving wallet.
Will my insurer force me to pay the ransom?
No reputable Canadian cyber insurer can force a policyholder to pay a ransom; the decision to pay legally rests with the insured business. What most policies do require is that you notify the insurer promptly and use their approved incident response and negotiation panel before making that decision, and many policies condition ransom payment coverage on the insurer's prior consent. In practice, insurers strongly influence the decision through their panel negotiator's recommendation and through what they will or won't reimburse, but the final choice to pay or not pay remains the policyholder's.
Does cyber insurance cover a second attack after we already paid once?
It depends on your policy's structure and whether the second attack is treated as a separate incident or a continuation of the first. Many policies apply per-occurrence limits and deductibles, meaning a genuinely separate, later attack by a different threat actor is typically treated as a new claim against your full policy limits. However, if the same attacker retains access and strikes again shortly after a payment, some insurers may treat it as part of the same ongoing incident, which can affect how the claim is adjusted. This is precisely why insurers and forensics firms insist on a full environment rebuild rather than just decryption after a ransomware event — leaving old access in place is what enables repeat attacks.
What if we didn't have MFA when we said we did on the application?
This is one of the most common reasons a ransomware claim gets denied or reduced. If the insurer's forensics investigation determines that a control you attested to on the application — MFA, EDR, tested backups — was not actually in place at the time of the attack, the insurer can invoke a material misrepresentation or warranty breach clause and deny the claim in whole or in part, even if that specific gap wasn't the entry point the attacker used. Insurers increasingly verify these attestations forensically after a claim is filed, so an inaccurate application answer that seemed harmless at the time can surface at the worst possible moment.
Does cyber insurance cover the cost of upgrading our systems after a ransomware attack?
Generally not beyond restoring you to your pre-incident state. Most policies explicitly exclude betterment, meaning if your forensics firm recommends replacing an entire legacy server fleet or migrating to a fundamentally more secure architecture as part of recovery, the incremental cost of that upgrade — beyond what it would have cost to simply restore what you had — is typically your business's responsibility, not the insurer's. Some carriers offer optional betterment endorsements for an additional premium, so it's worth asking your broker directly whether that's available.
Will using my own IT provider instead of the insurer's panel firm affect my claim?
Very likely, yes. Most Canadian cyber policies require that incident response, forensics, and negotiation services be provided by vendors on the insurer's pre-approved panel, and using an outside provider instead can result in those costs not being reimbursed, or being reimbursed only up to what the panel firm would have charged. This doesn't mean your regular IT provider is shut out of the process entirely — they typically stay involved supporting the panel firm and handling day-to-day operations — but the lead forensics and negotiation role usually needs to go through the insurer's approved vendor for those costs to be covered.
Is decryption after paying a ransom guaranteed to restore all our data?
No. Even when a ransom is paid and a decryption key is provided, decryption tools supplied by criminal groups are frequently slow, incomplete, or produce corrupted files, particularly for databases and large, complex file structures. Forensics firms typically test decryption on a sample of files before certifying it usable, and even a technically working key does not guarantee full data integrity across every affected system. This is a core reason cyber insurance covers data restoration costs as a separate line item from any ransom payment itself — the two are not the same recovery step.
Does paying a ransom guarantee the stolen data won't be leaked?
No. In double-extortion attacks, where data is both encrypted and exfiltrated before encryption, paying for a decryption key is a separate transaction from any promise not to leak the stolen data, and there is no reliable mechanism to enforce a criminal group's promise to delete or not publish stolen data even after payment. Canadian privacy regulators, including the Office of the Privacy Commissioner of Canada, advise treating exfiltrated data as compromised regardless of payment, which is why breach notification obligations under PIPEDA typically apply whether or not a ransom was paid.

Not Sure What Your Policy Actually Covers?

IT Cares helps Canadian businesses understand their real security gaps against what cyber insurers now expect — and provides emergency ransomware removal and containment support if you're facing an active incident today.

Comments (3)

DL
Daniel L., Winnipeg
July 23, 2026

We went through almost this exact process last year. The part about the panel negotiator knowing which groups actually honour decryption keys was very true in our case — made a real difference.

SF
Sophie F., Montreal
July 21, 2026

The unpatched-vulnerability exclusion is exactly what tripped up a colleague's firm. Wish more people understood this before renewal, not after a claim gets denied.

TW
Tyler W., Barrie
July 19, 2026

The extortion sublimit point needs way more attention. We assumed our full policy limit applied to a ransom and were surprised to learn it was capped much lower.

Leave a Comment

Need Help?