Yes, ransomware insurance can pay the ransom: paying is not prohibited in France, and most cyber policies include a "cyber extortion" cover that reimburses the sum handed over. But that reimbursement is conditioned by law (a criminal complaint filed within 72 hours), by the policy (the insurer's prior approval, a sublimit, sanctions screening) and by market reality, where the ransom is almost never the most expensive line of an attack. What really matters is crisis management and how fast you get back to work.
Is paying a ransom legal in France?
Nothing in French law forbids a company hit by ransomware from paying. The victim is legally the person being extorted under Article 312-1 of the Penal Code, not an accomplice. The authorities strongly advise against it: the response sheet published by Cybermalveillance.gouv.fr recommends not paying, because nothing guarantees data recovery, stolen data may still be leaked after payment, and every ransom funds the next attack.
Two limits turn this freedom into a grey area: international sanctions (sending funds to a group listed by the European Union or the US OFAC exposes the company, and its insurer, to prosecution) and terrorism financing (Article 421-2-2 of the Penal Code). In practice, no insurer reimburses a ransom without first checking the identity of the attacking group.
What does the LOPMI law say about insurers reimbursing ransoms?
The Interior Ministry orientation and programming law (LOPMI) of 24 January 2023 settled a debate that had lasted several years. Its Article 5 created Article L12-10-1 of the Insurance Code, in force since 24 April 2023: any indemnity paid for an attack on an automated data processing system is conditional on the victim filing a criminal complaint no later than 72 hours after becoming aware of the attack.
The text legitimises ransom reimbursement by insurers, by giving it a legal framework, and turns it into a lever for investigators: without a complaint within 72 hours, the insurer may refuse any indemnity, not just the ransom but also remediation costs and business interruption losses. It applies to legal entities and professionals, not to private individuals.
An attack on an automated data processing system (STAD, in French legal terminology) is the criminal qualification of Articles 323-1 to 323-7 of the Penal Code: fraudulent access to an IT system, obstructing its operation, modifying data. It covers intrusion, encryption and exfiltration, in other words the whole of a ransomware attack.
What does a policy's cyber extortion cover actually pay for?
Cyber extortion cover is the part of a cyber policy that pays for the consequences of a digital extortion threat: the fees of a specialised negotiator, investigation costs to identify the attacker, and reimbursement of the ransom if the insurer has given prior approval. It almost always comes with a sublimit, a maximum amount lower than the policy's overall limit, specific to this type of claim.
For a ransom to be reimbursed, French policies generally require five cumulative conditions: a complaint filed within 72 hours, the insurer's written approval before any payment, screening of the attacking group against sanctions lists, traceability of the cryptocurrency flow and anti-money-laundering checks (with a report to Tracfin where required). A policy with an overall limit of €500,000 may thus cap cyber extortion at €50,000.
| Element of the cyber policy | What to look at | SME order of magnitude 2026 |
|---|---|---|
| Overall limit | Amount per claim and per year | €500,000 to €1.5M |
| Cyber extortion sublimit | Ransom + negotiator + investigation | 10% to 100% of the limit depending on insurer |
| Deductible | Amount retained per claim | €500 to €2,500 |
| Business interruption waiting period | Hours of downtime not indemnified | 8 to 24 hours depending on policy |
| Annual premium (10 to 50 employees) | Excluding options | €1,000 to €5,000 |
Why is the ransom not the real cost of a ransomware attack?
Because the figures show it. In the Sophos "State of Ransomware 2026" survey (2,158 organisations hit across 17 countries), 48% of encrypted victims paid, for a median ransom of $769,000, but the average rebuild cost, excluding the ransom, reached $1.7 million. Coveware reports a median payment of $150,000 in the second quarter of 2026 and a payment rate at a record low. In France, the median cost of a cyberattack for an SME is estimated at €50,000 (Astérès for MEDEF), with the average pulled towards €450,000 by severe incidents.
In other words, the question "does the insurer pay the ransom?" hides the real question: who pays for the weeks your servers and ERP are down, the forensic experts, the lawyers, the notification to the CNIL and the rebuild of your information system?
A ransom is negotiated in a few days; a company stopped for three weeks with no recovery plan is not negotiated, it is lost.
How does the crisis management included in a cyber policy work?
It is the most useful part of the policy, and the most underestimated. A serious cyber policy gives you 24/7 access to a hotline that, within hours, mobilises an incident response team: forensic experts, specialised lawyers for the CNIL notification within 72 hours (Article 33 GDPR), a negotiator if contact with the attacker is considered, crisis communication.
Incident response is the set of technical and organisational actions taken from the moment an attack is detected: isolating compromised machines, preserving evidence, analysing the attacker's method, eradicating them and restoring systems. Carried out by seasoned specialists, it shortens downtime and avoids the classic mistake of reinstalling too quickly and destroying the evidence needed for the complaint and the insurance assessment.
ANSSI's 2025 cyber threat overview is a reminder of how exposed mid-sized companies are: of the 128 ransomware attacks it handled in 2025, 37% targeted very small, small and mid-sized businesses, and incidents involving exfiltration rose from 130 to 196 in one year. Even once restored, the company then has to manage the threat of publication and its obligations towards the people concerned.
How much downtime does your policy really indemnify?
Cyber business interruption cover indemnifies lost gross margin and the extra costs incurred during downtime, but only beyond a waiting period expressed in hours (often 8, 12 or 24 hours) and within an indemnity period (usually 3 to 12 months). According to Sophos, 53% of victims in 2025 were back up within a week, which leaves almost one victim in two beyond that.
Three questions to ask before signing: from how many hours of downtime am I indemnified? On what basis (gross margin, extra costs)? Does the cover extend to an outage at my hosting provider or a critical SaaS vendor? A SaaS scale-up whose platform goes down also faces the service-level penalties written into its client contracts, which we detail in our analysis of SLAs.
What conditions does the insurer impose to accept the ransomware risk?
The market has softened for those who document their security: AMRAE's LUCY 2026 study records premium reductions of up to 32% for large companies, but claims amounts up 53% and the number of claims multiplied by four among mid-caps. Insurers therefore only cover extortion after checking three prerequisites: multi-factor authentication on remote access and administrator accounts, EDR on workstations and servers, and tested offline or immutable backups.
Immutable backups are copies of data locked against writing for a set period, which no account, not even an administrator, can modify or delete; they are the only guarantee of restoring without paying when the attacker has encrypted production. Their absence is the leading reason for refusal or exclusion of cyber extortion cover. If your SME falls within the scope of NIS2, these same measures are now regulatory obligations, as we explain in our NIS2 and DORA guide.
Frequently asked questions
Will the insurer reimburse the ransom if I pay without telling them?
Almost never. Policies require the insurer's prior written approval, so that it can check the recipient is not under sanctions and bring in a negotiator. Paying on your own means giving up reimbursement, and running the risk of paying a sanctioned group.
What happens if I file the complaint after 72 hours?
Article L12-10-1 of the Insurance Code allows the insurer to refuse any indemnity, including remediation costs and business interruption losses. The clock starts when the victim becomes aware of the attack; file the complaint as soon as you detect it, without waiting for the technical findings.
Does a cyber policy cover data loss if I refuse to pay?
Yes: the costs of restoring, rebuilding systems and reconstituting data fall under the policy's "first-party costs" section, regardless of any ransom. That is why tested offline backups are required at underwriting.
Does my business property policy already cover ransomware?
Rarely, and ambiguously: the ACPR has flagged the "silent" cyber cover found in non-dedicated policies, which insurers now exclude or cap. Only a dedicated cyber policy offers crisis management, cyber extortion and digital business interruption cover.
At Lesto, we read cyber policy wordings line by line, extortion sublimit, waiting period, scope of crisis management, before approaching an average of nine insurers for your file. Want to know what your policy would really pay the day an attacker encrypts your servers? Discover our cyber insurance offer and request a 72-hour analysis.
Recommended coverage
Our offers
The coverages we recommend most often to businesses.
Professional Liability
When a client blames you for a mistake or a delay, legal fees pile up fast. Professional Liability picks up the bill for you.
DiscoverProperty Damage (BOP)
A fire or water damage can shut your premises overnight. This insurance pays for the repairs and keeps you afloat until you reopen.
DiscoverCyber
One morning your files are locked and a hacker demands a ransom. Cyber insurance pays for the recovery and the crisis response.
DiscoverTags
- #ransomware
- #cyber insurance
- #cyber extortion
- #LOPMI
- #crisis management

Loïc Carbonne
CTO
Loïc is passionate about tech, code and artificial intelligence. He is building the platform that allows Lesto's clients to be properly insured.
LinkedIn →