Back to blog

Ransomware: does cyber insurance pay the ransom? What the policies really say

French legal framework (LOPMI, complaint within 72 hours), reimbursement conditions, included crisis management and indemnified downtime.

Loïc Carbonne·8 min read

Yes, ransomware insurance can pay the ransom: paying is not prohibited in France, and most cyber policies include a "cyber extortion" cover that reimburses the sum handed over. But that reimbursement is conditioned by law (a criminal complaint filed within 72 hours), by the policy (the insurer's prior approval, a sublimit, sanctions screening) and by market reality, where the ransom is almost never the most expensive line of an attack. What really matters is crisis management and how fast you get back to work.

Nothing in French law forbids a company hit by ransomware from paying. The victim is legally the person being extorted under Article 312-1 of the Penal Code, not an accomplice. The authorities strongly advise against it: the response sheet published by Cybermalveillance.gouv.fr recommends not paying, because nothing guarantees data recovery, stolen data may still be leaked after payment, and every ransom funds the next attack.

Two limits turn this freedom into a grey area: international sanctions (sending funds to a group listed by the European Union or the US OFAC exposes the company, and its insurer, to prosecution) and terrorism financing (Article 421-2-2 of the Penal Code). In practice, no insurer reimburses a ransom without first checking the identity of the attacking group.

What does the LOPMI law say about insurers reimbursing ransoms?

The Interior Ministry orientation and programming law (LOPMI) of 24 January 2023 settled a debate that had lasted several years. Its Article 5 created Article L12-10-1 of the Insurance Code, in force since 24 April 2023: any indemnity paid for an attack on an automated data processing system is conditional on the victim filing a criminal complaint no later than 72 hours after becoming aware of the attack.

The text legitimises ransom reimbursement by insurers, by giving it a legal framework, and turns it into a lever for investigators: without a complaint within 72 hours, the insurer may refuse any indemnity, not just the ransom but also remediation costs and business interruption losses. It applies to legal entities and professionals, not to private individuals.

An attack on an automated data processing system (STAD, in French legal terminology) is the criminal qualification of Articles 323-1 to 323-7 of the Penal Code: fraudulent access to an IT system, obstructing its operation, modifying data. It covers intrusion, encryption and exfiltration, in other words the whole of a ransomware attack.

What does a policy's cyber extortion cover actually pay for?

Cyber extortion cover is the part of a cyber policy that pays for the consequences of a digital extortion threat: the fees of a specialised negotiator, investigation costs to identify the attacker, and reimbursement of the ransom if the insurer has given prior approval. It almost always comes with a sublimit, a maximum amount lower than the policy's overall limit, specific to this type of claim.

For a ransom to be reimbursed, French policies generally require five cumulative conditions: a complaint filed within 72 hours, the insurer's written approval before any payment, screening of the attacking group against sanctions lists, traceability of the cryptocurrency flow and anti-money-laundering checks (with a report to Tracfin where required). A policy with an overall limit of €500,000 may thus cap cyber extortion at €50,000.

Element of the cyber policyWhat to look atSME order of magnitude 2026
Overall limitAmount per claim and per year€500,000 to €1.5M
Cyber extortion sublimitRansom + negotiator + investigation10% to 100% of the limit depending on insurer
DeductibleAmount retained per claim€500 to €2,500
Business interruption waiting periodHours of downtime not indemnified8 to 24 hours depending on policy
Annual premium (10 to 50 employees)Excluding options€1,000 to €5,000

Why is the ransom not the real cost of a ransomware attack?

Because the figures show it. In the Sophos "State of Ransomware 2026" survey (2,158 organisations hit across 17 countries), 48% of encrypted victims paid, for a median ransom of $769,000, but the average rebuild cost, excluding the ransom, reached $1.7 million. Coveware reports a median payment of $150,000 in the second quarter of 2026 and a payment rate at a record low. In France, the median cost of a cyberattack for an SME is estimated at €50,000 (Astérès for MEDEF), with the average pulled towards €450,000 by severe incidents.

In other words, the question "does the insurer pay the ransom?" hides the real question: who pays for the weeks your servers and ERP are down, the forensic experts, the lawyers, the notification to the CNIL and the rebuild of your information system?

A ransom is negotiated in a few days; a company stopped for three weeks with no recovery plan is not negotiated, it is lost.

How does the crisis management included in a cyber policy work?

It is the most useful part of the policy, and the most underestimated. A serious cyber policy gives you 24/7 access to a hotline that, within hours, mobilises an incident response team: forensic experts, specialised lawyers for the CNIL notification within 72 hours (Article 33 GDPR), a negotiator if contact with the attacker is considered, crisis communication.

Incident response is the set of technical and organisational actions taken from the moment an attack is detected: isolating compromised machines, preserving evidence, analysing the attacker's method, eradicating them and restoring systems. Carried out by seasoned specialists, it shortens downtime and avoids the classic mistake of reinstalling too quickly and destroying the evidence needed for the complaint and the insurance assessment.

ANSSI's 2025 cyber threat overview is a reminder of how exposed mid-sized companies are: of the 128 ransomware attacks it handled in 2025, 37% targeted very small, small and mid-sized businesses, and incidents involving exfiltration rose from 130 to 196 in one year. Even once restored, the company then has to manage the threat of publication and its obligations towards the people concerned.

How much downtime does your policy really indemnify?

Cyber business interruption cover indemnifies lost gross margin and the extra costs incurred during downtime, but only beyond a waiting period expressed in hours (often 8, 12 or 24 hours) and within an indemnity period (usually 3 to 12 months). According to Sophos, 53% of victims in 2025 were back up within a week, which leaves almost one victim in two beyond that.

Three questions to ask before signing: from how many hours of downtime am I indemnified? On what basis (gross margin, extra costs)? Does the cover extend to an outage at my hosting provider or a critical SaaS vendor? A SaaS scale-up whose platform goes down also faces the service-level penalties written into its client contracts, which we detail in our analysis of SLAs.

What conditions does the insurer impose to accept the ransomware risk?

The market has softened for those who document their security: AMRAE's LUCY 2026 study records premium reductions of up to 32% for large companies, but claims amounts up 53% and the number of claims multiplied by four among mid-caps. Insurers therefore only cover extortion after checking three prerequisites: multi-factor authentication on remote access and administrator accounts, EDR on workstations and servers, and tested offline or immutable backups.

Immutable backups are copies of data locked against writing for a set period, which no account, not even an administrator, can modify or delete; they are the only guarantee of restoring without paying when the attacker has encrypted production. Their absence is the leading reason for refusal or exclusion of cyber extortion cover. If your SME falls within the scope of NIS2, these same measures are now regulatory obligations, as we explain in our NIS2 and DORA guide.

Frequently asked questions

Will the insurer reimburse the ransom if I pay without telling them?

Almost never. Policies require the insurer's prior written approval, so that it can check the recipient is not under sanctions and bring in a negotiator. Paying on your own means giving up reimbursement, and running the risk of paying a sanctioned group.

What happens if I file the complaint after 72 hours?

Article L12-10-1 of the Insurance Code allows the insurer to refuse any indemnity, including remediation costs and business interruption losses. The clock starts when the victim becomes aware of the attack; file the complaint as soon as you detect it, without waiting for the technical findings.

Does a cyber policy cover data loss if I refuse to pay?

Yes: the costs of restoring, rebuilding systems and reconstituting data fall under the policy's "first-party costs" section, regardless of any ransom. That is why tested offline backups are required at underwriting.

Does my business property policy already cover ransomware?

Rarely, and ambiguously: the ACPR has flagged the "silent" cyber cover found in non-dedicated policies, which insurers now exclude or cap. Only a dedicated cyber policy offers crisis management, cyber extortion and digital business interruption cover.

At Lesto, we read cyber policy wordings line by line, extortion sublimit, waiting period, scope of crisis management, before approaching an average of nine insurers for your file. Want to know what your policy would really pay the day an attacker encrypts your servers? Discover our cyber insurance offer and request a 72-hour analysis.

Recommended coverage

Our offers

The coverages we recommend most often to businesses.

Tags

  • #ransomware
  • #cyber insurance
  • #cyber extortion
  • #LOPMI
  • #crisis management
Loïc Carbonne

Loïc Carbonne

CTO

Loïc is passionate about tech, code and artificial intelligence. He is building the platform that allows Lesto's clients to be properly insured.

LinkedIn →