Botnet
A botnet is a network of internet-connected devices, such as computers, servers, mobile devices, and IoT devices, that have been infected with malware and are secretly controlled by an attacker. The person or group controlling the network, often called a bot-herder or botmaster, can direct all the compromised devices to act together. Because owners are usually unaware their devices are part of a botnet, these networks can be used to carry out large-scale malicious activity.
A botnet is a collection of compromised internet-connected hosts, each running one or more bots (automated malicious agents), placed under the coordinated command of an attacking party known as a bot-herder or botmaster. Initial compromise is commonly achieved through malware such as Trojan viruses that breach the security of multiple users' systems; the resulting fleet may span PCs, servers, mobile devices, and IoT devices. The controlling party issues instructions to the aggregated hosts to perform tasks at scale, including distributed denial-of-service (DDoS) attacks. The term derives from a contraction of "robot" and "network." This entry describes botnets as a threat and attack-infrastructure concept; it is not an insurance policy term, and whether losses arising from botnet activity are covered depends on the specific policy wording, endorsements, and exclusions.
Why it matters
Botnets concentrate the computing and network resources of many compromised devices under a single controlling party, which lets an attacker operate at a scale that no individual host could achieve. This makes botnets a foundational piece of attack infrastructure behind distributed denial-of-service (DDoS) campaigns and other automated abuse. For organizations, the risk is twofold: a business may be the target of botnet-driven activity, and its own inadequately secured devices, including servers and IoT devices, may be conscripted into a botnet without the owner's knowledge, potentially harming third parties.
For insurance and resilience purposes, it is important to keep the threat concept distinct from any coverage question. Whether losses arising from botnet activity, such as business interruption from a DDoS event, costs of incident response, or liability if your systems are used to attack others, are covered depends entirely on the specific policy wording, endorsements, exclusions, and conditions. Some policies address DDoS-related interruption through first-party coverage subject to waiting periods and sublimits, while liability to third parties would fall under different third-party sections; none of this can be assumed from the existence of the threat alone. Insurers and brokers should not treat a botnet incident as automatically triggering any particular coverage grant.
Botnets also illustrate why risk transfer through insurance is not a substitute for risk mitigation. Purchasing coverage does not reduce the likelihood that an organization's devices will be compromised and enrolled in a botnet, nor does it prevent a DDoS attack. Reducing exposure requires controls, such as patching, credential hygiene, and network defenses, that operate independently of any policy. Insurance may help finance certain consequences, but resilience against botnet-driven disruption depends on separate technical and operational measures.
Who it's relevant to
Inside Botnet
Common questions
Answers to the questions practitioners most commonly ask about Botnet.