Ransomware
Ransomware is a type of malicious software that locks up files or devices, usually by encrypting them, so the victim can no longer access their data or the systems that depend on it. Attackers typically demand a ransom in exchange for restoring access. Because it disrupts the availability of data and systems, ransomware can halt an organization's operations until the incident is resolved.
Ransomware is a category of malware that renders data or systems inaccessible, most commonly by encrypting files on affected devices, and conditions restoration of access on payment of a ransom. Some variants extend beyond encryption to withhold or threaten disclosure of exfiltrated data. The primary impact is to the availability (and, where data is stolen, the confidentiality) of information assets; the resulting operational disruption is what commonly intersects with cyber insurance considerations. Note that this entry defines the threat itself and does not address whether resulting losses are covered under any policy, which depends on the specific wording, endorsements, exclusions, and conditions of the applicable coverage.
Why it matters
Ransomware matters because it attacks the availability of data and systems directly: by encrypting files or locking devices, it can halt an organization's operations until the incident is resolved. This makes it distinct from threats that primarily compromise confidentiality without disrupting operations. For risk managers and resilience planners, the operational standstill is often the most immediate concern, since it can interrupt service delivery, revenue, and dependent business processes regardless of whether any ransom is ultimately paid.
Ransomware also sits at the intersection of first-party and third-party exposure. The insured's own losses may include business interruption, the cost of restoring or rebuilding data, and expenses tied to responding to extortion demands. Where attackers also exfiltrate data and threaten disclosure, the confidentiality of information assets is implicated as well, which can give rise to liability to affected individuals or regulatory scrutiny. Whether any of these losses fall within the scope of a given policy is a separate question entirely, and depends on the specific wording, endorsements, exclusions, and conditions of the applicable coverage rather than on the nature of the threat itself.
Who it's relevant to
Inside Ransomware
Common questions
Answers to the questions practitioners most commonly ask about Ransomware.