Skip to content
InsureMax

Cyber Insurance

Ransomware and Business Interruption: How Cyber Claims Actually Pay Out

Waiting periods, period of restoration, forensic accounting, and the documentation that decides how much of a ransomware outage your insurer reimburses.

Jordan Mahoney··9 min read

The headline number in a ransomware event is the demand. The number that actually determines the financial outcome is business interruption — how many days the business could not trade, and how much of that the policy reimburses.

Median small-business downtime from a ransomware event is around 20 days even when backups exist, because restoration is slower than most recovery plans assume. This piece walks through how a business interruption claim is calculated and where claims lose value.

The waiting period is a deductible measured in hours

Cyber business interruption starts after a waiting period, usually 8, 12, or 24 hours from the point the outage begins. Losses inside that window are never reimbursed, regardless of severity.

For a business that trades continuously, a 24-hour waiting period on a $40,000-per-day revenue base is a $40,000 uninsured deductible. Buying down to 8 hours typically costs little and is one of the highest-value negotiation points in the policy.

The clock starts at the outage, not at discovery, so accurate logging matters. Establish and document the timeline immediately.

Period of restoration: when does the payout stop?

The policy pays for the period of restoration — from the end of the waiting period until systems are restored, subject to a maximum, commonly 30, 60, 90, or 180 days.

Better wordings add an extended period of indemnity of 30 to 90 days, covering the tail during which revenue is still depressed after systems are back. Customers do not return the day the servers do, and for service businesses the tail is often larger than the outage itself.

If your policy lacks an extended indemnity period, ask for it. It is generally an inexpensive endorsement and closes the most commonly disputed part of the claim.

How the loss amount is calculated

The insurer calculates net income the business would have earned but for the incident, plus continuing operating expenses such as rent and payroll that ran during the outage.

This is derived from historical financials, usually 12 to 24 months of monthly management accounts, adjusted for trend and seasonality. A business with clean monthly accounts and a stable trend gets a clean calculation; one with erratic bookkeeping gets a conservative one.

Extra expense — overtime, temporary hardware, manual workarounds, expedited vendor fees — is reimbursed separately, but generally only up to the amount of loss it avoided. Keep every invoice and record the rationale at the time.

The first 48 hours determine most of the outcome

Notify the insurer's incident hotline before engaging any vendor. Costs incurred with firms outside the insurer's approved panel are frequently non-reimbursable, and this catches out businesses whose instinct is to call their existing IT provider first.

Preserve evidence: do not wipe and rebuild affected systems before forensics has imaged them. Forensic findings drive both the notification obligation and the claim, and a destroyed evidence trail hurts both.

Start a contemporaneous incident log with timestamps — who was told what, when systems went down, when each service came back. Forensic accountants will reconstruct the loss from this, and reconstructing it six weeks later from memory reliably understates it.

Why claims get reduced

Control warranty breaches are the leading cause. If the application stated MFA was enforced on all remote access and it was not on one legacy account, insurers may reduce or deny. Answer application questions with verified fact, not intent.

Late notification is second. Claims-made policies impose strict notice deadlines, sometimes as short as 72 hours for a security incident.

Third is inadequate financial documentation — a business that cannot demonstrate what it would have earned receives the insurer's conservative estimate. Keeping monthly management accounts is, in effect, a cyber control.

What to do before an incident to protect the claim

Test restoring from backup, end to end, and record the date and result. Insurers increasingly ask for evidence of a tested restore, and a tested restore also shortens the actual outage, which reduces the loss.

Keep an offline copy of your incident response plan, the insurer's hotline number, and your policy number. During a ransomware event your email, file shares, and CRM may all be inaccessible.

Run one tabletop exercise a year with your finance lead present. The finance function owns the business interruption claim, and it is almost always the least-rehearsed part of the response.

Frequently asked questions

How long does a ransomware outage typically last?

Median downtime for small businesses is around three weeks even where backups exist, because full restoration and validation take far longer than most plans assume.

What is a waiting period in cyber insurance?

A time-based deductible, usually 8–24 hours, before business interruption cover starts. Losses within that window are not reimbursed.

Can I use my own IT provider during a claim?

Often not without prior approval. Most policies require insurer-approved panel vendors, and unapproved costs may be excluded. Call the hotline first.

Does the policy cover lost revenue after systems are restored?

Only if it includes an extended period of indemnity, typically 30–90 days. Without that endorsement, cover ends when restoration ends.

Will an insurer deny a claim if my security was weak?

It can, where the application warranted controls that were not actually in place. Accuracy on the application is as important as the controls themselves.

Related reading