Here’s something I hear all the time from business owners: “We’ve got cyber insurance, so we’re covered.”
They say it the same way they’d say “we’ve got fire insurance,” like the policy itself is a firewall. Like buying coverage is the same as being protected.
It’s not. It never is. And I’m here to tell you exactly why, because I’ve walked clients through the insurance claims process after a ransomware attack, and what actually happens looks nothing like what most business owners think it does.
What You Picture vs. What Actually Happens
Most people imagine that when ransomware hits and you call your insurance company, some kind of elite response team mobilizes. Maybe a van shows up with ten cybersecurity specialists who take over your server room and start restoring everything while your legal team handles the paperwork.
That is not how it works.
Here’s what actually happens in the first 72 hours after you notify your insurance company that you’ve been hit.
You lose control of the process. The moment you file that claim, the insurance company is running the show. You don’t get to choose your attorney. They give you a list, and you pick from that list. You don’t get to choose your forensics company, either. Same deal. A list of pre-approved vendors that the insurance company has relationships with.
One of our clients had to pick a forensics company essentially at random because there was no time to vet anyone on the list. You’re hemorrhaging money (in this case, around $100,000 per day in lost revenue) and you’re scrolling through names you’ve never heard of, trying to make a decision that will define your recovery.
The forensics team is not what you expected. I’ll be honest, the forensics company our client ended up with was underwhelming. We expected a team of seasoned specialists who would hit the ground running. What we got was a remote engagement with people who needed us to hold their hands through parts of the process. We were guiding the forensics company at times, not the other way around. That’s not the “attack team of ten” you pictured.
Three days before recovery even starts. The forensics team has to assemble, get access to your environment, analyze the attack vector, determine what was compromised, and check for data exfiltration. That takes time. In our client’s case, it was three full days before we could even begin recovery. Three days. At $100,000 a day in lost production revenue. Do the math on that and tell me the insurance claim is going to make you whole.
Sub-Limits: The Fine Print That Destroys Your Payout
Now here’s the part that makes my blood pressure go up, because this is where business owners get absolutely blindsided.
You have a $4 million cyber insurance policy. Great. You feel good about that number. Your CFO signed off on it. Your board feels protected.
But have you read the sub-limits?
Your $4 million policy probably has a ransomware sub-limit of $100,000. Maybe $150,000 if you’re lucky. Data exfiltration? That might be capped at $50,000. Business interruption? There’s a sub-limit for that too, and it might not cover more than a few days of losses.
So your $4 million policy, in a real-world ransomware scenario, might pay out $150,000 to $200,000. Those sub-limits totally destroy your payout. And by the time you find out about them, you’re already in the middle of a crisis that’s costing you multiples of what the policy will cover.
Here’s the thing: the insurance company is not trying to help you recover. They’re trying to limit their exposure. And those sub-limits are how they do it.
What the Insurance Company Does After You File
So you’ve filed your claim. You’ve hired their attorney. You’ve engaged their forensics company. Recovery is underway, slowly, painfully, expensively. Now what?
They look for reasons not to pay. I don’t say this to be cynical. It’s just how insurance works. The insurance company is going to review your security posture and compare it to what you represented when you bought the policy. Did you say you had multi-factor authentication on all accounts? Did you actually? Did you say you had endpoint detection and response? Was it configured correctly? Was it on every machine?
If they find a gap between what you told them and what was actually in place, they have grounds to reduce or deny your claim. And after a breach, there are almost always gaps. Because the attackers got in somewhere, and that somewhere is going to be scrutinized.
They drop you. After the claim is processed, whether they paid in full, paid partially, or found reasons to deny, they drop you. Every time. I have never seen an insurance company renew a policy after a ransomware claim. Not once.
If you’ve ever had a car accident that was your fault, you know exactly what I’m talking about. Your premiums go up, or your insurer drops you entirely. Except with ransomware, it’s always your fault. There’s no debating it. You got breached. That means your defenses weren’t good enough. Period.
Your new premiums will shock you. When you go shopping for new cyber insurance after being dropped (and you need to, because your contracts and your clients probably require it) you’re looking at premiums that are 10 to 30 times what you were paying before. I’ve seen businesses go from $15,000 a year to $150,000 a year. Some go even higher.
And here’s where it gets really dark: some organizations can’t afford to stay in business after an incident, not because of the ransomware itself, but because the new insurance premiums eat their margins. They survived the attack but can’t survive the aftermath.
The CFO Math That Looks Smart Until It Doesn’t
I sit across from CFOs who have this all figured out. The spreadsheet looks great. It goes something like this:
“Cyber insurance costs us $300,000 a year for a $20 million policy. Comprehensive security would run $60,000 to $80,000 per month, that’s $720,000 to $960,000 a year. So insurance is cheaper. And if we get hit, insurance pays. If we go five or six years without an incident, we’ve saved millions.”
On paper, that math checks out. In the real world, it falls apart completely.
Here’s why. That calculation assumes the policy actually pays out $20 million. It won’t, because sub-limits mean you might see 5% of that. It assumes you can keep the same policy after a claim. You can’t, because you’ll get dropped. It assumes premiums stay the same. They won’t. They’ll jump 10 to 30 times. And it assumes the total cost of the incident fits inside the policy limits. It probably doesn’t, once you add up forensics, legal, hardware, lost revenue, reputation damage, and years of rebuilding.
They think they’ve got that insurance, and that’s the same as cybersecurity. It is not. It never is.
I spend close to $10,000 a year on my own cyber insurance premiums. I’ve talked to other IT company owners who spend $1,500 a year. I don’t even need to know how much coverage they have, because it’s not enough. You will not have a ransomware incident that impacts you or your customers for less than a million dollars.
Insurance Is Step One, Not the Whole Plan
Now, I’m not telling you to cancel your cyber insurance. You need it. It’s a legitimate piece of your risk management strategy. But it’s step one out of about twenty.
Think of it this way: you have car insurance, but you still wear your seatbelt. You still have airbags. You still check your mirrors and follow the speed limit. The insurance is there for when everything else fails. It’s not a substitute for driving safely.
Cyber insurance is no different. It’s the policy you hope you never need, behind the defenses that are supposed to keep you from needing it.
What an Actual Security Posture Looks Like
So what goes alongside that insurance policy? For a business with 10 to 100 computers (which is our sweet spot here at ArcLight) a real cybersecurity posture includes:
Endpoint detection and response on every device. Not just antivirus. Actual behavioral monitoring that catches threats traditional antivirus misses.
24/7 threat monitoring. Attacks don’t wait for business hours. You need someone watching your environment at 2 AM on a Saturday.
Backup and disaster recovery that’s tested regularly. Not “we set it up three years ago and we think it’s working.” Actually tested. Actually verified. With recovery time objectives documented and practiced.
Security awareness training for every employee. Because the number one way ransomware gets in is through a human clicking something they shouldn’t. Your people are either your first line of defense or your biggest vulnerability.
Multi-factor authentication everywhere. Email, VPN, cloud apps, admin accounts, everywhere.
Incident response planning. A documented plan that everyone knows about before the crisis hits. Who do you call? In what order? What do you not touch? This isn’t something you figure out in the moment.
Does this cost money? Yes. Figure $100 to $300 per user per month, depending on the size and complexity of your environment. For a 50-person company, that’s $5,000 to $15,000 a month.
Is that less than a ransomware incident? By a factor of fifty. Easily.
The Question You Should Be Asking
The question isn’t “do we have enough insurance?” The question is “what are we doing to make sure we never have to use it?”
Because insurance doesn’t prevent ransomware. It doesn’t stop the attacker. It doesn’t keep your production floor running or your patients’ data safe or your employees getting paid. It’s a financial backstop with fine print, sub-limits, and consequences that most business owners don’t understand until they’re standing in the middle of a crisis wondering why the check they’re getting is a fraction of what they expected.
If you’re not sure where you stand, whether your insurance actually covers what you think it covers, or whether your security posture has gaps that an attacker would find, we do a free 27-point IT Risk and Ransomware Assessment. We’ll tell you exactly where the holes are. Sometimes businesses are in better shape than they think. Usually, they’re not. Either way, you’ll have the information you need to make a real decision, not a spreadsheet decision.
Because the worst time to find out your insurance isn’t enough is the same day you find out you needed it.
Brian Largent is the CEO and founder of ArcLight Group, a managed IT and cybersecurity firm based in Tulsa, Oklahoma. With 30+ years in the industry and a SOC 2 Type 1 certified team, ArcLight protects businesses with 10–100+ computers across Oklahoma and beyond. Reach Brian’s team at (918) 270-6600 or [email protected].

Brian Largent
Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)




