Ransomware
In one sentence
Malware that locks or encrypts your data and demands payment to release it, often after stealing a copy too.
Ransomware encrypts your files and systems and demands a ransom for the key; modern variants also steal data first and threaten to leak it ('double extortion'). Tested, offline backups plus a response plan are what let victims recover without paying.
Why it's on your cyber insurance application
The loss cyber policies are most associated with; a record 86% of victims refused to pay in 2026, backed by good backups (Coalition).
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Backup & recovery
How is your critical business data backed up?
Why carriers ask: Tested, offline-capable backups are the difference between an outage and paying a ransom. Claims data shows a record share of ransomware victims now refuse to pay. Working backups are what make refusal possible.
If the answer is no: Stand up automatic off-site backup for critical systems this week, then schedule a restore test.
Endpoint protection
What protects your computers and servers from malware?
Why carriers ask: EDR (endpoint detection and response) is what stops ransomware mid-attack. Many carriers price policies differently, or decline outright, based on this answer alone.
If the answer is no: Deploy EDR to every computer and server this week. This is the single fastest insurability improvement after MFA.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:
Guides that cover this
Cybersecurity 101: the basic precautions insurers actually notice
A plain-English starter guide to the cybersecurity basics that move the needle on a cyber insurance application: MFA, EDR, tested backups, patching, email protection, training, and a written incident response plan — most fixable in an afternoon.
The 7 controls every cyber insurance application asks about in 2026
Cyber insurance applications in 2026 require MFA, EDR, tested backups, patching, email security, security awareness training, and a written incident response plan. Here's each requirement, why carriers ask, and what evidence you need before you sign the attestation.
How to write an incident response plan that satisfies your cyber insurance application
Carriers require an incident response plan that is written and tested. Here's the exact structure that satisfies the application question (roles, contacts, isolation steps, carrier notification) plus how to run the one-hour tabletop test that makes it real.
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.