Potentially.
Cyber Insurance can provide cover for certain ransomware and cyber-extortion costs, but a ransom payment should never be assumed to be covered or made without involving the insurer and its incident-response team.
What can Cyber Insurance cover during a ransomware incident? #
Depending on the policy and circumstances:
- Incident-response services
- Forensic investigation
- Cyber-extortion negotiation
- Legal and privacy advice
- Data restoration
- System restoration
- Business interruption
- An insurer-approved ransom or extortion payment where legally permitted
A payment does not guarantee that:
- Data will be restored
- Stolen information will be deleted
- Systems will be decrypted
- The organisation will not be targeted again
A particular payment can also be restricted by sanctions, counter-terrorism financing or other legal requirements.
Are ransomware payments reportable in Australia? #
Yes, for certain organisations.
Under the Australian ransomware payment reporting regime, a report can be required where a ransomware or cyber-extortion payment is made by or on behalf of:
- An entity carrying on business in Australia with annual turnover for the previous financial year of $3 million or more
- A responsible entity for certain critical infrastructure assets
The report must generally be made within 72 hours of making the payment or becoming aware that a payment was made on the organisation’s behalf.
Current reporting information is available through the Australian Government’s Cyber.gov.au ransomware payment reporting service.
If you experience a ransomware or cyber-extortion incident, use the emergency response details provided with your Cyber policy and notify Webber Insurance immediately.
Email [email protected] or use our Claims page.
Do not authorise a payment, negotiation or substantial response cost without first involving the insurer.

