§Ransomware / business-interruption loss

Ransomware and Business-Interruption Loss Mediation

A ransomware event produces a loss that several parties each have reason to believe belongs to someone else. The insured, its carrier, and the provider that managed the affected systems generally agree on what happened and disagree on what follows from it.

You are probably here because
  • An outage has produced a business-interruption figure the carrier disputes
  • A managed service provider's contract is being read against its performance during the incident
  • Restoration took materially longer than either side expected and the reasons are contested
  • The dispute has become a fight about whether the loss was avoidable

The allocation problem

In plain terms: Everyone agrees on the outage; nobody agrees on whose failure produced it.

Ransomware disputes have an unusual shape. The core event is rarely contested — systems were encrypted, operations stopped, restoration took a certain amount of time. What is contested is causation, and specifically the counterfactual: what would have happened had a particular control been configured differently, a particular backup been tested, or a particular alert been escalated.

That counterfactual is where the money sits, and it is genuinely hard. It cannot be read directly off the artifacts, so each party constructs it from the evidence plus a set of assumptions that happen to favour its own position. The assumptions are usually the real disagreement, and they are usually unstated.

Surfacing them is most of the work. Once the parties are arguing about the same counterfactual rather than three different ones, the range of defensible outcomes narrows considerably.

Reading the restoration timeline

In plain terms: How long recovery *should* have taken is an evidentiary question, not a rhetorical one.

Business-interruption value depends on the length of the interruption, and the length that gets litigated is rarely the length that was actually experienced. A carrier will argue that recovery should have been faster; an insured will argue that the conditions on the ground made the observed pace reasonable.

The systems themselves carry a good deal of evidence on this. Backup integrity, restoration sequencing, dependency order, and the points at which recovery stalled all leave traces, and those traces constrain the range of reasonable positions more tightly than either party usually expects.

A neutral who can work through that record with each side in caucus can often move a valuation without ever asking anyone to concede a legal position.

Bringing the service provider into the room

In plain terms: Two-party mediation of a three-party problem tends to reallocate the dispute rather than resolve it.

Where a managed service provider or other vendor is implicated, resolving only the coverage half leaves the indemnity half live and often makes it worse — the insured's settlement with its carrier becomes evidence in the next dispute. Where the contractual and practical realities permit it, bringing every party with exposure into a single confidential process is usually the cheaper path.

That is harder to convene and worth the effort. It also changes the negotiation: a provider that would resist an indemnity demand in isolation frequently engages differently when the alternative is being the only party still exposed after everyone else has settled.

Common questions

Can the service provider and the carrier be mediated together?
Often, and it is usually preferable. Resolving one relationship in isolation can leave the other worse off, because a settlement in the first becomes a data point in the second. Whether a joint process is workable depends on the contracts and on the parties' willingness, which is one of the first things to establish.
Is the ransom payment itself usually the dispute?
Rarely. The extortion payment is generally the smaller and better-documented part of the loss. The contested value is almost always in the interruption, the restoration, and the downstream consequences.
What if the forensic work was done by the insured's own responders?
That is the normal case, and it does not disqualify the record. It does mean the record was assembled under privilege and under time pressure, and the neutral's job includes helping the parties work out what can usefully be shared without waiving protections that matter.
Discuss a ransomware / business-interruption loss.

A conflicts check and a confidential scoping call follow — without obligation. Chambers, counsel, and carriers are all welcome to inquire.

Request a mediation

Related dispute types

The Breach Docket

Keep reading the docket

The Breach Docket collects recent data-breach decisions and notable settlements, read the way a neutral reads them. Free, every other week.

No advertising. Unsubscribe in one click.