Here is something almost nobody talks about – and almost everybody gets wrong.
When your cyber insurance policy comes through, what do you do with it? If you are like most business owners, it lands in your email. Maybe you download it and save it to a folder. Maybe it lives in your inbox, or in a shared drive, or in a document management system somewhere on your network.
That is exactly where an attacker wants it.
What Hackers Are Actually Looking For
When ransomware hits a business, most people imagine the attacker as someone who encrypted the files, set a number, and is waiting to see what happens. That is not how sophisticated attackers operate.
Before a ransom demand is ever made, attackers spend time inside a network. They are looking around. Reading emails. Searching for documents. Mapping out what the business has, what it is worth, and – critically – what it is insured for.
If they find your cyber insurance policy sitting in your inbox or saved to a network drive, they now know your coverage limit. And that number becomes the ransom.
Not $100,000. Not $500,000. Whatever the policy says it will pay – that is what they ask for. Because they know the insurance company is prepared to pay it. They know your coverage limit before you even know you have been hit. And they are willing to wait, because the math works in their favor.
This is not speculation. This is how sophisticated ransomware operations work. The reconnaissance happens before the demand. And your policy documents are part of what they are looking for.
The Digital Footprint Problem
Think about everything connected to your business email account.
Your inbox. Your sent folder. Every attachment you have ever received or forwarded. Every document saved to OneDrive or Google Drive through the same credentials. Every file on a shared network drive that anyone with access to your account can reach.
If an attacker gets into your email – through a phishing link, a compromised password, a credential stuffed from a data breach somewhere else – they have access to everything in that environment. And if your insurance policy is in that environment, they have that too.
The policy document that was supposed to protect you just handed the attacker a roadmap for exactly how much to demand.
The Rule Is Simple: It Never Touches the Network
Your cyber insurance documents – the policy itself, the coverage limits, the declarations page, any correspondence with your broker – should never exist in your digital business environment. Not in your email. Not in cloud storage. Not on a network drive. Not as a downloaded PDF on a company computer.
Here is how I tell business owners to handle it:
If you are not local to your broker: Have everything faxed. Not emailed. Faxed. A fax does not live in an inbox. It does not sit in a cloud folder. It does not travel through a server that an attacker might already be inside.
If you are local to your broker: Go in person. Sit down in their office. Review the documents there. Walk out with paper copies. The policy never needs to touch any part of your business network.
Where it lives after that: The same place your most important documents live. A fireproof safe at the office. A safe at home. A safety deposit box at the bank. A physical hard copy in a location that is completely air gapped from anything a ransomware attack could reach.
The same logic that applies to your off-site backup applies here. The document that survives an attack is the one that was never connected to begin with.
Who Should Know and Who Should Not
This is also a need-to-know conversation.
The coverage limit on your cyber insurance policy is not information that should be widely distributed inside your organization. Not because your employees are untrustworthy – but because every additional place that information exists is another place an attacker might find it.
The people who need to know the policy exists and where the physical documents are kept: the owner, and whoever would be responsible for contacting the insurer during an incident. That is probably a very short list.
Everyone else does not need the number. They do not need to know the coverage limit. And they certainly do not need a copy in their email.
The Ransom Note Is Written Before the Attack
Here is the way I want business owners to think about this:
By the time a ransom demand appears on your screen, the attacker has often already done their homework. They have been in your network. They have read your email. They know what you have and what you are worth and what your insurer is prepared to pay.
The ransom number is not a guess. It is a calculation. And if your policy documents were anywhere on your network, you handed them the inputs.
Keeping those documents off your network does not make you immune to attack. But it does remove one of the tools attackers use to calibrate how much to demand – and it removes the possibility that your own insurance coverage becomes the number on the ransom note.
Print it. Fax it. Lock it up.
And never let it touch your inbox.
—
Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.
Key Takeaways
- Attackers spend time inside a network before making a demand — reading emails and searching for documents including your insurance policy
- If they find your coverage limit they know exactly what to demand because they know the insurer is prepared to pay it
- Your cyber insurance documents should never exist in your digital business environment — not in email, not in cloud storage, not on a network drive
- The ransom number is not a guess — it is a calculation based on what attackers find during reconnaissance
- The document that survives an attack is the one that was never connected to begin with