When is a ransomware limit not a limit: Lessons from CiCi Enterprises v HSB
A US court has ruled that a clause added to a cyber insurance policy to limit how much an insurer pays out following a ransomware attack did not work as the insurer had intended, with important lessons for insurers reviewing their policy wording.
Background
CiCi Enterprises, a US restaurant franchise, suffered a ransomware attack in May 2022. A threat actor encrypted its systems and threatened to publish stolen data unless a ransom was paid. CiCi incurred around $1.2m in costs, including a $400,000 ransom payment.
HSB acknowledged that the attack triggered cover under several insuring agreements, including Cyber Extortion, under a policy with a $3m aggregate limit. It then relied on a Ransomware Event Sublimit Endorsement to cap its liability at $250,000, paid that sum, and considered the matter closed.
CiCi disagreed. On 23 February 2026, the US District Court for the Northern District of Texas found in CiCi's favour, holding that HSB had not drafted the endorsement clearly enough to achieve the result it intended.
Why the endorsement failed
The court identified four drafting problems.
- It did not say what it covered: The endorsement applied "solely with respect to the coverage afforded under this endorsement" but never identified which insuring agreements it modified. It sat in the Limits of Insurance section, not the Insuring Agreements section where cover is granted. That location alone was insufficient to restrict cover granted elsewhere.
- Other endorsements in the same policy were drafted differently: Endorsements relating to cryptojacking and funds transfer fraud each explicitly named the insuring agreements they modified. The ransomware endorsement did not.
- The policy structure did not support HSB's argument: HSB argued that a ransomware event was a subset of an extortion threat, bringing it within the Cyber Extortion cover. The court disagreed. The policy listed the two as separate categories.
- The preservation clause did not assist the insurer: The standard closing line, that "all other terms, conditions, and exclusions remain unchanged," reinforced the conclusion that the endorsement had not altered the existing Cyber Extortion cover. Boilerplate language does not fill a drafting gap.
Why this matters for insurers
English courts apply the same fundamental approach to policy construction. Under Arnold v Britton [2015] UKSC 36 and Wood v Capita Insurance Services [2017] UKSC 24, courts will generally give words their natural meaning in the context of the policy as a whole. Provisions that limit or restrict cover are construed carefully, and courts will not rewrite a policy to reflect what an insurer intended but failed to express.
Ransomware sub-limits are a standard feature of cyber policies. The CiCi case is a reminder that a sub-limit which is not clearly connected to the insuring agreements it is intended to restrict may not operate as intended when a claim is made.
Insurers should consider four practical steps
- Check that sub-limits clearly state which parts of the policy they apply to. If they do not, a court may find that broader policy limits remain available to the policyholder.
- If an endorsement introduces a new term, make sure that term is clearly linked to the existing language used in the operative sections of the policy.
- Review all endorsements together and check for inconsistencies. If some endorsements cross-reference specific coverage sections and others do not, a court will notice.
- If a sub-limit is intended to cap all losses from a particular event or peril, including the cost of responding to the incident or peril, lost revenue, and system restoration, say so explicitly in the endorsement rather than leaving it to be implied.
Contents
- Insurance Insights: The Word, March 2026
- Middle East conflict 2026: Insurance impacts across marine, aviation, travel and beyond
- Meningitis outbreaks are back on the liability radar: How might this impact insurers?
- Business interruption insurance: Aggregation
- GLP-1 weight loss drugs: What do Robbie Williams, GP bonuses and insurance have in common?
- From LOL to FNOL: Insurer impacts of romance-linked claims manipulation
Contact
Kathryn Balogun
Trainee Solicitor
kathryn.balogun@brownejacobson.com
+44 (0)330 045 2763
Tim Johnson
Partner
tim.johnson@brownejacobson.com
+44 (0)115 976 6557
You may be interested in
Legal Update
When is a ransomware limit not a limit: Lessons from CiCi Enterprises v HSB
Legal Update
FCA's anticipated priorities for InsurTechs
Legal Update
Cyber attacks: Could brokers be in the firing line?
Legal Update
“New low” for ransomware cybercriminals an opportunity for cyber insurers?
Legal Update
Physical property damage from cyber incidents: Implications for insurers
Legal Update
AI adoption without safeguards: A growing risk for insurers
Legal Update
Marine insurers face coverage uncertainty as GPS spoofing incidents rise
Legal Update
Aon calls for national AI regulation framework
Legal Update
“Silent AI”: The risk of unintended consequences
Legal Update
Exploring the impact of recent attacks on UK retailers and the future of cyber insurance
Legal Update
The M&S cyber attack: Lessons for UK retailers
Legal Update
Is your cyber resilience shored up?
Legal Update - DORA
EU Digital Operational Resilience Act: Countdown to comply with the January 2025 deadline
Legal Update
Artificial intelligence in insurance: Targeted marketing as a quasi-underwriting function
Legal Update
The EU AI Act: What does it mean for insurers?
Legal Update
The space data revolution
Legal Update
LockBit unlocked: International taskforce takes down major cyber criminal organisation
Legal Update - Autonomous vehicles
Progress on the Automated Vehicles Bill
Legal Update
CyberCube’s Global Threat Outlook: The evolving threat of cyber operations
Legal Update
A new digital safe space – How does the EU Digital Services Act affect insurers?
Legal Update
“TOBA traps” - general exposure risk under existing TOBAs
Legal Update
UK Government publishes the Online Safety Bill: an overview
Legal Update
The rising number of cyber-attacks
Legal Update
The continued threat of piracy in Southeast Asian waters
Legal Update
Government publishes its proposals for expanding the Scope of the Network and Information Systems Regulations 2018
Legal Update
‘Big Game Hunting’ – the new face of cyber extortion?
Legal Update
Economic crime and cybercrime
It is clear that the digital landscape, often termed cyberspace, is a man-made environment, in which human behaviour dominates and where technology both influences and aids our role in it — through the internet, telecoms and networked computer systems, which are often interdependent. The extent to which any organisation is potentially vulnerable to cyber-attack depends on how well these elements are aligned.
Legal Update
Let’s be direct – doubly so
Legal Update
The Ukraine War: Aviation and cyber issues
Legal Update
The physical consequences of cyber attacks
Legal Update
ICO consultation on research provisions guidance
The data protection legislation (namely, the UK GDPR and Data Protection Act 2018) contain various provisions that deal with the processing of personal data for research purposes.
Legal Update
More good news for data controllers: High Court finds local authority not vicariously liable for the actions of social worker who went off on a "frolic of her own"
Legal Update
Stemming the tide of data breach claims: good news for data controllers
The cases summarised give considerable comfort to data controllers seeking to defend themselves against claims that relate to breaches arising as a result of a failure rather than a direct act and/or are based on assertions of damage or distress that are exaggerated, unsubstantiated or bear little relation to the breach itself.
Published Article
Confidential information and subject access disclosure
In February 2021, the High Court handed down judgment London Borough of Lambeth v AM (No. 2) [2021] EWHC 186 (QB), in which Browne Jacobson LLP acted for the Claimant Council. The judgment is critical reading for public bodies who are required to take action to restrict the use of confidential information in circumstances where that information has been inadvertently disclosed to a third-party.
Published Article
Top tips for implementing ‘Data Protection by Design & Default’
The GDPR requires all businesses to implement ‘Data Protection by Design & Default’ but what does that mean in practice and how can businesses practically comply?
Published Article
Protecting your business from cyber threats
Did you know that cyber attackers can use publicly available information about your business and employees to make their attacks more successful? Information is often gleaned from websites and public social media accounts.
Legal Update
Legal and regulatory monthly update - September 2019
The latest update covering delegated authority, insurance product development, the senior insurance managers regime, data protection, operational control frameworks, Lloyds market, and horizon scanning.