Ransomware and the private bank
Why we treat ransomware as a treasury problem, not an IT problem — and what we actually carry as cover.
It hits the money, not the laptops
When a firm gets hit with ransomware, the headline is encrypted files. The real damage is that payments stop, counterparties stop trusting instructions, and a closing slips. For a bank that raises funds and sells companies, a missed settlement window is worse than a lost server.
So we plan for the money, not the machines. Every payment instruction has a second channel of verification. Every wallet has a policy that no single person can override. If our platform went dark tomorrow, the desk could still settle by phone against pre-agreed controls.
What we carry
We hold ransomware and cyber liability cover, and we treat the policy as a floor, not a plan. Insurance pays after the fact. Controls are what stop the event: hardware-backed keys, segregated environments, least privilege by default, and monitored access to anything that touches client money.
The client-side question
Most incidents we see in the deal world start with a compromised email box on the client side, not ours. Before a mandate goes live we agree a callback protocol and a fixed set of authorised signatories. If an instruction arrives outside that protocol, it does not get executed — however urgent it sounds.
