Halden logoHalden
Security2026-07-145 min

Ransomware and the private bank

Why we treat ransomware as a treasury problem, not an IT problem — and what we actually carry as cover.

It hits the money, not the laptops

When a firm gets hit with ransomware, the headline is encrypted files. The real damage is that payments stop, counterparties stop trusting instructions, and a closing slips. For a bank that raises funds and sells companies, a missed settlement window is worse than a lost server.

So we plan for the money, not the machines. Every payment instruction has a second channel of verification. Every wallet has a policy that no single person can override. If our platform went dark tomorrow, the desk could still settle by phone against pre-agreed controls.

What we carry

We hold ransomware and cyber liability cover, and we treat the policy as a floor, not a plan. Insurance pays after the fact. Controls are what stop the event: hardware-backed keys, segregated environments, least privilege by default, and monitored access to anything that touches client money.

The client-side question

Most incidents we see in the deal world start with a compromised email box on the client side, not ours. Before a mandate goes live we agree a callback protocol and a fixed set of authorised signatories. If an instruction arrives outside that protocol, it does not get executed — however urgent it sounds.