Estimated reading time: 6 minutes
VikingCloud surveyed large multi-location brands, which the report calls “distributed enterprises,” on how attacks spread and who pays. Headquarters makes the ransom call far more often than it mandates security. The survey did not ask whose cyber policy responds.
When ransomware hits one location of a large brand, headquarters usually makes the ransom call. That holds at 78% of brands.
Only 51% of those brands mandate one security standard across every location. That gap sits at the center of franchise cyber risk. VikingCloud’s 2026 Cyber Threat Landscape Report frames it plainly. Headquarters “owns the bill far more often than it owns the control,” the report says.
Ransom Payment Responsibility At Large Brands
VikingCloud surveyed 200 security and IT decision-makers online in July 2026. All worked at US and European brands with at least 5,000 employees and 500 locations. Sectors included supermarkets, mass-market retail, quick-service restaurants, pharmacies and automotive services.
47% estimate a breach hitting most locations would cost $11 million or more. Then comes the question of who pays. In 40%, headquarters decides and pays for every affected location. In 38%, headquarters decides, but franchisees share the bill. Next, 14% of companies have each franchisee pay for its own location. 7% have no policy at all. The split covers all 200 brands, including the 44% that own every location.
The survey did not ask which insurance policy responds. Kevin Pierce, VikingCloud’s president and COO, confirmed that to Cyber Insurance News.
“When headquarters makes the ransom call for franchisee locations it doesn’t control and hasn’t mandated security standards for, the question of who owns the cleanup, and whose insurance policy is on the hook is not clearly defined,” Pierce said. “This is an important gap for leaders to address.”
33% cited higher premiums, coverage exclusions, or lost coverage as an effect of a cyberattack.
Franchise Cyber Risk And The Mandate Finding
86% of brands suffered a cyberattack in the past year. Among the 171 attacked, 77% said it spread beyond where it started. It reached other locations, corporate systems, or shared vendors.
The report linked one factor to less spread: a corporate security mandate. The effect showed up where independent franchisees run some or most sites. Among those brands, 64% of attacks spread when headquarters mandated one standard. Without a mandate, 89% spread.
Pierce gave Cyber Insurance News the numbers behind that comparison. Of 112 mixed or franchise operators, 98 reported an attack. Fifty-four had no corporate mandate. Forty-four did.
“That means mandated operators were more than three times as likely to contain an attack as those without one (36% vs. 11%),” Pierce said.
In counts, that is roughly 16 contained attacks among mandated operators and six among the rest.
The report found no such effect for brands that own every location. Where headquarters employs everyone, the standard travels anyway, it said. None of the 13 security technologies it measured reduced reported spread on its own. Neither did real-time visibility.
Our Latest Podcast
A defense supplier held every certificate on the list, then opened 17,000 ports after a server move nobody reported. Cyber Tzar CEO Andrew Horkan explains why compliant isn’t the same as secure. Watch the episode →
Unreported Cyber Incidents That Stop Short Of Leadership
91% said at least one material incident in the past year never reached executive leadership or the governing body. 79% said multiple incidents did. 43% said five or more.
Cyber Insurance News asked for the exact wording of the question. It read: “To your knowledge, how many material cybersecurity incidents in the past 12 months were NOT reported to your organization’s executive leadership or governing body?”
The survey did not define material. It did not ask whether respondents’ companies were publicly traded. Of the 182 respondents who reported at least one unreported incident, 63 held C-suite roles. Forty-one were vice presidents, 43 directors, and 35 managers.
The top reason for leaving an incident unreported was fear of professional repercussions, cited by 47%. The report defines that as personal reputational damage or difficulty finding future employment. VikingCloud has found fear driving silence for three years running. Underreporting also grew with footprint. 33% of brands with 500 to 999 locations reported five or more unescalated incidents. Among brands with 2,500 or more, it was 58%.
That pattern raises a question for underwriting. Cyber applications ask leadership about prior incidents. If incidents stop short of leadership, the person signing may not know about them. What reaches the board has already been a recurring theme in this publication’s CISO coverage.
Distributed Enterprise Security At Each Location
63% said at least one location received a deepfake or AI-generated message impersonating an executive. 87% said AI-generated phishing or deepfake attacks on location staff had grown more frequent or severe.
New sites add exposure. 80% do not fully bring a new location into central monitoring by opening day. 18% take more than a month.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
Franchise Cyber Risk Across One Brand
For a carrier, franchise cyber risk is an accumulation question inside a single insured. One compromised site can reach hundreds of others under the same brand. Whether those losses sit on one policy or many depends on contracts the survey did not examine.
Pierce’s answer for brands is governance. “Top down security mandates from headquarters to all franchise locations under a brand is the most important step leaders can take to contain cyberattacks across the footprint,” he said.
FAQ – Franchise Cyber Risk
What did VikingCloud’s 2026 report survey?
200 security and IT decision-makers at US and European brands with at least 5,000 employees and 500 locations, surveyed online in July 2026.
Who pays the ransom when a franchise location is hit?
In 40% of brands, headquarters decides and pays. In 38%, headquarters decides and franchisees share the cost. In 14%, each franchisee pays, and 7% have no policy.
Does a corporate security mandate stop attacks spreading?
Among 98 attacked mixed or franchise operators, attacks spread in 89% of the 54 without a mandate and 64% of the 44 with one. The report found no measurable effect for brands owning every location.
How many incidents never reach the board?
91% said at least one material incident in the past year was not reported to executive leadership or the governing body. The survey did not define material.
Did the survey ask about cyber insurance?
Not about which policy responds. 33% cited higher premiums, exclusions or lost coverage as an effect of a cyberattack.
Why does franchise cyber risk matter to insurers?
One compromised location can spread to others under the same brand, and it is often unclear whether the parent’s or the franchisee’s policy carries the loss.
Related Cyber Insurance Posts
- Ransomware Victim Counts Held Flat. The Stolen Data Didn’t.
- UK Cyber Report Calls for Growth, Stronger Cyber Insurance, and Clearer Rules(Opens in a new browser tab)
- Cyber Insurance Helps Hospital Recover from Hack & Identify Location of Stolen Data(Opens in a new browser tab)
- Restaurant Cyber Risk: 94% Confident, 76% Breached Anyway, Says VikingCloud(Opens in a new browser tab)
- One in Three SMBs Hit by Cyberattacks: VikingCloud’s 2025 Report Urges Action Now(Opens in a new browser tab)