Cyber insurance faces soaring losses, denials, and market shifts

The gist

Cyber insurance is being rocked by soaring losses, skyrocketing denial rates, and seismic market shifts—leaving businesses scrambling for reliable coverage in a riskier world.

What to know

  • Business interruption costs from breaches surged 51% in a year, with catastrophic supply chain incidents topping $100 million, according to Verizon’s 2026 study.
  • New AIG and Willis cyber policies offer up to $100 million in modular, customizable coverage, but U.S. carriers are facing stubbornly high loss ratios and falling rates.
  • Claims denial rates now hover at a staggering 40–44% as security lapses and misrepresentation spike, fueling urgent calls for expert advisory teams and a federal cyber backstop.

Catastrophic Breach Costs Surge

Business interruption and supply chain cyberattacks now drive extreme, unpredictable losses—forcing insurers to confront the outsized impact of rare but devastating incidents.

By early 2026, Verizon’s Breach Impact Study underscores a significant shift in cyber insurance claims, with business interruption emerging as the dominant cost driver, surging 51% from 2023 to 2024 and reaching extreme losses nearing $5 million. While supply chain incidents constitute a mere 2% of claims, their financial severity is disproportionately high, boasting a median impact over $252,000 and catastrophic cases exceeding $100 million, highlighting the escalating complexity and risk embedded in third-party exposures.

Verizon’s analysis reveals a stark disparity in breach costs, where the median financial impact stands at $83,000, yet the top 10% of breaches inflict damages exceeding $920,000, and the most severe 2.5% surpass $5 million. This wide range illustrates the unpredictable nature of cyber losses, emphasizing the need for insurers and risk managers to prepare for high-severity, low-frequency events that can dramatically skew loss ratios.

Distinctively, Verizon opts for median values over averages in reporting financial impacts, a methodological choice that delivers more actionable and reliable data for practitioners. This approach avoids the distortion caused by extreme outliers common in other studies like Ponemon’s, enabling clearer, more pragmatic conversations with boards and stakeholders about realistic cyber risk exposures and insurance needs.

Sources
Resilient Cyber

Modular Coverage Redefines Risk

AIG and Willis are reshaping cyber insurance with flexible, high-limit policies and integrated security services, but regulatory gaps and uninsurable fines demand expert broker guidance.

By mid-2026, AIG revolutionized cyber insurance for mid-sized and large companies with its Cyber Insurance Primary product, offering up to $100 million in modular coverage that blends first-party incident response, business interruption, and third-party liability. This product not only integrates preventive services like security assessments and phishing training to qualify clients for higher limits but also empowers firms to tailor their policies with customizable deductibles and high-limit towers, enabling precise alignment with their risk appetite and budget constraints.

Shortly after, Willis expanded its CyMax Facility to address a critical protection gap for SMEs across EMEA, providing a panel-based primary and excess cyber insurance solution backed by insurers such as AXA XL and Beazley. Targeting businesses with turnovers up to €500 million, this facility adopts a flexible underwriting approach by accommodating firms with either fully established or partial cybersecurity controls, reflecting the sector’s varied maturity levels and widespread security gaps.

Both AIG and Willis emphasize regulatory alignment in their offerings, with AIG’s global 24/7 incident response network delivering forensic, legal, negotiation, and PR support tailored to regional regulations, while Willis’s CyMax Facility aligns coverage with key EU regulations including GDPR, NIS2, and DORA. However, Willis highlights the nuanced reality that regulatory fines often remain uninsurable depending on jurisdiction, underscoring the necessity for brokers to provide tailored client guidance amid evolving regulatory landscapes.

Sources

Market Splits, Growth Stalls

Surplus lines carriers dominate a bifurcated market as premium growth falters and mounting third-party claims push loss ratios beyond 50%, exposing vulnerabilities in traditional strategies.

By mid-2026, the U.S. cyber insurance market has clearly bifurcated into two distinct segments: surplus lines carriers, which now command nearly two-thirds of all cyber premiums and focus on primary and excess cyber-specific policies, and admitted carriers that primarily offer endorsements to broader commercial policies. This segmentation reflects divergent strategic approaches, with surplus lines carriers like Beazley increasingly managing complex, longer-tail third-party claims that challenge their historical paid-loss advantage.

Pricing pressures have intensified, with the U.S. cyber insurance market experiencing eight consecutive quarters of rate declines through early 2026, culminating in a softening environment that erodes premium growth despite a headline $7.5 billion in total written premiums for 2025. Notably, much of this premium volume stems from internal business transfers—such as Beazley relocating blocks of business from offshore to domestic entities—rather than organic market expansion, underscoring the fragile nature of growth amid competitive pricing.

The surge in longer-tail third-party cyber claims has driven industry loss ratios above 50%, with surplus lines carriers bearing a heavier burden—posting a 56% incurred loss ratio in 2025 compared to 50.2% for admitted carriers. This trend not only threatens to erode the surplus lines carriers’ current paid-loss advantage but also injects significant uncertainty into reserving practices, compelling insurers to reevaluate pricing and risk management strategies amid a challenging claims landscape.

Sources

Cyber ILS Gains Traction

Cyber insurance-linked securities are evolving from niche to necessity, with growing investor trust and advanced risk modeling paving the way for alternative capital amid rising catastrophic risks.

Cyber insurance-linked securities (ILS) currently occupy a niche yet strategically vital role in the cyber insurance ecosystem, focusing primarily on transferring tail risk rather than day-to-day losses. Despite representing only 1.3% of the outstanding catastrophe bond market and a mere 0.19% of new issuances in 2026, their targeted protection against large-scale cyber events complements ample traditional reinsurance capacity and soft pricing, which currently limit broader market penetration.

Investor confidence in cyber ILS is gradually strengthening, buoyed by advancements in cyber risk modeling that enhance risk assessment and risk/return evaluation. This growing sophistication is exemplified by Hannover Re’s Cumulus Re parametric cloud outage catastrophe bond, which has seen three consecutive renewals with increasing issuance sizes—most recently securing $35 million—signaling rising trust and maturation within this alternative capital segment.

The future growth trajectory of cyber ILS hinges on evolving market dynamics, particularly the potential tightening of traditional reinsurance capacity amid rising cyber losses and underwriting pressures. Should these conditions materialize, cyber ILS could emerge as a scalable and attractive alternative capital source, offering per-occurrence excess-of-loss coverage preferred by investors who seek protection against extreme, remote tail risks rather than attritional losses from smaller incidents.

Sources
Artemis.bm

Denials Soar, Expertise Needed

With nearly half of cyber claims denied over technical missteps, only specialized advisory teams can navigate complex policies and shrinking protection gaps in a volatile risk environment.

By mid-2026, cyber insurance claims denial rates have alarmingly hovered between 40% and 44%, largely due to misrepresentations, lapses in mandated security controls, and inaccurate application responses often signed off by personnel lacking deep technical expertise. Dr. Chase Cunningham highlights that while a federal cyber backstop akin to the Terrorism Risk Insurance Act could bolster resilience against catastrophic systemic cyber events, it must be carefully structured as a last-resort mechanism contingent on adherence to standards like NIST CSF and CISA’s Cybersecurity Performance Goals to avoid inadvertently subsidizing poor cybersecurity practices.

The cyber protection gap remains a daunting challenge, with the Global Federation of Insurance Associations estimating that insured losses cover only a fraction of the staggering $900 billion in annual global cyber economic damages reported in 2023. This vast shortfall underscores the urgency for more comprehensive coverage solutions and risk-sharing frameworks to better shield organizations from escalating cyber threats.

Navigating the labyrinthine terms of cyber insurance policies has become increasingly complex, especially for mid-market insureds who often depend heavily on brokers for risk interpretation. Experts like Cunningham advocate for an advisory triangle comprising a cyber-specialist broker, an independent technical advisor or fractional CISO, and outside counsel well-versed in cyber coverage and breach response, emphasizing that advisors with direct claims experience are crucial to effectively manage policy intricacies and improve claims outcomes.

Sources

AI & Insurers Drive Security

Artificial intelligence is transforming threat detection and raising the bar for insurability, fueling a surge in cyber defense valuations as insurers become gatekeepers for robust security standards.

By mid-2026, AI-driven innovations have revolutionized cybersecurity by enabling behavioral monitoring techniques that detect subtle anomalies, such as unusual email tones or instructions, which traditional defenses often miss. This advancement not only enhances protection but also aligns with insurers' growing insistence on robust cyber defenses as prerequisites for coverage, effectively making insurance companies 'the best salesmen for cybersecurity' by enforcing stringent security standards before issuing policies.

Reflecting these technological strides and shifting market dynamics, investor confidence in cyber defense firms has soared dramatically. For instance, CrowdStrike's valuation nearly doubled from 65 times expected earnings in early 2023 to 124 times by 2026, signaling a widespread belief that the integration of AI and insurance-driven demand marks a fundamental and lasting transformation in the cybersecurity landscape.

Sources
Viewsroom

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.