Topic
Cyber Insurance
Cyber is the line where underwriting, security engineering and claims response collide. Pricing has swung hard in both directions since 2020 and risk selection now leans on live security telemetry. Here is what the market is saying.
The short version
- Cyber pricing has moved through a hard market and back into softening — capacity, not loss cost, drives most of the swing.
- Ransomware remains the dominant loss driver, with business interruption outpacing extortion payments.
- Insurers increasingly underwrite from outside-in scanning and attested controls such as MFA and EDR.
- Systemic and war-exclusion wordings are the market's biggest unresolved question.
- Incident response services are part of the product, not an add-on.
What does cyber insurance actually cover?
A cyber policy typically bundles first-party cover (incident response costs, forensics, business interruption, data restoration, extortion payments where lawful) with third-party liability (privacy claims, regulatory defence, PCI penalties). The incident response panel — lawyers, forensics, negotiators — is a core part of the product, and for most insureds the response service is worth more than the indemnity.
What is the state of the cyber insurance market?
After the 2020-2022 hard market, when rates rose sharply and capacity contracted following ransomware losses, new capacity has pushed pricing down again while retentions and control requirements have stayed strict. Demand keeps growing, particularly in SME, where penetration remains low. The market's open question is systemic accumulation: a single cloud or software supply-chain failure hitting thousands of insureds at once.
How do insurers assess security posture?
Through three lenses: outside-in scanning of the internet-facing estate, attested controls in the application (MFA, EDR, offline backups, privileged access management, patch cadence), and, increasingly, continuous telemetry shared by the insured in return for premium credit. Controls are treated as eligibility gates rather than pricing factors — no MFA on remote access is a decline in most appetites, not a loading.
What drives cyber losses today?
Ransomware still dominates severity, but the loss is increasingly business interruption and restoration rather than the extortion payment itself. Business email compromise drives frequency. Third-party and supply-chain incidents — a managed service provider or SaaS vendor being breached — produce the correlated losses insurers fear most. Regulatory and privacy litigation is the slowest-developing but fastest-growing tail.
What should buyers check in the wording?
Look at the war and state-backed attack exclusion and how attribution is determined; the definition of a waiting period for business interruption and how it is measured; whether dependent business interruption covers named suppliers only; sublimits on extortion and social engineering; and whether the insured can use its own incident response vendors or must use the panel.
Videos on Cyber Insurance
No videos tagged to this topic yet.
Read more on InsurTech360
Visit InsurTech360
InsurTech360
The E&S Market’s Next Evolution: From Capacity Advantage to Intelligent Execution
E&S Insurer Conference & Awards | May20 | Convene Brookfield Place, Liberty 225, New York For years, the Excess & Surplus market thrived by doing what the standard market could not. Complex risks. Emerging exposures. Speed. Flexibility. Specialized underwritin

InsurTech360
Outlook: The Evolution of the MGA Model in the United States
The managing general agent (MGA) model has become one of the most powerful growth engines in the global insurance industry, and its evolution is particularly evident in the United States. The numbers tell their own story. US MGA premiums exceeded $114bn in 202

InsurTech360
From OCR to Intelligent Automation: How Upstage and Kasey Roh Are Building the Future of Enterprise AI
When Kasey Roh talks about Upstage, there’s an unmistakable sense of purpose – a belief that enterprise AI should move beyond hype into measurable impact. From its early days in Seoul to its growing presence across the U.S., Upstage has carved out a distinct p

InsurTech360
Cyber Risk and The Critical Role of Partnerships
Cyber breaches and attacks remain an ongoing threat in 2025 especially for SME businesses, therefore having accurate risk data is vital to choosing the appropriate coverage.

InsurTech360
How can Insurance Respond to the Deepfake Threat?
The world of cyber is evolving; statistics reveal that the computing and human power put into developing artificial intelligence (AI) is increasing ten fold every six months. This pace of change is unprecedented; so much so that AI has become the most rapidly
Frequently asked questions
How big is the cyber insurance market?
Global cyber premium is in the tens of billions of dollars and still growing at double digits, with the United States accounting for roughly half. SME penetration remains low in most markets, which is where most forecast growth sits. Check the latest broker and rating-agency market reports for current figures before quoting a number.
Why did cyber insurance get so expensive, then cheaper again?
Ransomware losses in 2019-2021 outran pricing, so insurers raised rates sharply, cut limits and imposed control requirements. Those measures worked, results improved, and new capacity entered — which pushed rates back down. Control requirements, however, have largely stayed, so the cost of buying cyber cover now includes the cost of meeting the security baseline.
What security controls do insurers require?
Multi-factor authentication on remote access, email and privileged accounts; endpoint detection and response; tested offline or immutable backups; privileged access management; timely patching of internet-facing systems; and security awareness training. Missing MFA is the single most common reason a submission is declined outright.
Does cyber insurance cover ransomware payments?
Most policies cover extortion payments where making them is lawful in the relevant jurisdiction, alongside negotiation and forensic support. Sanctions screening applies, and payment is generally a last resort after restoration options are assessed. In practice the larger part of a ransomware claim is business interruption and restoration cost, not the ransom.
Related topics
Claims Automation
Claims is where policyholders find out what an insurer is actually worth. Automation is now reshaping every step of it, from first notice of loss to payment. This hub answers the questions carriers and vendors ask most, and links to the talks and demos worth watching.
Embedded Insurance
Embedded insurance puts cover at the point of sale: in a checkout flow, a booking confirmation, a car dashboard, a payroll system. It is the fastest-growing distribution channel in the industry and the hardest to get commercially right. Start here.
Parametric Insurance
Parametric cover pays a fixed amount when a measurable index crosses a threshold — wind speed, rainfall, earthquake magnitude, flight delay. No adjuster, no proof of loss, payment in days. It is where climate risk, data and insurance meet.
Underwriting Automation
Underwriting automation moves risk selection from a human reading a submission to a system that pulls data, applies rules and routes only the genuine exceptions to an underwriter. This hub covers what works, where it breaks, and how to govern it.
Last reviewed 31 July 2026 by the InsurTech.TV editorial team.