main logo icon

Published on

April 29, 2026

|

22 min read

Cyber Insurance Statistics 2026: Premiums, Claims, Denials

Verified 2024 to 2026 cyber insurance statistics from Munich Re, Marsh, Aon, Howden, Coalition, At-Bay, NetDiligence, AM Best, Allianz, Lloyd's, and NAIC. 80 sourced stats.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The global cyber insurance market closed 2025 at nearly US$15 billion in gross written premium per Munich Re's Global Cyber Risk and Insurance Survey 2026, effectively flat against the US$15.3 billion recorded for 2024, with Munich Re projecting around US$28 billion by 2030 at a 15% average annual growth rate across 2020 to 2030. The US market grew slightly and gave up margin doing it: AM Best's June 2026 segment report measured US$7.5 billion of US cyber direct premium written in 2025 against US$7.1 billion in 2024, while the industry-wide cyber loss ratio rose 4.3 points to 53.0%, a second consecutive annual increase, with surplus lines carriers running 55.9% against 50.2% for admitted carriers. Pricing tells the same story. Marsh's Global Insurance Market Index recorded cyber down 7% in Q4 2025, 5% in Q1 2026, and 4% in Q2 2026, the twelfth consecutive quarterly decline, while Howden's 2025 Rebooting Growth report puts cumulative cyber rate decline at roughly 27% from mid-2022 through mid-2025 against approximately US$9 billion of cumulative underwriting profit from 2022 to 2024 at combined ratios averaging 70%. Claims activity is decisive. Coalition's 2026 Cyber Claims Report, covering full-year 2025, found 86% of businesses refused to pay ransoms (a record high) while the average initial demand surged 47% year over year to more than US$1 million, and BEC plus funds transfer fraud drove 58% of all claims. At-Bay's 2026 InsurSec Report measured a 7% frequency rise across more than 100,000 policy years, ransomware severity at US$508K (+16% YoY), Akira behind more than 40% of ransomware claims, and remote-access services as the entry vector for 87% of ransomware claims, with VPN compromise alone driving 73% of identified-vector intrusions. Sophos's State of Ransomware 2026, published in July 2026, put the median ransom payment at US$769K and the median demand at US$698K, with average recovery cost up 11% to US$1.7 million. Named loss events still anchor the loss-ratio narrative: UnitedHealth Group disclosed approximately US$2.457 billion in Change Healthcare costs across full-year 2024, and the July 19 2024 CrowdStrike Falcon update is estimated to have triggered between US$300 million and US$1.5 billion of insured business-interruption losses. This post is the Stingrai research team's 2026 reference page on cyber insurance, with every numeric claim sourced inline to a named primary publisher.

Munich Re's Global Cyber Risk and Insurance Survey 2026 puts the global cyber insurance market at nearly US$15 billion in 2025, effectively flat against the US$15.3 billion it measured for 2024, and projects premium volume reaching around US$28 billion by 2030 at a 15% average annual growth rate across 2020 to 2030 (Munich Re, April 2026; Munich Re Cyber Insurance: Risks and Trends 2025). The US market grew, but gave up margin doing it. AM Best's June 2026 segment report measured US$7.5 billion of US cyber direct premium written in 2025 against US$7.1 billion in 2024, while the industry-wide cyber loss ratio climbed 4.3 points to 53.0%, its second consecutive annual increase (AM Best, June 2026; Risk & Insurance, July 2026). Cyber is still one of the fastest-growing property and casualty lines through 2030, but 2024 and 2025 were the years underwriters proved they could hand back rate and keep writing the business.

Three forces drive the 2026 numbers. Pricing has softened for three straight years. Marsh's Global Insurance Market Index recorded the cyber line down 7% globally in Q4 2025, 5% in Q1 2026, and 4% in Q2 2026, the twelfth consecutive quarterly cyber decline, with Howden's 2025 Rebooting Growth report placing cumulative cyber rate decline at roughly 27% from mid-2022 through mid-2025 (Marsh Q2 2026 GIMI; Marsh Q1 2026 GIMI; Howden 2025 Cyber Report). Underwriting still made money, but less of it. Howden estimates cyber generated approximately US$9 billion in cumulative underwriting profit between 2022 and 2024 with combined ratios averaging 70%, while AM Best's US cyber loss ratio has risen two years running, from 41.6% in 2023 to 48.8% in 2024 and then up 4.3 points to 53.0% in 2025 (AM Best, June 2025; AM Best, June 2026). And named catastrophic events tested capital. UnitedHealth Group disclosed approximately US$2.457 billion in Change Healthcare costs across full-year 2024 (Cybersecurity Dive, March 2025), while the July 19 2024 CrowdStrike Falcon update is estimated by reinsurance brokers to have triggered between US$300 million and US$1.5 billion of insured business-interruption losses against approximately US$5.4 billion in direct Fortune-500 financial impact (Parametrix via Fortune, August 2024; Cybersecurity Dive, August 2024).

This post is the Stingrai research team's canonical 2026 reference for cyber insurance market and claims activity. It assembles more than 80 numeric claims from named primary publishers including Munich Re, Marsh, Aon, Howden, Coalition, At-Bay, NetDiligence, AM Best, Guy Carpenter, Lloyd's of London, the National Association of Insurance Commissioners (NAIC), Allianz Risk Barometer, Sophos, CyberCube, Parametrix, Fitch Ratings, the European Insurance and Occupational Pensions Authority (EIOPA), Marsh McLennan, Microsoft, the European Union (DORA), and US-listed corporates whose SEC filings or court records produced incident-cost figures (UnitedHealth Group, MGM Resorts, Caesars, Mondelez, Zurich). Lead data is Q2 2026 broker pricing (Marsh GIMI, July 2026), AM Best's June 2026 US cyber segment report covering calendar year 2025, full-year 2025 claims telemetry from Coalition and At-Bay, and the Sophos State of Ransomware 2026 survey published in July 2026. Where an older edition is still the most recent, it is labeled with its year. Every figure carries its source, year, and methodology window so any claim can be audited inline.

TL;DR: 12 labeled key stats

Key takeaways

  • The market is profitable but rate-soft. Cumulative cyber underwriting profit of approximately US$9B from 2022 to 2024 and combined ratios averaging 70% kept capital flowing in (Howden 2025 Cyber Report). That capital met flat demand, and the result is twelve consecutive quarterly cyber rate declines on Marsh's index through Q2 2026 alongside a US cyber loss ratio that has risen two years running to 53.0% (Marsh Q2 2026; AM Best, June 2026). Underwriters did not pull back; price-takers did.

  • Claim frequency is rising while paid-ransom shares are falling. Coalition's 2026 dataset, drawn from more than 100,000 policyholders across the US, Canada, UK, Australia, and Germany, found 86% of insured businesses refused to pay ransoms in 2025, up from a 44% pay rate the prior year, even as initial ransom demands jumped 47% to more than US$1 million on average (Coalition 2026). Sophos measured the same direction from a different denominator: median ransom payment fell to US$769K and median demand to US$698K in its 2026 survey (Sophos, July 2026).

  • Remote-access compromise is the dominant ransomware vector by a wide margin. At-Bay's 2026 InsurSec Report measured 87% of ransomware claims entering through remote-access services, with VPN compromise alone driving 73% of identified-vector intrusions (up from 38% in 2023 and 66% in 2024). The single ransomware family Akira accounted for more than 40% of ransomware claims, with average demand US$1.2M, roughly 50% higher than other groups (At-Bay, April 2026; Insurance Business, April 2026).

  • Two named events define recent loss-ratio risk. UnitedHealth's Change Healthcare attack (February 2024) cost the parent US$2.457 billion for full-year 2024 (Cybersecurity Dive, March 2025). The CrowdStrike Falcon update of July 19 2024, although operational rather than malicious, took roughly 8.5 million Windows devices offline; broker estimates of insured business-interruption losses span US$300M to US$1.5B, against US$5.4B of Fortune-500 direct financial impact (Cybersecurity Dive, August 2024; Fortune via Parametrix). The same line covers both kinds of accumulation.

  • MFA and EDR are now under-the-line underwriting, and test evidence is the tie-breaker. Marsh McLennan's 2024 cyber market data showed 41% of cyber applications denied on first submission, with missing MFA and inadequate endpoint protection the top two reasons; the 2025 carrier survey found 96% of cyber insurers mandate enforced MFA and 88% require EDR or MDR on every endpoint (Prescient Solutions; CyberDuo summary of Marsh McLennan 2025). Coalition reported that 94% of organizations hit by ransomware saw threat actors target backups, driving carrier insistence on immutable or offline copies (Coalition 2025). With controls table-stakes, dated penetration test evidence is what separates two otherwise identical submissions (underwriting questions guide).

Methodology

$23

Chart Cyber Ins Market Size

Market size: where the cyber line stands in 2026

Munich Re's longitudinal estimate is the most-cited single figure for global cyber gross written premium. Its Global Cyber Risk and Insurance Survey 2026, published in April 2026 and drawn from more than 9,500 respondents across 20 countries, puts the global cyber insurance market at nearly US$15 billion in 2025 and notes that premium growth has slowed in each of the past three years (Munich Re, April 2026). That is below the US$16.3 billion Munich Re had forecast for 2025 a year earlier, and effectively flat against the US$15.3 billion it measured for 2024, of which more than US$10 billion (69% of global premium) was written in North America (Munich Re Cyber Insurance: Risks and Trends 2025; Industrial Cyber summary). The forward outlook still points up: Munich Re now projects global cyber premium of around US$28 billion by 2030, a 15% average annual growth rate across the 2020 to 2030 decade (Munich Re, April 2026).

Year

Global cyber GWP

Source

2022

~US$13.0B

Munich Re composite

2023

~US$14.0B

Munich Re composite

2024

~US$15.3B

Munich Re 2025

2025

~US$15.0B

Munich Re Survey 2026

2030 (forecast)

~US$28B

Munich Re Survey 2026

Two contextual numbers matter. First, cyber represents less than 1% of total global property and casualty insurance premium volume in 2024, so although headline growth is in double digits, the absolute scale remains small relative to P&C as a whole (Munich Re). Second, the global growth rate has decelerated sharply: Howden's 2025 report measured worldwide cyber premiums growing at roughly 6% CAGR from 2022 to 2024, down from approximately 40% CAGR from 2020 to 2022 (Howden 2025 Cyber Report), and Munich Re's 2026 survey confirms the slowdown has now run three years (Munich Re, April 2026). The post-2022 cyber market is no longer growth-stage; it is a maturing line.

European cyber insurance penetration remains low. Howden reports that only 22% of businesses in Italy carry cyber insurance and 39% in the UK, with more than 70% of companies across France, Germany, Italy, and Spain combined remaining uninsured for cyber (Howden 2025 Cyber Report). Munich Re sizes European cyber premium at US$3.3 billion in 2024, 21% of the global total, growing at a 26% CAGR from 2020 to 2024 and expected to reach 24% of global premium by 2027 (Munich Re Cyber Insurance: Risks and Trends 2025). The opportunity is real; the take-up has been slow.

US market: AM Best, NAIC, and two years of margin compression

The US cyber line is the single most-tracked piece of the global market because of AM Best's annual segment report and NAIC's Cybersecurity Insurance Report. AM Best's June 2026 edition covers calendar year 2025; the NAIC report published in 2025 covers calendar year 2024.

AM Best, calendar 2025: US cyber direct premium written reached US$7.5 billion in 2025 against US$7.1 billion in 2024, and the industry-wide cyber loss ratio rose 4.3 points to 53.0%, its second straight annual increase. Surplus lines carriers, which now write nearly two-thirds of all US cyber premium, ran a 55.9% incurred loss ratio against 50.2% for admitted carriers. Endorsements account for more than 2.5 million of roughly 4.7 million US cyber policies in force, while primary policies represent more than 60% of market premium. Top writers on 2025 direct premium: Chubb at US$629.2M (+12% YoY) and Beazley at US$571M, which moved into second place (AM Best, June 2026; Risk & Insurance, July 2026).

AM Best, calendar 2024: US standalone cyber direct premium written totaled US$7.075 billion, a 2.3% decline from 2023 and the first ever year-over-year drop since AM Best began tracking US cyber data in 2015, with the loss ratio at 48.8% against 41.6% in 2023 (AM Best, June 2025). Top US writers by 2024 direct premium: Chubb US$560.6M (~7.92% market share); Travelers US$535.4M (~7.56%, +39.1% YoY); Fairfax Financial US$360.6M (~5.09%); AXA US$340.4M (~4.81%); At-Bay Specialty US$280M (+344.9% YoY, ~4.00%); Sompo US$262.7M (~3.71%) (Insurance Business / AM Best ranking; BeInsure ranking).

Chart Cyber Ins Top Insurers

NAIC: under reclassified 2024 reporting in NAIC's 2025 Cybersecurity Insurance Report, primary policies generate 65% of cyber premium, excess 31%, and endorsement 4% (NAIC 2025 Cybersecurity Insurance Report). The reclassification cleaned up a long-standing comparability issue between AM Best (which historically counted standalone) and NAIC (which historically counted both standalone and bundled). The US numbers across both publishers now triangulate.

Pricing: twelve straight quarters of cuts

Marsh's Global Insurance Market Index (GIMI) is the canonical broker-side rate benchmark. Its cyber line has now logged twelve consecutive quarterly declines through Q2 2026.

Chart Cyber Ins Premium Rate Index
  • Q2 2026 GIMI: cyber rate down 4% globally, the twelfth consecutive quarterly decline, with -14% IMEA, -10% LAC, and -2% US; the overall global composite fell 6%, its eighth straight quarterly decline (Marsh Q2 2026 release).

  • Q4 2025 GIMI: cyber rate down 7% globally, with regional cuts ranging from -14% in LAC to -3% in US (Marsh Q4 2025 release).

  • Q1 2026 GIMI: cyber rate down 5% globally, with -14% IMEA, -11% LAC, -2% US, and an overall global commercial rate down 5% (the seventh consecutive quarterly decline in overall global commercial insurance rates, of which cyber is the most consistent contributor) (Marsh Q1 2026 release).

  • Aon's 2025 Cyber Risk Report measured a 7% premium decrease in Q1 2025 for cyber buyers (Aon Cyber Risk Report 2025).

  • Howden's 2025 Cyber Report aggregates the trajectory: cumulative cyber rate decline of approximately 27% from mid-2022 through mid-2025 (Howden 2025 Cyber Report; Cyber Insurance News summary).

  • AM Best's US view: the ratings agency counted Q1 2026 as the eighth consecutive quarter of US cyber pricing cuts, with the steepest declines landing in Q4 2025 and Q1 2026 (Risk & Insurance, July 2026).

The pricing trend is consistent across continents and across broker, ratings agency, and primary-publisher data. What it has not done is collapse the underlying profitability of the line: Howden estimates cumulative cyber underwriting profit of approximately US$9 billion between 2022 and 2024 with combined ratios averaging 70% (Howden 2025 Cyber Report). The margin is thinner than it was, though. AM Best's US cyber loss ratio of 53.0% in 2025 sits 11.4 points above the 2023 trough (AM Best, June 2026). The market gave back rate from a position of strength and is now testing how much of that strength was rate.

Loss ratios: AM Best's six-year arc

The clearest profitability series for US cyber is AM Best's loss ratio history (AM Best, June 2025; AM Best, June 2026).

Chart Cyber Ins Loss Ratio

Year

US standalone cyber loss ratio

2020

~67.0%

2021

~65.4%

2022

~43.2%

2023

41.6%

2024

48.8%

2025

53.0%

The arc is a textbook hard-to-soft transition. The 2020 to 2021 peak was the ransomware-driven loss explosion that produced the 2021 to 2022 hard market. The 2022 to 2023 retreat was underwriting tightening (MFA, EDR, incident-response plans, immutable backups) doing its job. The 2024 and 2025 rebound is the soft market biting back: cyber rates fell in every quarter of both years on Marsh's index while claim frequency rose, so loss ratio drifts up. AM Best attributes the 2025 move to pricing cuts eroding premium growth while third-party claims became a larger source of loss uncertainty (AM Best, June 2026; Risk & Insurance, July 2026).

Claims: Coalition's 2026 dataset and At-Bay's full-year 2025

Two annual claims publications now anchor the US-and-allied cyber claims picture: Coalition's Cyber Claims Report (annual since 2022) and At-Bay's InsurSec Report (annual since 2024). Both produce 2026 editions covering full-year 2025 telemetry.

Chart Cyber Ins Claims By Cause

Coalition 2026 Cyber Claims Report (covering full-year 2025; dataset spans more than 100,000 policyholders across the US, Canada, UK, Australia, and Germany) (Coalition 2026):

  • Initial ransom demands surged +47% YoY in 2025 to an average of more than US$1 million.

  • 86% of businesses refused to pay ransoms in 2025, a record high (The Actuary, April 2026).

  • BEC and funds transfer fraud accounted for 58% of all claims in 2025; 52% of FTF claims originated from BEC at an average loss of US$112K, and 71% of FTF claims involved social engineering.

  • Average ransomware claim loss: US$269K in 2025, the most expensive category by claim.

  • Dual-extortion ransomware (encryption + data theft) accounted for 70% of all ransomware claims in 2025; data-theft attacks were 2x+ more expensive than encryption-only.

  • Coalition recovered US$21.8M in stolen funds for policyholders in 2025, average per recovery US$202K.

  • 64% of closed claims produced no out-of-pocket loss for the policyholder, and Coalition Incident Response negotiated ransom reductions averaging 65% where clients did pay.

  • 72% of privacy claims cited the California Invasion of Privacy Act, with 11% of alleged violations involving the Meta Pixel.

The 2025 Cyber Claims Report (covering full-year 2024) provides the comparison base. 44% of policyholders that experienced a ransomware event opted to pay when paying was deemed reasonable and necessary, with Coalition Incident Response negotiating an average 60% reduction for those that paid, and 56% of cyber matters handled with no out-of-pocket payments (Coalition 2025 Cyber Claims Report). Both numbers improved a year later, to a 65% average reduction and 64% of closed claims with no out-of-pocket loss (Coalition 2026). The shift from a 44% pay rate in 2024 to an 86% refusal rate in 2025 is the largest single year-on-year movement in cyber-insurance ransom-payment statistics on record.

At-Bay 2026 InsurSec Report (published April 2026, covering full-year 2025; dataset spans more than 100,000 policy years) (At-Bay, April 2026; Help Net Security, April 2026; Insurance Business, April 2026; Swept.ai summary):

  • +7% YoY rise in overall claim frequency; all-time-high average severity US$221K.

  • Ransomware severity reached US$508K in 2025, +16% YoY, the costliest incident type.

  • Akira ransomware accounted for more than 40% of ransomware claims; average Akira ransom demand US$1.2M, roughly 50% higher than other groups.

  • Remote-access services were the entry vector for 87% of ransomware claims in 2025 (up from 80% the prior year). VPN compromise alone accounted for 73% of identified-vector ransomware intrusions, climbing from 38% in 2023 and 66% in 2024.

  • Financial fraud (BEC) was approximately 30% of all claims for the third consecutive year; email was the initial entry vector in 82% of fraud incidents; average stolen funds US$285K, +16% YoY; largest single fraud loss US$9.65M.

  • Companies under US$25M in revenue saw average claim severity rise 26%, with ransomware severity in that segment reported at US$422K (At-Bay, April 2026; Insurance Business, April 2026).

  • One in three ransomware claims triggered business-interruption coverage; those claims averaged US$510K in severity against US$168K for ransomware claims without BI (At-Bay, April 2026).

  • 86% of Akira attacks occurred in environments where a SonicWall device was present, and two-thirds of Akira attacks landed on nights or weekends (At-Bay, April 2026).

The Aon Q2 2025 cyber-and-E&O update added two notable counterpoints. Global ransomware incident counts fell -6% quarter-over-quarter in Q2 2025, but the average ransomware demand jumped +104% to US$1.13M per case, reinforcing the Coalition observation that fewer cases are bigger (Aon, Q2 2025). Aon's Global 2025 Cyber Risk Report counted 1,228 cyber/E&O incidents reported across Aon broking clients in 2024, +22% YoY, with US-only at 776 reported incidents in 2024, up roughly a third YoY (Aon Cyber Risk Report 2025). Aon also measured ransomware incidents +24% in 2024 versus 2023, with the average ransomware payment falling -77% in 2024 as more victims refused to pay or negotiated demands down.

NetDiligence: 15 years of cyber claims pricing

NetDiligence publishes the most-cited claim-size dataset for cyber insurance, the Cyber Claims Study (now in its 15th annual edition). The 2025 study analyzed 10,402 cyber insurance claims from incidents 2020 to 2024 (NetDiligence 2025; press release; Carrier Management summary).

  • Five-year average incident cost (2020 to 2024 incidents): US$264K for SMEs (under US$2B revenue) and US$10.3M for large companies; crisis-services costs alone averaged US$152K and US$3M respectively (Carrier Management summary of NetDiligence 2025).

  • Insurance payouts covered 32% of total incident cost across all sizes, 69% for SMEs and 27% for large companies (Carrier Management, September 2025).

  • SMEs were 98% of claims by count; large companies 2% of claims but more than 50% of total incident cost.

  • Claim sizes ranged from less than US$1K to more than US$500M.

  • Ransomware initial demands as high as US$150M; ransoms paid as high as US$75M.

  • Business-interruption claims averaged 650%+ higher total incident cost than non-BI claims.

  • Large-enterprise BI claims averaged US$36.1M total, including US$26M in downtime costs.

  • Ransomware incidents with recovery expenses averaged US$961K total, nearly 400% higher than incidents without recovery expenses (Cyber Insurance News summary).

  • 1,864 BEC claims tracked across the 5-year window; 468 BEC claims in 2024 alone; average US$75K per BEC claim.

The NetDiligence numbers explain the dispersion in average vs median claim sizes that confuses some buyers: 2% of claims drive more than half of total cost. SME programs price the median; large-account programs price the long tail.

Sophos State of Ransomware 2026: a parallel survey lens

Sophos's seventh annual State of Ransomware report, published in July 2026, surveys 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the previous 12 months (Sophos, July 2026).

  • 48% of organizations with encrypted data paid the ransom, the second-lowest share Sophos has recorded.

  • 51% of paying organizations negotiated the payment below the original demand.

  • Median ransom demand fell to US$698K, down from US$1.32M a year earlier and US$2M two years earlier.

  • Median ransom payment fell to US$769K, down from US$1M a year earlier, while the average recovery cost rose 11% to US$1.7M.

  • 66% of organizations with encrypted data restored from backups, up 12 percentage points year over year, even as 56% of attacks succeeded in encrypting data (up from 50%).

  • 79% of ransomware attacks began with an identity-based approach; malicious email (26%), phishing (24%), and compromised credentials (23%) were the top root causes, while exploited vulnerabilities fell 14 points to 18%.

The Sophos numbers are not directly comparable to Coalition or At-Bay (different denominator, different respondent universe), but the directional signal is the same: fewer victims are paying, the median payment trajectory is downward, and the cost of recovery keeps rising even when no ransom changes hands. For a cyber insurance buyer that combination means ransom sublimits matter less each year and recovery, forensics, and business-interruption limits matter more.

Allianz Risk Barometer: cyber as #1 risk for the fifth straight year

The Allianz Risk Barometer is the longest-running global business risk survey and a useful triangulation point on demand for cyber insurance.

  • Allianz Risk Barometer 2025: cyber incidents are the #1 global business risk for the fourth consecutive year, with 38% of responses, the largest margin ever. Business interruption #2 with 31% of responses; natural catastrophe #3. A decade earlier in 2015, cyber risk was #8 globally with just 12% of responses (Allianz, January 2025).

  • Allianz Risk Barometer 2026: cyber #1 for the fifth consecutive year, with the highest-ever 42% of responses and a +10ppt margin over AI risk at #2. Cyber ranks #1 across every region (Americas, Asia Pacific, Europe, Africa & Middle East) and across all company-size tiers. Survey: 3,338 risk-management experts from nearly 100 countries (Allianz, January 2026; BusinessWire).

The Allianz signal is unambiguous: cyber risk concern is rising, not plateauing, even as cyber insurance pricing softens. That gap between perceived risk and willingness to pay for coverage is the structural reason European take-up remains low.

Named loss events: Change Healthcare, CrowdStrike, MGM, Caesars

A small number of named events shape industry loss-ratio narrative for the 2024 to 2025 cycle. Each is corroborated by SEC filings or court records.

UnitedHealth Group / Change Healthcare, February 2024. The breach of Change Healthcare's claims-processing platform crippled US prescription, billing, and claims workflows for weeks. Reported impacts:

  • UnitedHealth Group's Q3 2024 disclosure put total full-year 2024 cyber-attack impact at US$2.457 billion (Cybersecurity Dive, March 2025). Direct response and remediation costs alone were over US$1 billion within the first three months.

  • The breach is widely cited as the largest US healthcare cyber-attack disclosure in dollars, although the headline figure is dominated by business impact and customer reimbursement, not insurance recoveries alone.

CrowdStrike Falcon update, July 19, 2024. A faulty channel-file update to the CrowdStrike Falcon endpoint sensor crashed approximately 8.5 million Windows systems worldwide, the largest single IT outage in history (Wikipedia, 2024 CrowdStrike-related IT outages). It was operational, not malicious, but cyber and tech-E&O policies covered a meaningful share of the consequential business interruption. Insured-loss estimates from major brokers and modeling firms span a wide range:

  • Parametrix: approximately US$5.4 billion in direct losses to the Fortune 500 (excluding Microsoft); approximately US$540M to US$1.08B insured (~10% to 20% of direct), out of approximately US$10B to US$15B in industry-wide cyber insurance liabilities (Fortune via Parametrix, August 2024).

  • Guy Carpenter: insured losses of approximately US$300 million to US$1 billion (Cybersecurity Dive, August 2024).

  • CyberCube: insured losses of approximately US$400 million to US$1.5 billion (Cybersecurity Dive).

  • Fitch Ratings: industry-wide impact in the mid- to high-single-digit billion USD range.

  • Hardest-hit Fortune-500 sectors: healthcare US$1.94 billion; banking US$1.15 billion (Parametrix) (Fortune via Parametrix, August 2024).

The CrowdStrike outage is the single best-documented systemic cyber event in primary-source coverage. It stress-tested the cyber line's ability to absorb a non-malicious global IT failure and produced the first concrete spread of insured-loss estimates across multiple modeling firms.

MGM Resorts International, September 2023. In a Form 8-K dated October 5, 2023, MGM estimated an approximately US$100 million negative impact to September Adjusted Property EBITDAR across its Las Vegas Strip Resorts and Regional Operations, plus less than US$10 million of one-time third-quarter expenses for technology consulting, legal fees, and other advisors. The filing states that MGM believed its cybersecurity insurance would be sufficient to cover the financial impact (MGM Form 8-K, October 2023).

Caesars Entertainment Inc., September 2023. Caesars filed a Form 8-K (event date September 7, 2023) disclosing that a social engineering attack on an outsourced IT support vendor let an unauthorized actor copy its loyalty program database, including driver's license numbers and social security numbers for a significant number of members (Caesars Form 8-K). The filing discloses no ransom payment. The widely repeated figure of roughly US$15 million comes from contemporaneous press reporting, not from the company's disclosure, and should be cited that way.

These four events collectively account for the bulk of named-large-loss cyber narrative across 2023 to 2024 and inform the loss-ratio rebound visible in the AM Best 2024 number.

Cyber insurance underwriting requirements in 2026

Marsh McLennan's 2024 cyber-application data showed 41% of cyber insurance applications denied on first submission, with the top denial reasons being missing MFA and inadequate endpoint protection (Prescient Solutions summary). The 2025 Marsh McLennan Cyber Insurance Market Report further measured:

  • 96% of cyber insurers mandate enforced MFA across email, VPN, RDP, cloud apps, and admin accounts (CyberDuo summary of Marsh McLennan 2025).

  • 88% of carriers require EDR or MDR tools deployed across all endpoints.

  • 94% of organizations hit by ransomware saw threat actors target backups (Coalition), driving carrier insistence on immutable / offline backup copies (Coalition 2025).

The list of carrier-mandated controls has hardened over the 2022 to 2025 cycle from a polite preference list into hard underwriting filters. Buyers without enforced MFA on remote-access services, EDR or MDR on every endpoint, an annually tested incident-response plan, immutable backups segregated from production, and patching SLAs against known-exploited vulnerabilities are now routinely declined or surcharged. The Stingrai team's view is that this control list is the floor, not the ceiling. Buyers competing for best-in-class pricing also need to show an offensive testing program, whether that is an annual penetration test or continuous PTaaS coverage on internet-facing assets, plus external attack-surface monitoring.

How insurers and reinsurers priced cyber risk in 2026

The buyer-side view of soft pricing has an insurer-side mirror. AM Best's June 2026 report shows the US market splitting: surplus lines carriers now write nearly two-thirds of US cyber premium and carry the higher loss ratio, 55.9% against 50.2% for admitted carriers, which is where appetite for harder-to-place risk has migrated (AM Best, June 2026; Risk & Insurance, July 2026). Reinsurance softened in step. Guy Carpenter's January 1 2026 renewal report recorded non-proportional cyber rates falling roughly 2.5% to as much as 25% depending on structure, loss experience, and layer position, with ceding commissions flat to two points higher and retentions largely unchanged, alongside new risk excess-of-loss covers, hard retrocession arrangements, and combined property and cyber tail programmes (Guy Carpenter via Reinsurance News, December 2025).

At Lloyd's, underwriting discipline is set through market bulletins rather than price. Bulletin Y5381 (August 2022) required standalone cyber policies to exclude state-backed cyber attacks from March 31, 2023 (Lloyd's Y5381). Bulletin Y5433 (14 May 2024) then tightened the regime: non-compliant Type 7 clauses were barred from new and renewal insurance business incepting from 1 July 2024, dispensations for Type 6 clauses were not renewed, Type 4 clauses that extend cover to state-backed attacks carried out as part of a conventional war were barred entirely for policies incepting from 1 January 2025, and managing-agent clause attestations moved to a twice-yearly cycle beginning 31 January 2025 (Lloyd's Market Bulletin Y5433). Munich Re, the largest cyber reinsurer, frames the same exposure from the accumulation side: first-party claims are 62% of its actively managed cyber claims, malicious events outnumber non-malicious roughly 3 to 1, and ransomware, data breach, business email compromise, and DDoS remain the four main drivers of insured loss (Munich Re Cyber Insurance: Risks and Trends 2026).

The practical consequence for a buyer is simple. Capacity is abundant and price is negotiable, but the questions on the application are not. Carriers competing on price compete harder on control evidence, because control evidence is the only lever left that moves their loss ratio.

What pentest evidence underwriters ask for in 2026

Control attestations on a renewal form are self-reported. Penetration test evidence is the artifact that turns a "yes" on the application into something an underwriter can price against, and it is now a standard attachment on mid-market and enterprise cyber submissions. The specific items carriers and brokers ask for:

  • A dated report from an independent tester, covering the internet-facing perimeter at minimum, with scope, methodology, and testing window stated on the cover page.

  • Severity-ranked findings with a remediation status column, because an underwriter reads the closure rate, not the raw finding count.

  • A retest or remediation-validation letter confirming criticals and highs were fixed, ideally inside the policy period.

  • Evidence that remote-access paths were tested, given that remote-access services were the entry vector for 87% of ransomware claims in At-Bay's full-year 2025 data (At-Bay, April 2026).

  • A stated testing cadence, since a report older than twelve months is routinely discounted and rolling or quarterly evidence is treated more favorably than a single stale snapshot.

We wrote the full walkthrough of the questions carriers ask and the evidence that satisfies each one in pentest evidence for cyber insurance underwriting questions. Budgeting the work is a separate question, and what a penetration test costs in 2026 breaks the numbers down scope by scope. Stingrai's own packages and rates are published on the pricing page.

Stingrai offers one-time assessments and continuous testing programs across applications, cloud, networks, and people, delivered by its penetration testers through PTaaS. A one-time test produces a dated report and retest evidence, while a continuous program keeps findings and remediation status current between renewals. Snipe supports web application testing and joins penetration testers on Hybrid web engagements.

Regulation: war exclusion, state-backed exclusion, and DORA

Three regulatory beats define cyber-insurance coverage scope through 2026.

  • Mondelez vs Zurich settlement, November 2022. The seven-year property/cyber coverage dispute over Mondelez's US$100 million+ NotPetya claim settled in November 2022 without producing precedential court guidance on the "act of war" exclusion (Cybersecurity Dive, November 2022). The settlement was a turning point: it ended the appetite for case-by-case war-exclusion litigation and pushed the market toward explicit cyber-war exclusions in policy wordings.

  • Lloyd's of London state-backed exclusion mandate, effective March 31, 2023. Market bulletin Y5381 (August 2022) required all standalone cyber policies to exclude state-backed cyber attacks at inception or renewal from that date, with explicit attribution criteria and a systemic-impact carve-out, implemented in the market through clauses such as LMA5564 (CSO Online, August 2022; Lloyd's Y5381). Bulletin Y5433 (14 May 2024) tightened the regime again, barring non-compliant Type 7 clauses from 1 July 2024 and conventional-war Type 4 clauses from 1 January 2025 (Lloyd's Y5433). The mandate flows through London market wordings and influences global policy drafting.

  • EU Digital Operational Resilience Act (DORA), application date January 17, 2025. DORA applies to 20 categories of financial entities plus their ICT third-party providers, with administrative penalties up to 2% of total annual worldwide turnover or 1% of average daily global turnover (EIOPA DORA materials). DORA imposes direct ICT-risk management, incident-reporting, third-party-risk, and operational resilience-testing obligations on covered entities and indirectly increases demand for cyber insurance from the EU financial sector.

Outlook: what primary publishers project for 2026

Few primary publishers offer 2026 forecasts. The ones that do have produced a consistent picture:

  • Munich Re: global cyber premium of around US$28 billion by 2030, a 15% average annual growth rate across 2020 to 2030, from a base of nearly US$15 billion in 2025. Munich Re's 2026 threat outlook flags agentic AI, digital supply-chain accumulation, and geopolitically motivated attacks as the key 2026 to 2030 watch items, and reports that nearly 9 in 10 C-level respondents to its 2026 survey do not feel adequately protected (Munich Re Survey 2026; Munich Re Risks and Trends 2026).

  • Marsh: Q2 2026 GIMI shows cyber down 4% globally, the twelfth consecutive quarterly decline, with the gap between US (-2%) and IMEA (-14%) persisting as US underwriters absorb the 2025 loss-ratio rebound. Softening remains a feature of the global commercial market through mid-2026 (Marsh Q2 2026; Marsh Q1 2026).

  • Aon: US$1.13M average ransom demand in Q2 2025 (+104% QoQ) suggests the second half of 2025 and 2026 will see severity rise even as frequency softens. Aon's view is that buyer-friendly conditions will persist into 2026 but capacity discipline is tightening on accumulation accounts (large healthcare, large financial services) (Aon Q2 2025).

  • Howden: cumulative cyber underwriting profit through 2024 of approximately US$9 billion is the float that funds 2026 capacity; Howden explicitly framed its 2025 report as "Rebooting Growth" because the slowdown from 40% CAGR (2020 to 2022) to 6% CAGR (2022 to 2024) requires the next leg of growth to come from underpenetrated sectors and geographies, not from rate increases (Howden 2025 Cyber Report).

  • Guy Carpenter: the January 1 2026 reinsurance renewal cleared with non-proportional cyber rates down roughly 2.5% to 25%, ceding commissions flat to two points higher, and growing demand for non-proportional protection, which means primary carriers enter 2026 with cheaper reinsurance and therefore more room to keep competing on price (Guy Carpenter via Reinsurance News, December 2025).

  • Allianz: cyber risk concern at 42% of responses in 2026, the highest in survey history, with AI risk the fastest-rising parallel (#2 at 32%). The signal is that demand for coverage in 2026 will be driven by AI-enabled incident scenarios more than by traditional ransomware narrative (Allianz Risk Barometer 2026).

The market-watcher consensus across these publishers: rates keep softening into the second half of 2026, severity keeps rising faster than frequency, loss ratios keep drifting up from the 2023 trough, and demand growth comes from European and Asian penetration plus AI-driven risk awareness rather than from US enterprise pricing.

What this means for defenders

For CISOs and risk officers planning 2026 cyber insurance renewal, four operational themes carry over from the 2025 data.

First, MFA and EDR are decision gates, not preferences. 96% of carriers require enforced MFA across remote-access, email, RDP, cloud, and admin accounts, and 88% require EDR or MDR on every endpoint (CyberDuo summary of Marsh McLennan 2025). A 2026 renewal application that does not affirmatively answer both is denied or surcharged on first review (Prescient Solutions).

Second, VPN compromise is the top single ransomware vector by a wide margin, with At-Bay measuring it at 73% of identified-vector intrusions in 2025 and remote-access services overall at 87% of ransomware claims (At-Bay, April 2026). The 2026 Stingrai recommendation is to retire username and password VPN access entirely, move to phishing-resistant authentication (FIDO2 or WebAuthn) on every remote-access path, and put zero-trust network access in front of staff and contractors. Anything less leaves the most-exploited entry vector in place, and it is the first thing an external network penetration test should prove.

Third, third-party and vendor exposure keeps climbing the claims tables. Coalition traced a majority of funds-transfer-fraud losses to social engineering of people rather than technology failures, at 71% of FTF claims, and Munich Re reports that more than two-thirds of large organisations experienced at least one third-party cybersecurity incident in the previous 12 months (Coalition 2026; Munich Re Risks and Trends 2026). Cyber insurance applications now ask granular questions about vendor risk management, support-portal MFA, and third-party access controls. Pre-audit your top 25 vendors against the criteria the carrier will ask about.

Fourth, business-interruption limits are the line item most at risk of being underbought. NetDiligence data shows BI claims averaging more than 650% higher total cost than non-BI claims, with large-enterprise BI averaging US$36.1M (NetDiligence 2025; Carrier Management, September 2025). At-Bay measured one in three ransomware claims triggering BI cover, at US$510K average severity against US$168K without it (At-Bay, April 2026). The CrowdStrike outage produced insured BI losses estimated between US$300M and US$1.5B industry-wide (Cybersecurity Dive, August 2024). Re-test BI sublimits against modeled outage scenarios (single-cloud, single-SaaS-vendor, single-EDR) and realistic downtime, not the optimistic four-hour figure.

Stingrai's offensive-testing programs are built to feed the carrier underwriting questionnaire directly. We run both one-time annual penetration tests and continuous PTaaS coverage, so a buyer can produce either the dated annual report a renewal underwriter expects or rolling evidence between renewals. For organizations that need to demonstrate active vulnerability management to a carrier, our external attack-surface work and red-team simulation produce the audit-ready evidence pack, and the cyber insurance underwriting questions guide maps each control assertion to the artifact that satisfies it.

Frequently Asked Questions

What is the most cited cyber insurance statistic for 2026?

The most cited market figure for 2026 is Munich Re's measurement of nearly US$15 billion in global cyber insurance gross written premium for 2025, effectively flat against the US$15.3 billion it recorded for 2024, with a projection of around US$28 billion by 2030 (Munich Re, April 2026). The most cited US figure is AM Best's June 2026 segment report finding US$7.5 billion of US cyber direct premium written in 2025 against US$7.1 billion in 2024, with the industry-wide loss ratio up 4.3 points to 53.0% (AM Best, June 2026). The most cited claims figure is Coalition's finding that 86% of insured businesses refused to pay ransoms in 2025, a record high, even as the average initial ransom demand jumped 47% year over year to more than US$1 million (Coalition 2026).

How big is the global cyber insurance market in 2026?

Munich Re's Global Cyber Risk and Insurance Survey 2026 puts global cyber insurance gross written premium at nearly US$15 billion in 2025, effectively flat on the US$15.3 billion recorded for 2024, and projects around US$28 billion by 2030 at a 15% average annual growth rate across 2020 to 2030 (Munich Re, April 2026). North America wrote more than US$10 billion of the 2024 total, 69% of global premium, and Europe US$3.3 billion, 21% (Munich Re, 2025). Cyber represents less than 1% of total global property and casualty premium volume, so the line is small relative to P&C as a whole but still among the fastest-growing.

What did cyber insurance rates do in 2025 and 2026?

Marsh's Global Insurance Market Index recorded the cyber line down 7% globally in Q4 2025, 5% in Q1 2026, and 4% in Q2 2026, the twelfth consecutive quarterly decline (Marsh Q2 2026; Marsh Q1 2026). Regional Q2 2026 splits: -2% US, -10% LAC, -14% IMEA. Howden's 2025 Rebooting Growth report places cumulative cyber rate decline at approximately 27% from mid-2022 through mid-2025 (Howden). AM Best counted Q1 2026 as the eighth consecutive quarter of US cyber pricing cuts (Risk & Insurance, July 2026). Rates are softening, but profitability has held: cumulative cyber underwriting profit from 2022 to 2024 was approximately US$9 billion at a 70% combined ratio.

What is the average cyber insurance claim size in 2025?

NetDiligence's 15th Annual Cyber Claims Study, analyzing 10,402 claims from 2020 to 2024, puts the 5-year average incident cost at US$264K for SMEs (under US$2B revenue) and US$10.3M for large companies, with SMEs at 98% of claims by count and large companies driving more than half of total incident cost (NetDiligence 2025). At-Bay's 2026 InsurSec Report measured an all-time-high average claim severity of US$221K across more than 100,000 policy years for full-year 2025 (At-Bay, April 2026). Coalition's 2026 Cyber Claims Report measured an average ransomware claim loss of US$269K in 2025, the most expensive category by claim (Coalition 2026).

How much do most ransomware victims pay in 2025?

Coalition's 2026 Cyber Claims Report found 86% of insured businesses refused to pay ransoms in 2025, a record high, and Coalition Incident Response negotiated an average 65% reduction from the initial demand for the minority that paid (Coalition 2026). Sophos's State of Ransomware 2026 survey of 2,158 IT and cybersecurity leaders across 17 countries found 48% of organizations with encrypted data paid, with median ransom payment US$769K (down from US$1M) and median demand US$698K (down from US$1.32M), while the average recovery cost rose 11% to US$1.7M (Sophos, July 2026). Initial demands are still rising at the top end: Coalition measured average initial demand above US$1 million in 2025, up 47% year over year.

What are carriers requiring before they will write a 2026 cyber policy?

Marsh McLennan's 2024 application data showed 41% of cyber applications denied on first submission, with missing MFA and inadequate endpoint protection the top reasons (Prescient Solutions). Marsh McLennan's 2025 carrier survey found 96% of cyber insurers mandate enforced MFA across email, VPN, RDP, cloud apps, and admin accounts, and 88% require EDR or MDR on every endpoint (CyberDuo). Coalition reports 94% of organizations hit by ransomware saw threat actors target backups, which drove carrier insistence on immutable or offline copies (Coalition 2025). The de-facto 2026 carrier checklist: enforced phishing-resistant MFA, EDR or MDR coverage, immutable backups, an annually tested incident-response plan, patching SLAs against known-exploited vulnerabilities, and a documented offensive-testing program on internet-facing assets (underwriting questions guide).

Does a penetration test lower cyber insurance premiums?

A penetration test does not carry a published discount the way a telematics device does on an auto policy, but it changes the two things that set your price: which carriers will quote you, and what they assume about your control maturity. With 41% of applications declined on first submission and rate softening for twelve straight quarters on Marsh's index, underwriters differentiate on evidence rather than price (Prescient Solutions; Marsh Q2 2026). A dated report from an independent tester, severity-ranked findings, a retest letter closing criticals and highs, and proof that remote-access paths were tested move a submission from "assumed average" to "demonstrated", which is what earns broader terms, higher sublimits, and fewer coverage restrictions. See the cyber insurance underwriting questions guide for the question-by-question mapping and penetration testing cost in 2026 for budget ranges.

Who are the largest cyber insurers in the US?

AM Best's June 2026 report ranks Chubb first on 2025 US cyber direct premium written at US$629.2 million, up 12% year over year, with Beazley moving into second at US$571 million (Risk & Insurance, July 2026). On the prior year's 2024 standalone ranking: Chubb (US$560.6M, ~7.92% market share), Travelers (US$535.4M, ~7.56%, +39.1% YoY), Fairfax Financial (US$360.6M, ~5.09%), AXA (US$340.4M, ~4.81%), At-Bay Specialty (US$280M, ~4.00%, +344.9% YoY), and Sompo (US$262.7M, ~3.71%) (Insurance Business / AM Best). Globally, Munich Re, Allianz, AIG, Beazley, Hiscox, AXA XL, and Tokio Marine HCC rank in the top tier of cyber writers, with Coalition, At-Bay, Resilience, and Cowbell the largest InsurTech-backed cyber specialists. Surplus lines carriers now write nearly two-thirds of US cyber premium (AM Best, June 2026).

What does the CrowdStrike outage tell us about systemic risk?

The July 19 2024 CrowdStrike Falcon update crashed approximately 8.5 million Windows systems worldwide, the largest single IT outage on record (Wikipedia). The event was operational rather than malicious, but cyber and tech-E&O policies covered a meaningful share of the consequential business interruption. Insured-loss estimates from brokers and modeling firms span a wide range: Guy Carpenter US$300M to US$1B, CyberCube US$400M to US$1.5B, Parametrix US$540M to US$1.08B insured of US$5.4B in Fortune-500 direct losses, and Fitch Ratings mid- to high-single-digit billion USD industry impact (Cybersecurity Dive, August 2024; Fortune via Parametrix). Hardest-hit Fortune-500 sectors were healthcare at US$1.94 billion and banking at US$1.15 billion in direct losses. It remains the best-documented systemic cyber accumulation case in primary-source coverage.

How did UnitedHealth's Change Healthcare attack affect cyber insurance?

UnitedHealth Group's disclosures put total full-year 2024 cyber-attack impact at approximately US$2.457 billion, with direct response and remediation costs alone exceeding US$1 billion within the first three months (Cybersecurity Dive, March 2025). It is widely cited as the largest US healthcare cyber-attack disclosure in dollars. The figure is dominated by business impact and customer reimbursement rather than insurance recoveries alone, but it set the ceiling for single-event healthcare cyber loss disclosure and fed the AM Best US loss-ratio rebound that ran to 48.8% in 2024 and 53.0% in 2025 (AM Best, June 2026).

What is DORA and what does it mean for cyber insurance demand?

The EU Digital Operational Resilience Act (DORA) entered application on January 17, 2025, applying to 20 categories of financial entities and their ICT third-party providers, with administrative penalties up to 2% of total annual worldwide turnover or 1% of average daily global turnover (EIOPA). DORA imposes direct ICT-risk management, incident-reporting, third-party-risk, and operational resilience-testing obligations, including threat-led penetration testing for significant entities. The indirect effect on cyber insurance is to increase demand from the EU financial sector through 2026 and 2027. DORA does not mandate buying cyber insurance, but it does mandate the controls that materially reduce the cost of a 2026 renewal.

How do US and European cyber insurance penetration rates compare?

Howden's 2025 Cyber Report found only 22% of businesses in Italy carry cyber insurance and 39% in the UK, with more than 70% of companies across France, Germany, Italy, and Spain combined uninsured for cyber (Howden). Munich Re sizes North America at US$10.6 billion, 69% of 2024 global premium, against Europe at US$3.3 billion, 21%, with Europe growing at a 26% CAGR from 2020 to 2024 and projected to reach 24% of global premium by 2027 (Munich Re, 2025). The structural gap between perceived risk, with cyber ranked the #1 global business risk at a record 42% of responses, and willingness to pay for coverage is why European penetration is the line's biggest 2026 to 2030 opportunity (Allianz Risk Barometer 2026).

Where can I get the latest cyber insurance market data?

The primary publishers to track for cyber insurance market and claims telemetry: Munich Re (annual Cyber Insurance: Risks and Trends report each March, plus the Global Cyber Risk and Insurance Survey each April), Marsh (quarterly Global Insurance Market Index releases), Aon (annual Global Cyber Risk Report and quarterly cyber-and-tech-E&O updates), Howden (annual Cyber Report), Coalition (annual Cyber Claims Report, March or April), At-Bay (annual InsurSec Report, April), NetDiligence (annual Cyber Claims Study, September), AM Best (annual US Cyber Insurance Market Segment Report, June), the NAIC (annual Cybersecurity Insurance Report), Lloyd's of London (market bulletins such as Y5381 and Y5433, plus systemic-risk scenarios), Guy Carpenter (January and mid-year reinsurance renewal reports), Allianz (Risk Barometer, January), Sophos (State of Ransomware, mid-year), and Fitch Ratings, S&P Global, CyberCube, and Parametrix on systemic-risk modeling. SEC Form 8-K filings, the UK Information Commissioner's Office, and EIOPA DORA bulletins produce primary incident and regulatory data continuously.

Put these numbers to work

The figures above describe the threat. A penetration test shows which of them apply to your own applications, cloud and network, with evidence your team can act on. Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with retesting included. Book a free scoping call, get a quote, or read the published pricing.

References

  1. AM Best. US Cyber Insurance Market Segment Reports. June 2025 press release; June 2026 press release; Risk & Insurance summary of the 2026 report.

  2. Allianz Commercial. Allianz Risk Barometer 2025. January 2025. Allianz.

  3. Allianz Commercial. Allianz Risk Barometer 2026. January 2026. Allianz; BusinessWire summary.

  4. Aon. Global Cyber Risk Report 2025. February 2025. Aon; Q2 2025 update; ransomware payouts decline.

  5. At-Bay. 2026 InsurSec Report (full-year 2025 data). April 2026. At-Bay key findings; Help Net Security summary; Insurance Business summary; Swept.ai summary.

  6. BeInsure. Global Ranking of Cyber Insurers. 2025. BeInsure.

  7. Coalition. 2025 Cyber Claims Report. March 2025. Coalition announcement; blog summary.

  8. Coalition. 2026 Cyber Claims Report. April 2026. Coalition; The Actuary, April 2026.

  9. CSO Online. Lloyd's of London to exclude state-backed attacks. August 2022. CSO Online.

  10. Cyber Insurance News. Cyber insurance market down 27 percent, 2026 outlook. 2025. Cyber Insurance News; NetDiligence summary.

  11. CyberDuo. Cyber Insurance Renewal Denied 2026 Checklist. CyberDuo.

  12. Cybersecurity Dive. UnitedHealth's cyber-attack costs reach US$2.3B. March 2025. Cybersecurity Dive; insured losses CrowdStrike, August 2024; Mondelez Zurich settlement, November 2022; CrowdStrike Fortune 500 losses.

  13. EIOPA. Digital Operational Resilience Act (DORA). EIOPA.

  14. Fortune (via Parametrix). CrowdStrike outage Fortune 500 5.4 billion damages. August 2024. Fortune.

  15. Guy Carpenter. January 1, 2026 Reinsurance Renewal Report (cyber section). Reinsurance News summary, December 2025.

  16. Howden. 2025 Cyber Report: Rebooting Growth. September 2025. Howden Group Holdings.

  17. Industrial Cyber. Munich Re sees untapped potential in 15.3B cyber insurance market. 2025. Industrial Cyber.

  18. Insurance Business. The 10 best cyber insurance companies based on US market share. 2025. Insurance Business.

  19. Lloyd's of London. Market Bulletin Y5381, State-backed cyber-attack exclusions, August 2022. Lloyd's. Market Bulletin Y5433, State-backed cyber-attack wordings, 14 May 2024. Lloyd's.

  20. Marsh. Global Insurance Market Index Q4 2025. February 2026. Marsh.

  21. Marsh. Global Insurance Market Index. Q1 2026 release, April 2026; Q2 2026 release, July 2026.

  22. Munich Re. Cyber Insurance: Risks and Trends. 2025 edition, March 2025; 2026 edition, March 2026; Global Cyber Risk and Insurance Survey 2026, April 2026.

  23. NAIC. 2025 Cybersecurity Insurance Report. 2025. NAIC.

  24. NetDiligence. 15th Annual Cyber Claims Study. September 2025. NetDiligence; press release; Carrier Management summary.

  25. Prescient Solutions. Cyber Insurance Requirements 2026 SMB Checklist. Prescient Solutions.

  26. Reinsurance News. Global cyber premium to more than double by 2030 (Munich Re). Reinsurance News.

  27. Sophos. State of Ransomware. 2026 edition, July 2026; 2025 edition, June 2025.

  28. US Securities and Exchange Commission. MGM Resorts International Form 8-K, October 5, 2023; Caesars Entertainment, Inc. Form 8-K, event date September 7, 2023.

  29. Wikipedia. 2024 CrowdStrike-related IT outages. Wikipedia.

Take action with Stingrai

Cyber insurance underwriters in 2026 are reading the same primary-source data this post compiles: rising claim frequency, rising ransom demands, falling pay rates, and a small handful of named events that drive the loss-ratio narrative. Buyers who can demonstrate active offensive-testing programs against their internet-facing surface and their critical internal applications get faster underwriting, lower surcharges, and higher coverage limits.

Stingrai is a Toronto and London based offensive security firm founded in 2021. Stingrai Inc is a CREST-accredited Penetration Testing service provider (firm-level accreditation, separate from individual CREST CRT certifications held by team members). The team publishes vulnerability research and certifications including OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, CRTE, and eWPTX. Stingrai is rated 5.0/5.0 across 19 Clutch reviews, presents original research at DEFCON and BSIDES, and our pentest output supports SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 / 800-171, DORA, and NIS2 compliance evidence.

Three places to start:

  • PTaaS and annual penetration tests: Stingrai delivers both one-time annual engagements and continuous PTaaS programs. Senior pentesters and Snipe, our web-app-focused AI pentest agent trained on more than 6,000 HackerOne reports, test at the same time throughout the engagement, with the team directing where Snipe digs and extending the attack paths it opens. Snipe performs black-box dynamic testing and white-box code review, generates AutoFix pull requests, and runs as a PR-gating check that blocks vulnerable code from being merged. Carrier-aligned reports for Marsh, Aon, and Lockton renewal questionnaires.

  • Penetration Testing: external, internal, web, mobile, cloud, Active Directory, and AI-application engagements, delivered as one-time annual tests or on a continuous schedule. Reports map directly to underwriter control assertions.

  • Read the case studies: customer engagements across SaaS, fintech, healthcare, and gov-tech, with public-permission references.

If your 2026 cyber insurance renewal is up in the next 90 days, book a 30 minute call. Stingrai will return a no-cost gap analysis against the carrier checklist (MFA, EDR, incident-response plan, backup posture, vulnerability management, third-party risk) and a one-page recommendation letter that fits the application form. Package scopes and rates are on the pricing page.

0 views

0

X

Related reading

GDPR Article 32 and Penetration Testing: What Regular Testing Means for EU SaaS
AdvisoriesWeb App Security

GDPR Article 32 and Penetration Testing: What Regular Testing Means for EU SaaS

GDPR never says penetration test. Article 32(1)(d) still requires regular testing. What that means for SaaS processors selling into the EU, with evidence.

19 min read

ISO 27001 Penetration Testing: Annex A Mapping, Frequency and Auditor Evidence (2026)
AdvisoriesWeb App Security

ISO 27001 Penetration Testing: Annex A Mapping, Frequency and Auditor Evidence (2026)

ISO 27001 does not mandate a penetration test. The Annex A control mapping, the real cadence drivers, and the evidence certification bodies accept.

20 min read

Penetration Testing Requirements by Framework: The 2026 Matrix
AdvisoriesNetwork Security

Penetration Testing Requirements by Framework: The 2026 Matrix

Which compliance frameworks actually require penetration testing? PCI DSS, NYDFS and FedRAMP do. SOC 2, ISO 27001 and HIPAA do not. The 2026 matrix.

22 min read

Contents

X