The cyber insurance renewal quote landed on Tuesday. Premium up 28% from last year. The carrier excluded ransomware payments above $50K. They excluded "silent cyber" entirely. They added a sub-limit on business email compromise. The new policy covers maybe 40% of the exposure your old policy covered, at 128% of the old price.
The instinct is to renew anyway. Cyber insurance is the responsible thing, the diligent thing, the thing every advisor recommends. But for an increasing number of mid-market companies, the math has flipped. The premium dollars now produce a better return spent on controls than spent on a policy that excludes most of the loss vectors that would actually fire.
This is the analysis. Not a recommendation to drop coverage — a framework for when dropping it is the right call, when it isn't, and how to tell the difference in dollar terms.
What the insurance industry actually did in 2025
Three structural shifts happened in cyber insurance over the past 18 months. Together they changed the calculus for anyone whose policy is up for renewal in 2026.
Carriers narrowed coverage at the same time they raised premiums. The "all-risk" cyber policies of 2022 are gone. Modern policies carve out ransomware payment caps, social engineering sub-limits, infrastructure-failure exclusions, nation-state attribution clauses, and "known vulnerabilities not patched within X days" denials. The named exclusions list has roughly doubled in policy language between 2023 and 2025.
Carriers shifted from indemnification to control verification. The pre-bind security assessment is now a serious technical evaluation. MFA on every privileged account, EDR coverage on every endpoint, immutable backups, documented incident response capability — without these, the carrier either declines, excludes specific scenarios, or quotes a premium that prices in the absent controls.
Carriers raised the bar on what counts as a "covered incident." Claims denials based on "control failure that the carrier asserts the insured should have prevented" are increasingly common. Even when a claim is paid, the average payout has shrunk relative to total loss; the gap is now routinely $200K–$500K out-of-pocket on a six-figure loss.
In 2022, cyber insurance covered roughly 70–80% of a typical incident's economic loss. In 2026, that ratio is closer to 30–50% for mid-market policyholders, depending on incident type. The premium-to-protection ratio inverted; the question of whether the policy is worth its cost is now a real one for a meaningful slice of the market.
The four-quadrant decision framework
Two questions drive the decision. Plot the answer on this 2x2:
The two thresholds (10% of ALE, 70% scenario coverage) aren't arbitrary. They're the rough breakpoints where the math stops penciling for typical mid-market organizations. Move the thresholds based on your risk appetite, but the structure holds.
How to compute the inputs honestly
1. Premium as a percentage of ALE
You need both numbers. The premium is the renewal quote (annualized if it's multi-year). The ALE is the sum of expected annual losses across your top five cyber scenarios — same FAIR-style five-scenario worksheet that drives the CFO budget defense and the board pack.
The ratio: annual premium ÷ total ALE. If your policy costs $24K and your ALE is $310K, the ratio is 7.7% — solidly in the "renew or negotiate" half of the matrix. If your policy costs $48K against the same $310K, the ratio is 15.5% — you're paying enough for the premium to be a real decision input.
2. Coverage match on likely incidents
This requires reading the policy language scenario by scenario. For each of your top five ALE scenarios, ask: if this incident materialized tomorrow exactly as modeled, would the current policy actually pay out, and for how much of the loss?
For each scenario, score the policy's coverage on a 0–1 scale:
1.0 — policy covers the full incident with no material exclusions or sub-limits
0.7 — covered but with a sub-limit that caps payout below total loss
0.4 — covered in principle but with exclusions likely to apply (e.g., ransomware sub-limit, nation-state carve-out)
0.1 — technically covered but the named exclusions almost certainly apply
0.0 — explicitly excluded
Average across the five scenarios. That's your coverage match percentage. If it's below 70%, the policy is named-cover-only; the dollars don't flow when an incident actually happens.
When dropping is the right call
Dropping cyber insurance is the right call when three conditions are jointly true.
Premium >10% of ALE
The annual premium is materially larger than 10% of your annualized expected loss. You're paying a substantial percentage of expected loss to transfer a fraction of it; the math is upside down.
Coverage match <70%
The policy excludes, sub-limits, or carve-outs the majority of your real scenarios. Most claims you'd file under this policy would either be denied or pay out at far below full loss.
The premium dollars can fund controls that materially reduce ALE
The control investments you'd make with the premium dollars (EDR deployment, MFA enforcement, IR retainer, backup immutability) would reduce the ALE faster than the policy would protect against it. The premium dollars produce a better ROI deployed against the risk than transferred.
If all three are true, dropping the policy and redeploying the premium against controls is the financially rational choice — provided you've done the ALE math honestly. The decision to self-insure isn't a rejection of risk transfer; it's the recognition that the available risk-transfer product no longer prices the risk you actually have.
When you should not drop it
Some scenarios force you to carry cyber insurance regardless of the math. Most fall into one of three categories:
Contractual requirement. Enterprise customer contracts, government contracts, and certain regulated industries (financial services, healthcare) require active cyber coverage at specified minimums. The premium becomes a cost of doing business, not a risk-transfer decision.
M&A in flight. Active cyber coverage is standard in PE and strategic acquirer diligence requirements. Dropping coverage during a deal process signals risk and complicates the transaction. Wait until after close.
Catastrophic-loss exposure. If a single incident could plausibly produce a loss of 20%+ of annual revenue and you couldn't absorb it from cash reserves, insurance is doing its real job — covering the tail. The premium-to-ALE ratio matters less in this case because the policy is bought against the variance, not the expected value.
The middle path: partial coverage + controls investment
For most mid-market companies, the answer isn't binary. The middle path is to drop unnecessary coverage layers (high-cost endorsements, low-payout sub-limits) and redirect those premium dollars into controls. Concretely:
Coverage layers worth keeping
Liability coverage for affected-party claims (the loss vector you can't materially control). Business income interruption for systemic outages (where the loss is real but harder to prevent than to insure). Regulatory defense coverage (legal costs scale faster than the underlying fine).
Coverage layers worth dropping
Ransomware payment coverage that excludes nation-state attribution (almost all material ransomware now traces to such groups). Social engineering coverage with low sub-limits relative to typical BEC losses. "Silent cyber" or other vague indemnifications carriers have systematically eroded.
The carrier conversation: "I'm keeping the liability and BI coverage. I'm dropping the ransomware endorsement, the SE sub-limit, and the silent cyber rider. I'd like a quote against that scoped policy." Most carriers will negotiate; the ones who won't are signaling that the only profitable policy for them is the maximalist one you're already questioning.
The bottom line
Cyber insurance was a clear good in 2022 and a more complicated decision in 2026. The premium structure has detached from the coverage structure for a meaningful slice of the market. The question of whether to renew, drop, or restructure is now a real financial decision — not a default. Run the four-quadrant test honestly, with sourced ALE math underneath. Sometimes the answer is keep the policy. Sometimes the answer is restructure. Sometimes the answer is drop it and invest the premium in controls. The math, not the convention, should decide.
Make the insurance decision with real numbers underneath
vCISO Lite produces the five-scenario ALE math that the insurance renewal conversation depends on — premium-to-ALE ratio, per-scenario coverage match, control investment ROI vs premium dollar. The same dollar-denominated risk methodology that drives the CFO budget defense and the board pack also drives the insurance decision. Built for the 33 million US small and mid-sized businesses that don't have a CISO yet, but need to renew, restructure, or drop a cyber policy with the math behind the choice.
If your cyber insurance renewal is on the calendar, or you're evaluating whether the current policy is doing its job, visit vcisolite.com to learn more and get started.
Where this matters next
Cybersecurity risk assessment: a practical guide — the pillar methodology that produces the ALE numbers the insurance decision rests on.
Cyber risk quantification for mid-market — the FAIR-based five-scenario worksheet that supplies both the ALE total and the per-scenario coverage audit inputs.
How CFOs defend the cybersecurity budget at the board table — when "premium dollars vs control dollars" becomes a real choice, this is the budget-defense format that justifies the redirected spend.
Where this matters next
Cyber Insurance Is Broken Because Carriers Can't See Inside the Policyholder — Property insurance works because adjusters can see the roof. Auto works because police reports document the crash
The Five Controls That Most Move Cyber Insurance Premiums — The renewal came in at $48K, up from $32K. The broker said \
Why Cyber Insurance Premiums Keep Going Up (And the Math Behind 2026's Increase) — The 28% increase on your renewal isn't your posture failing. It's the loss-ratio math catching up to the entire market
Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Team — FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time