Cyber insurance premiums dropped in 2023 and held flat through most of 2024. Brokers got comfortable telling clients the market had stabilized. Then Q1 2025 happened — ransomware incident volume up 126% year-over-year, average loss per incident up 17%, loss ratios at multiple major carriers crossed back into unprofitable territory. By the time the 2026 renewal season opened, S&P had revised the carrier outlook back to negative and brokers were quietly preparing clients for premium increases in the 15–20% range.
The 28% increase on your renewal binder isn't your specific posture failing. It's the underlying loss-ratio math catching up to the entire market. Understanding why matters — because the same dynamics that drove the 2025 hardening will drive the next two renewals, and the policyholders who understand the curve can position for the renewal beyond the next one.
The four-year cycle that brought us here
Cyber insurance pricing moves in cycles like every other line of P&C insurance, but the cycle has been shorter and sharper than mature lines because the underlying loss data is thinner. The cycle since 2020 has had four discernible phases:
The pattern: each soft phase ends when the loss-ratio data catches up to the pricing. The 2024 soft was always vulnerable because the 2022 hard hadn't permanently rewired the loss dynamics — it just narrowed coverage and improved underwriting in a way that depressed claims for 18 months while threat actors retooled. The Q1 2025 spike was the retooling completing.
The loss-ratio math, explained for non-actuaries
Carriers run a number called the loss ratio: total claims paid divided by total premium earned. Below roughly 60% is profitable (the carrier earns underwriting profit). Between 60% and 100% is unprofitable but recoverable through investment income. Above 100% is structurally unsustainable — the carrier has to either raise premiums, narrow coverage, or exit the line.
Major cyber carriers reported 2025 loss ratios in the 78–95% range across the standalone cyber book. Standalone cyber (the policy you actually buy) has been running materially worse than the broader P&C portfolio it sits inside. Carriers absorbed it for a year through investment income gains and reserve releases from the better 2022–2023 vintages. The 2025 data made the absorption strategy untenable; pricing action was inevitable for 2026.
The three structural pressures driving the 2026 hardening
Three forces are operating simultaneously. None of them is going to reverse in the next 12 months.
Ransomware severity is up, not just frequency
Average ransom demand in 2025 was 17% higher than 2024 and 2.4× higher than 2022. Even when no ransom is paid, the incident response cost, the business interruption duration, and the regulatory exposure have all scaled. The same incident type that produced a $400K loss in 2022 produces a $700K loss in 2025.
Regulatory loss costs are scaling faster than incident counts
State breach notification laws, GDPR enforcement actions, SEC cyber disclosure rules, and the federal CIRCIA reporting framework have all added cost to the response side of any incident. The defense-and-notification line on a 2026 incident is materially larger than the same line in 2022.
Underwriting capacity is structurally tighter post-2022
Multiple carriers that exited cyber in 2022 have not returned. The remaining carriers are more conservative in writing new business and more disciplined in re-pricing renewals. There's no longer enough capacity competing for share to soften pricing the way 2024 saw.
The 2024 soft phase was made possible by new capacity entering the market. That entry was based on the assumption that the 2022 underwriting reforms had permanently reduced loss frequency. The Q1 2025 data falsified that assumption. New capacity isn't going to enter at scale again until either the threat landscape demonstrably stabilizes (no current signal) or the underwriting infrastructure changes in a way that lets carriers actually price the risk (visibility-based underwriting, which is in early build-out). Neither happens in 12 months.
The three responses that work in the current cycle
Faced with a 15–28% renewal increase, policyholders have three rational responses. The choice depends on the premium-to-ALE ratio and the coverage-match score (the same two axes from the renew/restructure/drop decision framework).
What changes the curve
The current cycle is reversible, but the reversal requires a structural change rather than a market-timing change. Two things would shift the dynamics meaningfully:
Threat landscape stabilization. If ransomware incident volume and severity flatten for 18+ months, carriers re-baseline and soft pricing returns. Current signal is the opposite — incidents up, severity up, regulatory cost up. No reversal evident.
Visibility-based underwriting at scale. Carriers who can independently verify continuous control posture price the actual risk rather than the worst-case-imagined risk. Policyholders whose actual posture is better than the market average get priced below the band — pulling the overall pricing distribution wider and creating a competitive opening for carriers willing to write the verified segment. This is in early build-out and is the structural change the market is actually moving toward.
What this means for the 2026 renewal
Assume the 15–20% increase unless your posture is materially better-attested than last year. Use the renewal to test 2–3 carriers, not just the incumbent. Read the policy language for new exclusions — they've been added quietly to multiple carriers' templates in the past 12 months. Don't drop coverage reactively; run the four-quadrant decision framework with sourced ALE math.
What this means for 2027 and beyond
Continuous-attestation evidence will increasingly drive pricing. Policyholders who can supply it walk into renewal in a pricing band the market average can't reach. The premium gap between attested-posture policyholders and questionnaire-only policyholders will widen — by 2028, the difference could be 30–50% on identical revenue and sector.
The bottom line
The 2026 cyber premium increase isn't a temporary spike. It's the loss-ratio math catching up to the structural problems the 2024 soft market papered over. The reversal requires either a threat landscape that flattens for 18 months (not happening) or an underwriting infrastructure change that lets carriers price risk accurately (in build-out, not yet at scale). For the immediate renewal: run the four-quadrant decision honestly. For the 2027 renewal: invest in the continuous-attestation evidence that will increasingly determine which pricing band you sit in.
Position for the 2027 renewal, not just the 2026 one
vCISO Lite produces the continuous-attestation evidence — control posture, dollar-denominated ALE, telemetry-grounded incident readiness — that will increasingly separate the premium bands as the cyber insurance market matures into visibility-based underwriting. Same FAIR-style five-scenario methodology underlying the CFO budget defense and the board pack, exposed in the format the next-generation underwriter actually consumes. Built for the 33 million US small and mid-sized businesses that don't have a CISO yet, but need to walk into the next two cyber renewals in a stronger position than the last two.
If you just got hit with a steep renewal increase, or you're planning ahead for the 2027 cycle, visit vcisolite.com to learn more and get started.
Where this matters next
Cyber insurance is broken because carriers can't see inside the policyholder — the structural reason behind the loss-ratio dynamics that drive the premium cycle.
How cyber insurance underwriters actually score your business — what the underwriter sees, and how to walk into renewal in a posture that prices into the better band.
When the risk math says drop the cyber insurance policy — the four-quadrant decision framework for the policyholders whose premium-to-ALE math no longer pencils.
The five controls that most move cyber insurance premiums — the specific investments that move you into the better pricing band the fastest.
Where this matters next
Cyber Insurance Is Broken Because Carriers Can't See Inside the Policyholder — Property insurance works because adjusters can see the roof. Auto works because police reports document the crash
The Five Controls That Most Move Cyber Insurance Premiums — The renewal came in at $48K, up from $32K. The broker said \
When the Risk Math Says Drop the Cyber Insurance Policy — Premium up 28%. Carrier excluded ransomware. The new policy covers 40% of the exposure at 128% of the price
Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Team — FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time