Back to Blog

Why Cyber Insurance Premiums Keep Going Up (And the Math Behind 2026's Increase)

The 28% increase on your renewal isn't your posture failing. It's the loss-ratio math catching up to the entire market. The four-year cycle, the structural pressures, and what it means for 2027.

Quick Answer

The 28% increase on your renewal isn't your posture failing. It's the loss-ratio math catching up to the entire market. The four-year cycle, the structural pressures, and what it means for 2027.

Cyber insurance premiums dropped in 2023 and held flat through most of 2024. Brokers got comfortable telling clients the market had stabilized. Then Q1 2025 happened — ransomware incident volume up 126% year-over-year, average loss per incident up 17%, loss ratios at multiple major carriers crossed back into unprofitable territory. By the time the 2026 renewal season opened, S&P had revised the carrier outlook back to negative and brokers were quietly preparing clients for premium increases in the 15–20% range.

The 28% increase on your renewal binder isn't your specific posture failing. It's the underlying loss-ratio math catching up to the entire market. Understanding why matters — because the same dynamics that drove the 2025 hardening will drive the next two renewals, and the policyholders who understand the curve can position for the renewal beyond the next one.

15–20%
forecast cyber insurance premium increase in 2026 after two years of declining rates (S&P Global Ratings, 2026 outlook)
+126%
Q1 2025 ransomware incident volume growth vs Q1 2024 — the proximate trigger of the renewed market hardening
+17%
average per-incident cost increase 2024 → 2025, driven by longer dwell times, larger data exfiltration volumes, and increased regulatory costs (IBM Cost of Data Breach Report, 2025)

The four-year cycle that brought us here

Cyber insurance pricing moves in cycles like every other line of P&C insurance, but the cycle has been shorter and sharper than mature lines because the underlying loss data is thinner. The cycle since 2020 has had four discernible phases:

Period
Market State
Driver
2020–2021
Soft market, premiums declining
Pre-ransomware-surge loss assumptions, abundant capacity, carriers competing for share
2022–2023
Hard market, premiums up 50–100%, capacity withdrawn
Ransomware loss-ratio shock, multiple major carrier exits, capacity scarcity
2024
Soft re-entry, premiums down 5–15%
New capacity entering, ransomware claims temporarily flattening, carriers winning back share
2025–2026
Re-hardening, premiums up 15–20%
Q1 2025 ransomware surge resumed, per-incident severity up, loss ratios crossing unprofitable again

The pattern: each soft phase ends when the loss-ratio data catches up to the pricing. The 2024 soft was always vulnerable because the 2022 hard hadn't permanently rewired the loss dynamics — it just narrowed coverage and improved underwriting in a way that depressed claims for 18 months while threat actors retooled. The Q1 2025 spike was the retooling completing.

The loss-ratio math, explained for non-actuaries

Carriers run a number called the loss ratio: total claims paid divided by total premium earned. Below roughly 60% is profitable (the carrier earns underwriting profit). Between 60% and 100% is unprofitable but recoverable through investment income. Above 100% is structurally unsustainable — the carrier has to either raise premiums, narrow coverage, or exit the line.

The Cyber Loss Ratio Picture in 2025

Major cyber carriers reported 2025 loss ratios in the 78–95% range across the standalone cyber book. Standalone cyber (the policy you actually buy) has been running materially worse than the broader P&C portfolio it sits inside. Carriers absorbed it for a year through investment income gains and reserve releases from the better 2022–2023 vintages. The 2025 data made the absorption strategy untenable; pricing action was inevitable for 2026.

The three structural pressures driving the 2026 hardening

Three forces are operating simultaneously. None of them is going to reverse in the next 12 months.

Ransomware severity is up, not just frequency

Average ransom demand in 2025 was 17% higher than 2024 and 2.4× higher than 2022. Even when no ransom is paid, the incident response cost, the business interruption duration, and the regulatory exposure have all scaled. The same incident type that produced a $400K loss in 2022 produces a $700K loss in 2025.

Regulatory loss costs are scaling faster than incident counts

State breach notification laws, GDPR enforcement actions, SEC cyber disclosure rules, and the federal CIRCIA reporting framework have all added cost to the response side of any incident. The defense-and-notification line on a 2026 incident is materially larger than the same line in 2022.

Underwriting capacity is structurally tighter post-2022

Multiple carriers that exited cyber in 2022 have not returned. The remaining carriers are more conservative in writing new business and more disciplined in re-pricing renewals. There's no longer enough capacity competing for share to soften pricing the way 2024 saw.

Why the Soft Market Won't Return on Its Own

The 2024 soft phase was made possible by new capacity entering the market. That entry was based on the assumption that the 2022 underwriting reforms had permanently reduced loss frequency. The Q1 2025 data falsified that assumption. New capacity isn't going to enter at scale again until either the threat landscape demonstrably stabilizes (no current signal) or the underwriting infrastructure changes in a way that lets carriers actually price the risk (visibility-based underwriting, which is in early build-out). Neither happens in 12 months.

The three responses that work in the current cycle

Faced with a 15–28% renewal increase, policyholders have three rational responses. The choice depends on the premium-to-ALE ratio and the coverage-match score (the same two axes from the renew/restructure/drop decision framework).

Response
When It Fits
What It Looks Like
Renew at the increase
Premium still <10% of ALE; coverage match >70%
Pay the higher premium, accept the carve-outs, keep the relationship. Focus on closing the underwriting score gaps for the next renewal.
Restructure coverage
Premium >10% of ALE but the structural coverage you need is still useful
Drop redundant endorsements, narrow the scope to the layers that fire on your actual scenarios, shop carriers with the narrower scope
Drop and self-insure
Premium >10% of ALE, coverage match <70%, premium dollars produce better ROI as control investment
Decline renewal, redirect premium budget to controls that materially reduce ALE; revisit insurance in 2 years when the market shifts again or visibility-based products mature

What changes the curve

The current cycle is reversible, but the reversal requires a structural change rather than a market-timing change. Two things would shift the dynamics meaningfully:

Threat landscape stabilization. If ransomware incident volume and severity flatten for 18+ months, carriers re-baseline and soft pricing returns. Current signal is the opposite — incidents up, severity up, regulatory cost up. No reversal evident.

Visibility-based underwriting at scale. Carriers who can independently verify continuous control posture price the actual risk rather than the worst-case-imagined risk. Policyholders whose actual posture is better than the market average get priced below the band — pulling the overall pricing distribution wider and creating a competitive opening for carriers willing to write the verified segment. This is in early build-out and is the structural change the market is actually moving toward.

What this means for the 2026 renewal

Assume the 15–20% increase unless your posture is materially better-attested than last year. Use the renewal to test 2–3 carriers, not just the incumbent. Read the policy language for new exclusions — they've been added quietly to multiple carriers' templates in the past 12 months. Don't drop coverage reactively; run the four-quadrant decision framework with sourced ALE math.

What this means for 2027 and beyond

Continuous-attestation evidence will increasingly drive pricing. Policyholders who can supply it walk into renewal in a pricing band the market average can't reach. The premium gap between attested-posture policyholders and questionnaire-only policyholders will widen — by 2028, the difference could be 30–50% on identical revenue and sector.

The bottom line

The 2026 cyber premium increase isn't a temporary spike. It's the loss-ratio math catching up to the structural problems the 2024 soft market papered over. The reversal requires either a threat landscape that flattens for 18 months (not happening) or an underwriting infrastructure change that lets carriers price risk accurately (in build-out, not yet at scale). For the immediate renewal: run the four-quadrant decision honestly. For the 2027 renewal: invest in the continuous-attestation evidence that will increasingly determine which pricing band you sit in.

Position for the 2027 renewal, not just the 2026 one

vCISO Lite produces the continuous-attestation evidence — control posture, dollar-denominated ALE, telemetry-grounded incident readiness — that will increasingly separate the premium bands as the cyber insurance market matures into visibility-based underwriting. Same FAIR-style five-scenario methodology underlying the CFO budget defense and the board pack, exposed in the format the next-generation underwriter actually consumes. Built for the 33 million US small and mid-sized businesses that don't have a CISO yet, but need to walk into the next two cyber renewals in a stronger position than the last two.

If you just got hit with a steep renewal increase, or you're planning ahead for the 2027 cycle, visit vcisolite.com to learn more and get started.

Where this matters next

Cyber insurance is broken because carriers can't see inside the policyholderthe structural reason behind the loss-ratio dynamics that drive the premium cycle.

How cyber insurance underwriters actually score your businesswhat the underwriter sees, and how to walk into renewal in a posture that prices into the better band.

When the risk math says drop the cyber insurance policythe four-quadrant decision framework for the policyholders whose premium-to-ALE math no longer pencils.

The five controls that most move cyber insurance premiumsthe specific investments that move you into the better pricing band the fastest.

Where this matters next

Cyber Insurance Is Broken Because Carriers Can't See Inside the Policyholder — Property insurance works because adjusters can see the roof. Auto works because police reports document the crash

The Five Controls That Most Move Cyber Insurance Premiums — The renewal came in at $48K, up from $32K. The broker said \

When the Risk Math Says Drop the Cyber Insurance Policy — Premium up 28%. Carrier excluded ransomware. The new policy covers 40% of the exposure at 128% of the price

Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Team — FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time

Share this article:

Ready to build your security program?

See how easy it can be.