3 min read

Cyber Insurance Market Tightens as Premiums Rise 21 Percent and Insurers Demand Stronger Controls

The cybersecurity insurance market is undergoing its most significant transformation in years as leading insurers announce major changes to policy terms, pricing models, and coverage requirements. Rising claim costs from ransomware and data breaches, combined with the emergence of AI-driven threats, are forcing the industry to rethink how it underwrites and prices cyber risk.

Premiums Rise, Coverage Tightens

Average cyber insurance premiums increased 21 percent in the first half of 2026, according to data from Marsh McLennan, one of the world’s largest insurance brokers. The increase follows two consecutive years of relatively stable pricing and reflects a surge in large-scale ransomware claims and a growing number of incidents involving AI-generated attacks.

Several major insurers have also narrowed their coverage terms. Lloyd’s of London syndicates have introduced explicit exclusions for losses arising from nation-state cyberattacks, a provision that has generated controversy given the difficulty of attributing attacks to specific government actors. AIG and Chubb have implemented sub-limits for ransomware payments, capping the amount they will reimburse for extortion demands.

Minimum Security Requirements

Perhaps the most consequential change is the introduction of mandatory security controls as a condition of coverage. Insurers are increasingly requiring policyholders to demonstrate that they have implemented specific security measures before a policy will be issued. Common requirements now include multi-factor authentication on all remote access systems, endpoint detection and response (EDR) deployment, regular vulnerability scanning, and incident response plan testing.

The AI Factor

The emergence of AI-powered cyberattacks is creating new underwriting challenges. Insurers are struggling to model the frequency and severity of AI-generated threats because historical loss data does not reflect the capabilities of current attack tools. Several underwriters have begun requiring that applicants disclose their use of AI systems and the security controls surrounding those systems.

“AI is changing the threat landscape faster than our actuarial models can adapt,” said Tom Reagan, cyber practice leader at Marsh McLennan. “We are seeing attack techniques today that did not exist in the data we use to price risk.”

Market Dynamics

Despite tightening terms, demand for cyber insurance continues to grow. Regulatory requirements in several jurisdictions now mandate cyber insurance for companies handling sensitive personal data, and board-level awareness of cyber risk has driven increased adoption among mid-market companies.

The market is also seeing the entry of new insurers and the emergence of alternative risk transfer mechanisms. Several insurtech companies have launched parametric cyber insurance products that pay out automatically when predefined conditions are met, such as a confirmed data breach affecting a specified number of records, eliminating the need for lengthy claims investigations.

What Organizations Should Do

Organizations seeking cyber insurance should proactively invest in the security controls that underwriters require, as this can significantly reduce premiums and improve coverage terms. Working with a specialized cyber insurance broker who understands the evolving market is also critical, as policy language varies significantly between carriers.

Companies should also review their existing policies carefully to understand any new exclusions or sub-limits that may have been introduced at renewal. The days of broad, inexpensive cyber insurance coverage appear to be ending, replaced by a more mature market that demands genuine security investment in exchange for meaningful protection.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.