Cyber insurance used to be a hedge. Companies paid premiums, the insurance paid out when something went wrong. The market worked, in the way insurance markets work, when the premiums covered the losses. The market is not working now. Premiums are up 200 to 400% over the last 4 years. Coverage is down. Exclusions are everywhere. The insurers are pulling out of the market. The companies that have cyber insurance are finding that the insurance does not cover what they thought it covered. The companies that do not have cyber insurance are finding that they cannot get it. The market is breaking, and the breaking is going to reshape how companies think about cyber risk.
Cyber insurance went through a typical insurance cycle. The early 2010s were the soft market. Premiums were low, coverage was broad, almost anything was insurable. The 2017 to 2020 period was the loss period, with NotPetya, with ransomware, with the major breaches, with the insurers paying out more than they took in. The 2021 to 2024 period was the hard market, with premiums rising fast, with coverage narrowing, with exclusions being added. The 2025 to 2026 period amounts to the exit period, with several major insurers pulling out of the market, with the remaining insurers demanding more from the buyers, with the market starting to consolidate.
The companies that have been relying on cyber insurance as a safety net are discovering that the net has holes. The companies that have not been relying on cyber insurance are discovering that they cannot get a net at all. The market is breaking, and the breaking is structural.
How the cyber insurance market used to work
The cyber insurance market, in the early 2010s, was a growth market. The insurers saw a new line of business. The insurers saw low loss ratios. The insurers competed for market share. Premiums fell. Coverage broadened. The buyers, the companies buying cyber insurance, got more for less. The market was, in the language of insurance, a soft market. Soft markets are good for buyers. Soft markets are bad for insurers, because soft markets end in loss periods.
The buyers, in the soft market, also got a false sense of security. The insurance would pay out. The insurance would cover the breach. The insurance would cover the ransomware payment. The insurance would cover the regulatory fine. The insurance would cover the lawsuit. The buyers did not, in most cases, have to think too hard about what the insurance did and did not cover, because the coverage was broad, and the exclusions were few, and the insurer paid the claim.
The buyers, in the soft market, also reduced their security investment. The insurance was the safety net. The safety net reduced the marginal value of additional security. The companies, in many cases, underinvested in the security they would have otherwise funded. The underinvestment, combined with the rising threat, set up the loss period that was coming.
The 2020 to 2024 loss spiral

The 2020 to 2024 period was the loss period. NotPetya, in 2017, was a warning. The 2020 to 2021 ransomware wave was the trigger. The 2022 to 2023 supply chain attacks, including the 2022 Uber breach, the 2022 LastPass breach, the 2023 MOVEit breach, were the multiplier. The 2024 Snowflake breaches, the 2024 Change Healthcare breach, were the peak.
The losses, in aggregate, were larger than the premiums. The loss ratio, which sits as the ratio of claims paid to premiums collected, was, in some years, above 100%. The insurers were paying out more than they took in. The insurers, as a category, lost money on cyber insurance for 4 consecutive years. The pattern was not sustainable. The insurers responded.
Where the premiums are now
The premiums are up 200 to 400% over the last 4 years, depending on the buyer, the industry, the size of the company, the loss history. A company that paid $50,000 a year for $5 million of coverage in 2020 is now paying $150,000 to $200,000 a year for the same coverage. A company that paid $200,000 a year for $25 million of coverage is now paying $600,000 to $800,000. The premiums have, in many industries, doubled or tripled.
The premium increases have not been uniform. The companies that have had claims have seen larger increases. The companies in high risk industries, healthcare, financial services, retail, have seen larger increases. The companies in low risk industries, software, professional services, have seen smaller increases. The companies with strong security postures, with the documentation to prove it, have seen smaller increases than the companies with weak security postures.
The coverage exclusions
The coverage has narrowed as the premiums have risen. The exclusions, in 2026, are everywhere. The major exclusions include war, which is undefined in cyber terms and which the insurers use to deny claims related to state sponsored attacks. The exclusions include acts of terrorism, which the insurers use to deny claims related to ransomware groups that the insurers decide are terrorist. The exclusions include prior knowledge, which the insurers use to deny claims when the company knew, or should have known, about a vulnerability that was exploited. The exclusions include failure to maintain, which the insurers use to deny claims when the company did not patch a known vulnerability. The exclusions include failure to follow minimum security practices, which the insurers use to deny claims when the company did not have multi factor authentication, or did not have backups, or did not have an incident response plan.
The exclusions are, in many cases, the right exclusions. The exclusions are also, in many cases, broad enough that the insurer can deny almost any claim. The exclusions are, in other words, the way the insurers have reduced their exposure without reducing the premium. The exclusions are the way the insurers have made the policy look like coverage while making the coverage narrower than the buyer thinks.
The market exit
Several major insurers have pulled out of the cyber insurance market entirely. The exit runs as the result of the loss spiral, the regulatory uncertainty, and the legal exposure. The insurers that remain are consolidating. The market, in 2026, is dominated by a smaller number of insurers, with stricter underwriting, with higher premiums, with more exclusions. The buyer, in 2026, has fewer choices, and the choices are worse than they were in 2020.
The market exit has a knock on effect on the broker market. The cyber insurance brokers, in 2020, were an active market, with many buyers, with many insurers, with competitive pricing. The brokers, in 2026, are a consolidating market, with fewer buyers (because the premiums are unaffordable), fewer insurers (because of the exits), and a market that is more about retention than growth. The brokers, in 2026, are also increasingly important, because the policy language is more complex, and the exclusions are more nuanced, and the buyer needs expertise to navigate.
What this means for the buyer
For the buyer, the market breaking means several things. The buyer should expect premiums to continue to rise, in the near term, as the insurers try to catch up to the loss experience. The buyer should expect coverage to continue to narrow, in the near term, as the insurers add more exclusions. The buyer should expect the renewal process to be more difficult, in the near term, as the insurers demand more documentation of the security posture, the controls, the incident response plan.
The buyer should also expect that the insurance, whatever the policy says, will pay out in fewer cases than the buyer thinks. The exclusions are broad. The insurers have lawyers. The claims process is adversarial. The buyer, in 2026, should treat the cyber insurance as a partial hedge, not as a full safety net. The buyer should assume that, in the event of a material breach, the insurance will cover some of the costs, with a fight, and that the buyer will be on the hook for some of the costs, regardless of what the policy says.
What this means for the security program
The market breaking is, in the long run, good for the security program. The market breaking means the cost of risk is being priced, more accurately, by the insurers. The pricing, in turn, is being passed to the buyers. The buyers, in turn, are investing in the security that reduces the premium. The security investment is, in other words, being driven by the insurance market, not by the security industry.
The security program in 2026 is, in many enterprises, being shaped by the insurance underwriting. The insurers want multi factor authentication. The companies implement multi factor authentication. The insurers want tested backups. The companies test the backups. The insurers want an incident response plan. The companies write the plan. The insurers want phishing resistant authentication. The companies roll out passkeys. The security program, in other words, is being driven by the insurance market, and the insurance market is being driven by the loss experience. The feedback loop is, finally, working.
The realistic forecast
The market will, in the next 2 to 3 years, reach a new equilibrium. The equilibrium will have higher premiums than 2020, narrower coverage than 2020, and fewer insurers than 2020. The equilibrium will also have stronger security postures across the buyer base, because the insurers are demanding it. The equilibrium will be a smaller market than 2020, in terms of buyers, because the premiums are unaffordable for some, but the market that remains will be a more functional market, in terms of pricing, than the 2020 market.
The companies that have stayed in the market, with strong security postures, with documented controls, with tested incident response, will continue to be insurable, at premium prices. The companies that have not invested, that have weak security postures, that have not documented their controls, will either pay very high premiums, or will not be able to get coverage at all. The market, in other words, is sorting the buyers. The sort is, in 2026, accelerating.
The bottom line
Cyber insurance is breaking. The premiums are up, the coverage is down, the exclusions are everywhere, the insurers are exiting. The companies that have insurance are finding that the insurance does not cover what they thought it covered. The companies that do not have insurance are finding that they cannot get it. The market is breaking, and the breaking is structural.
The fix is not to wait for the market to recover. The market is not going to recover to the 2020 soft market. The fix is to invest in the security that the insurers are demanding, to document the controls, to test the backups, to deploy the multi factor authentication, to roll out the passkeys. The fix is to treat the insurance as a partial hedge, not a full safety net. The fix is to accept that, in 2026, the security program amounts to the real protection, and the insurance amounts to the financial backstop, and the two are not the same thing.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



