Your Cyber Insurance Renewal Went Up. The Market Isn’t Why.

September 14, 2026
September 14, 2026
By Melissa Thornton, CISSP | Cybersecurity Advisory Group | cyberadvisor.tech
Small-business cyber claims: 52% began with an email attack, 98% of claims came from businesses under $2 billion revenue, the average claim at businesses under $25 million revenue was $180,000, and 64% of closed claims resolved with no out-of-pocket loss

Part 1 of 3.

Cyber insurance rates have fallen for twelve consecutive quarters. If your renewal moved the other way, that is not the market — it is a statement about your business, and it is the most actionable message your renewal will give you all year.

There is a particular kind of quiet that follows a cyber insurance renewal coming back forty percent higher than last year. Or coming back with a limit you didn't ask for. Or, occasionally, not coming back at all.

The explanation a business owner usually gets is some version of "the cyber market is tough right now." It's a comfortable answer. It's also, at the moment, not true — and believing it costs you the one thing the renewal was actually trying to tell you.

What the market is actually doing

Global cyber insurance rates fell 4% in the second quarter of 2026 — the twelfth consecutive quarter of declines (Marsh Global Insurance Market Index, Q2 2026). US cyber rates fell 2%. The quarter before that, global cyber was down 5%; the quarter before that, down 7%. Marsh attributes the broader softening — now in its eighth straight quarter of composite decreases — to "abundant capacity and strong insurer competition across all major product lines."

Aon's read is the same: cyber conditions are soft across all five global regions (Aon Q1 2026 Global Insurance Market Overview).

So if your renewal went up, you moved in the opposite direction from a market that has been falling for three years. That is not bad luck, and it is not the cycle. It is a statement about your business specifically.

There's an important caveat, and it's the whole strategic picture for a smaller business. Softening is not distributed evenly by account size. Brokers reporting to the Council of Insurance Agents & Brokers put average premium change in Q2 2026 at −3.7% for large accounts, −1.9% for medium, and just −0.5% for small accounts — across all lines. Cyber specifically fell 3.2%, though CIAB doesn't break cyber out by account size (CIAB Q2 2026 Commercial P/C Market Survey).

The direction is consistent, and it's worth absorbing: the discounts are concentrated at the top of the market. A small business shouldn't expect to be carried along by a softening cycle. If your premium is going to improve, the improvement has to come from your own risk profile.

Why carriers are getting pickier while prices fall

This seems contradictory until you look at the regulator's numbers.

The National Association of Insurance Commissioners compiles what carriers actually file. For data year 2024: total US cyber premium fell about 7% to $9.14 billion. Claims rose almost 40%, to roughly 50,000. And the number of policies in force stayed essentially flat — a change of 0.03% (NAIC Report on the Cybersecurity Insurance Market, data year 2024).

Falling revenue, rising claims, no new customers. That is a market under real pressure, and there are only two ways for a carrier to respond. Compete hard on price for the risks it wants, and price out — or decline outright — the risks it doesn't.

Which is why the softening you read about in the trade press and the increase sitting in your inbox are not in conflict. They are the same phenomenon seen from two sides. Carriers are competing aggressively. They are simply not competing for everyone.

Aon puts the boundary in one sentence: "Risk qualification remains critical and where minimum security standards are not met, capacity is limited."

That's the line worth sitting with. Not "you'll pay more." Capacity is limited — meaning that below a certain standard, the question stops being price and starts being whether anyone will write you at all.

What's actually happening to businesses your size

It helps to know what carriers are seeing, because the picture is less dramatic and more mundane than the headlines suggest.

One of the largest multi-carrier claims studies covering this market analyzed 10,402 claims from 2020 through 2024. Businesses under $2 billion in revenue accounted for 98% of all claims. Their average total incident cost in 2024 was $243,000, against a five-year average of $264,000 (NetDiligence 15th Annual Cyber Claims Study).

The trend for the smallest businesses is the part that should get an owner's attention. Among companies under $25 million in revenue, average claim severity rose 26% year over year to roughly $180,000, ransomware frequency rose 21%, and ransomware severity rose 40% (At-Bay 2026 InsurSec Report, drawn from more than 100,000 policy years).

And what actually causes these claims is rarely cinematic. In At-Bay's book, 52% of claims began with an email attack. Financial fraud alone accounts for 30% of claims, and 82% of that started in email. One carrier's book puts business email compromise and funds transfer fraud together at 58% of all incidents (Coalition 2026 Cyber Claims Report, covering over 100,000 policyholders).

Different carriers write different books and count categories differently, so these figures describe overlapping realities rather than one number. What they agree on is the shape of it: for a small business, the loss is usually someone tricked into moving money or clicking a link, not a sophisticated intrusion.

That matters commercially, because it means the controls that change your insurability are unglamorous and largely affordable.

Why the answers that worked in 2021 don't work now

In the first years after the ransomware surge, cyber applications were short. Many barely asked whether a business had multi-factor authentication at all. A yes was a yes.

That era is over, and the reason is worth understanding. Multi-factor authentication has become a baseline underwriting expectation rather than a differentiator — effectively every applicant now answers yes. When everyone reports a control, reporting it stops telling an underwriter anything.

So underwriters moved to the next question, and the evidence supports them. Analysis linking self-reported controls to actual claims found that phishing-resistant MFA correlated with a 9% lower breach likelihood than MFA that isn't phishing-resistant (Marsh McLennan Cyber Risk Intelligence Center, August 2025). The same analysis found that endpoint detection and response works on a sliding scale — each 25% increase in deployment across an organization's workstations correlated with a further 10% decrease in breach likelihood.

The question is no longer "do you have EDR." It's "on what percentage of your endpoints," and "can you show me."

This is the single biggest change in cyber underwriting, and it's the one most SMBs haven't caught up with. The application that got you a good rate three years ago is being read by a much better-informed reader today.

The part that's genuinely good news

I want to be careful not to turn this into a warning, because the honest read of the situation is optimistic.

A soft market with abundant capacity and intense competition is the best possible environment in which to be a well-controlled risk. Carriers are actively hunting for business they want to write. Every quarter of declining rates is a quarter in which underwriters are looking for reasons to say yes.

It's also worth knowing that most claims are survivable. In one large carrier's book, 64% of closed claims resolved with no out-of-pocket loss to the insured (Coalition, 2026). The system does work — for the businesses that qualify to be inside it.

An increase or a decline, then, isn't a verdict. It's a diagnostic. It tells you where you sit relative to a standard that is now measurable, published, and — unlike most business problems — fixable on a known timeline with a known set of steps.

What it doesn't tell you is which gaps did the damage. Underwriters don't send a report card. That's the subject of the next piece in this series: why finding out what your real answers are requires someone independent of the people who built and run your systems, and why the party filling out your application shouldn't be the party being graded by it.

Where to start this week

Before your next renewal, three things are worth doing regardless of who helps you do them:

  • Find your current application. Read what your business told the carrier. In my experience, most owners have never seen it.
  • Ask when your renewal date actually is, and count back six to nine months. That's your real deadline, because a training cycle with records and a tested backup restore can't be produced in the three weeks before a submission.
  • Get your policy out and read what it covers. Not the certificate — the policy.

If those three steps turn up more questions than answers, that's normal, and it's the reason this work usually needs someone whose only job is to look.

Sources

Next in this series: why your MSP shouldn't be the one filling out your insurance application, and how much coverage you actually need.

Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022

This article is provided for general informational purposes and does not constitute legal, insurance, or coverage advice. Policy terms vary by carrier; read your own form.

Connect with Melissa Thornton on LinkedIn

Related Blogs

September 2, 2026
September 2, 2026

$11.5 Million Is the Average. You're Not Average — And That's the Problem.

Read More
September 1, 2026
September 1, 2026

Nobody Told Them To

Read More
Chart of six 2026 HIPAA settlements showing time from incident to resolution, ranging from about 4.5 to 6.3 years, against a median private equity buyout hold of about 5.4 years
August 26, 2026
August 26, 2026

The Enforcement Lag Is Now Shorter Than Your Hold Period

Read More