AM Best and S&P Flag Cyber Pricing Risks: What Underwriters Should Do at Renewal

AM Best and S&P both flagged cyber pricing risks — flat premium, rising third-party claims. What underwriters should do at renewal.

AM Best and S&P both flagged cyber pricing risks — flat premium, rising third-party claims. What underwriters should do at renewal.

Two of the US cyber insurance market’s most-cited ratings shops — AM Best and S&P Global Ratings — have, in the same week, used the word “risk” to describe what is happening to cyber pricing. AM Best’s market segment outlook pointed to flat-to-down pricing in 2026 even as third-party claim frequency keeps rising. S&P’s take was narrower: cyber pricing power is weak right now, but the underlying insurance product is structurally more volatile than the rating category suggests. Both reports reach the same place by different paths — pricing is failing to keep up with the actual loss curve. For an underwriter looking at a Q3 2026 renewal, that gap is the only thing that matters this week.

What happened

AM Best’s segment outlook, published in late July, projects a third consecutive year of pricing pressure on the US cyber market: rate movement flat to slightly down, with the smallest accounts still seeing the steepest reductions. The market is now in a soft cycle, but with a twist: third-party claim frequency has continued to rise even as direct-loss frequency has flattened. The result is that aggregate loss ratios are drifting up even when the topline looks stable.

S&P Global Ratings, in a separate report that same week, focused on the supply side: cyber pricing power is weakening, but the underlying insurance product is more volatile than the rating category itself implies. The translation for an underwriter is that the financial strength of the carrier matters more than the topline rate — a carrier that has cut prices aggressively to keep share is not necessarily weaker than a carrier that has held firm, but it is exposed differently.

The Insurance Journal round-up of the same data pointed to a third dimension: third-party claims — vendor, supplier, business associate — are now the dominant claim type in many carriers’ portfolios, a structural shift from the direct-loss-driven market of 2020-2023. The migration mirrors what has been happening in healthcare ransomware (where the Klue – Salesforce breach aggregation analysis and the healthcare billers analysis both covered): a single event at a supplier becomes a many-claim event at the carriers.

Why this matters for insurance

The standard renewal cycle is built around a single insured: one tower, one retention, one set of controls, one carrier. When two ratings agencies flag the same cycle from two different angles — AM Best from the demand side, S&P from the supply side — they are describing the same underlying market shape: carriers are competing for share on price, and the cost of that competition is showing up in the loss ratio for the kinds of claims that are now dominant.

For an underwriter, the practical implication is that the topline rate conversation at renewal is no longer the right conversation. The thing that changed is the distribution of where claims come from. A book that priced correctly in 2023 on direct-loss frequency may price incorrectly in 2026 on third-party frequency, even if the topline rate is identical. The carrier that quoted flat is not the same carrier as the one that quoted flat-and-adjusted-sublimits.

This is the same pattern the supply-chain risk analysis for underwriters flagged at the start of the year: when the insured surface widens, the loss curve follows a different shape than the rate model assumes. Two ratings agencies flagging the same cycle in the same week is the macro version of that pattern.

The carrier posture, in business language

A carrier that wants to keep share in 2026 has three moves it can make. The first is to compete on price, which is what most of the top-ten carriers are doing. The second is to compete on coverage, which is where the third-party-gap language starts to appear — endorsements, sublimits, and exclusions that move the risk without moving the rate. The third is to compete on service: pre-breach services, claims handling, panel providers. Each of these has a different underwriting signal.

What the ratings agencies are flagging is the mismatch between the first move and the underlying loss curve. When price is flat and third-party claim frequency is rising, the carrier is subsidizing the gap. For some carriers, that subsidy is sustainable (large diversified book, low expense ratio, big balance sheet). For others, it is not. The underwriting signal at renewal is not the rate — it is the carrier’s posture on coverage and service, and whether the carrier has a track record of moving on coverage under pressure.

For readers who want to model the loss curve quantitatively rather than argue it on instinct, the FAIR risk report tool produces a Monte Carlo loss-exceedance curve that captures the third-party-aggregation tail. For a snapshot of where a carrier’s pricing posture sits relative to peers, the broker scorecard provides a sector-calibrated comparison.

Implications for coverage and underwriting

The ratings-agency convergence forces four renewal-cycle questions that most submissions are not yet asking.

First, sublimits and the third-party gap. Most towers still write ransomware sublimits as if the loss is direct. If the carrier’s portfolio is now dominated by third-party claims, the sublimit that was sized for direct loss is now undersized for the actual loss curve. Re-underwrite the sublimit against the insured’s vendor footprint, not just its own security posture.

Second, service quality and panel pressure. When a carrier’s loss ratio drifts, the pressure shows up first in the panel: which vendors are approved, which are restricted, which are silently de-listed. Ask the carrier for its current panel composition and any recent changes. A carrier that has quietly restricted its panel is a carrier that is managing a loss ratio it is not yet ready to admit.

Third, re-underwriting on third-party exposure. The submission question “do you use a third-party billing vendor” is now underwriting-critical. The follow-up question — “what is the carrier’s posture on third-party claims in this book” — is the renewal cycle’s actual content.

Fourth, the carrier’s coverage stability. S&P’s note that the underlying product is more volatile than the rating category implies is the technical way of saying “the rating may not protect you.” Coverage stability — how the carrier has historically moved on coverage language under pressure — matters more than the rating itself.

Actionable recommendations

  • Underwriters: at Q3 2026 renewal, run the broker scorecard on the carrier book before the rate conversation. Compare the carrier’s pricing posture to its peers. Map the submission’s third-party vendor footprint before quoting sublimits. Re-underwrite ransomware sublimits against the vendor footprint, not the insured’s own security posture.
  • Brokers: walk the client through the third-party-aggregation risk explicitly. The conversation is no longer “what is your MFA” — it is “who are your top five vendors and what is the carrier’s net position on each.” Document the carrier’s response in writing.
  • Insured CISOs and risk engineers: treat the third-party vendor inventory as a renewably relevant artifact. Update it quarterly. The carriers that win the next renewal cycle will be the ones that can answer the third-party-exposure question accurately.
  • Risk managers at carriers: pricing posture is no longer the differentiator — coverage stability is. Surface your coverage-language history at the next broker meeting. Brokers want to know which carriers have moved on coverage under pressure, and which have not.

Takeaway

AM Best and S&P are flagging the same cycle from two angles: flat pricing that has decoupled from the loss curve. For underwriters, the renewal cycle should reframe — from rate to coverage stability, from direct-loss to third-party exposure, from carrier price to carrier posture. The next 90 days of renewals will tell which carriers read the same signals and which did not.

Michael Guiao Michael Guiao founded Resiliently AI and writes Resiliently. He has CISM, CCSP, CISA, and DPO certifications — but let them lapse, because in the age of AI, knowledge is cheap. What matters is judgment, and that comes from eight years of hands-on work at Zurich, Sompo, AXA, and PwC.

Go deeper with premium cyber risk reports

Professional-grade analysis, NIS2 compliance guides, and threat intelligence — used by underwriters across Europe.

Starter

€199 /month

Unlimited scans, submission packets, PDF downloads, NIS2/DORA

View Plans →
Best Value

Professional

€490 /month

Full platform — continuous monitoring, API access, white-label reports

Everything in Starter plus professional tools

Upgrade Now →
30-day money-back
Secure via Stripe
Cancel anytime

Free NIS2 Compliance Checklist

Get the free 15-point PDF checklist + NIS2 compliance tips in your inbox.

No spam. Unsubscribe anytime. Privacy Policy

blog.featured

AM Best and S&P Flag Cyber Pricing Risks: What Underwriters Should Do at Renewal

Cyber Insurance ·

7 min read

One Salesforce Integration Breach Just Hit 200 Cyber Insureds

Cyber Insurance ·

8 min read

The Death of the Questionnaire: Why Underwriters Now Demand EDR Telemetry Before Binding

Underwriting ·

10 min read

WordPress Plugin Flaw CVE-2023-4213 Exposes 10K+ Sites to Cyber Claims

Cyber Risk ·

6 min read

Premium Report

2026 Cyber Risk Landscape Report

24 pages of threat analysis, claims data, and underwriting implications for European cyber insurance.

View Reports →

Related posts

The Five Toxic Powers of Agentic AI — What Underwriters Need to Know
Agentic AI · · 11 min read

The Five Toxic Powers of Agentic AI — What Underwriters Need to Know

Agentic AI introduces five double-edged powers that create toxic risk combinations. Here's how underwriters, brokers, and CISOs should assess the threat.

Agentic Security: What Underwriters Need to Know in 2026
Agentic AI · · 9 min read

Agentic Security: What Underwriters Need to Know in 2026

Autonomous AI agents are entering production at scale — and they bring a completely new attack surface that traditional cyber insurance questionnaires weren't designed to capture.

An AI Agent Deleted a Startup's Production Database — Can You Insure Against That?
AI Agents · · 7 min read

An AI Agent Deleted a Startup's Production Database — Can You Insure Against That?

PocketOS lost its production database to a Cursor AI agent in 9 seconds. The incident exposes a gap in cyber insurance that most policies don't cover: AI-caused operational destruction with no external attacker.