Rates down 32%, severity up 17%: pricing the cyber reinsurance inflection

Cyber reinsurance rates fell sharply at July 2026 renewals while claims severity rose. The rate-severity divergence is the underwriting story of 2026 — wh…

Cyber reinsurance rates fell sharply at July 2026 renewals while claims severity rose. The rate-severity divergence is the underwriting story of 2026 — wh…

On January 1, 2026, cyber aggregate excess-of-loss reinsurance rates fell 32% — the eleventh consecutive quarter of negative rate change. Six months later, at the July 2026 renewals, reinsurers and brokers were still quoting 10–20% declines. At the same time, Carrier Management reported that underlying claims severity had climbed 17% year-over-year, and that ransomware incidents had surged 126% in Q1 2025. This is the inflection: a market where capital is cheaper to buy just as the loss trend is bending the wrong way.

The Inflection: Rates Down 32%, Severity Up 17%

The headline numbers contradict each other, and that contradiction is the story. Cyber aggregate XOL reinsurance rates dropped 32% at the January 1, 2026 renewal, extending what is now more than eleven consecutive quarters of negative rate change. U.S. reinsurance rates followed with an approximately 30% decline at the April 2026 renewal. By July, the softening continued but moderated: rates fell between 10% and 20%, with brokers reporting 15–20% reductions on best-performing programs while reinsurers pegged declines at 10–15%.

Underneath the rate slide sits a deteriorating claims trend. Carrier Management documented in May 2026 that claims severity climbed 17% year-over-year, while ransomware incidents surged 126% in Q1 2025. The Howden Re Cygenesis report, published May 6, 2026, characterizes the cyber market as in its fourth consecutive year of rate softening, observing that capacity has expanded ahead of demand, leaving excess supply concentrated within a largely unchanged buyer base and sustaining lower pricing.

The American Academy of Actuaries, in its February 2026 issue brief, documented that U.S. direct gross written premium actually declined from $7.25 billion in 2023 to $7.08 billion in 2024. For a market that has spent a decade growing double digits, a contracting top line paired with double-digit rate decreases is an unusual combination. It signals that capital is leaving cyber as a destination — not because the risk disappeared, but because the price no longer compensates for the volatility.

Why This Matters for Insurance

Three insurance dynamics deserve attention, and each is observable in the numbers.

First, claims frequency and severity are decoupling in a way that masks loss development. Coalition’s 2026 Cyber Claims Report, released March 5, 2026 and built on more than 100,000 policyholders across five countries, shows overall claims frequency rose just 3% year-over-year to 1.54%, while average claim severity dropped 19% to $116,000. On the surface, that looks like a benign year. Read deeper: ransomware demands surged 47% even as 86% of businesses refused to pay, and 64% of claims resolved at zero cost. The 19% severity decline reflects negotiation outcomes and ransomware non-payment, not a safer threat landscape.

Second, peril composition is shifting inside the same policy form. Coalition found that business email compromise and funds transfer fraud together accounted for 58% of all cyber incidents. Within that bucket, BEC frequency rose 15% YoY while funds transfer fraud frequency fell 18%. The migration from FTF to BEC is consistent with controls hardening against payment fraud while social engineering of executives and vendors intensifies. For underwriters, this is a single policy period producing divergent trend signals on adjacent perils.

Third, the 4.7x frequency ratio between large and small policyholders documented in the Coalition report should reshape how brokers think about segmentation. The same rate per million of limit is buying very different exposure profiles depending on the insured’s size, industry, and revenue band. A flat rate-on-line approach is now structurally biased toward the wrong outcome.

Reading the July Renewal Mechanics

The July 2026 renewal tells us something concrete about where attachment points are heading. Across many programs, attachment points around 115% to 120% loss ratios are now common, and selected portfolios are securing protection attaching below 100%. For a cedant, attaching at 115% means the reinsurer is covering losses only after the primary carrier has burned through more than a full year’s earned premium. Attaching below 100% means the reinsurer is sitting on top of the primary’s loss — a structural shift from risk-bearing to quasi-fronting.

This is the part of the cycle where cedants get generous terms. It is also the part of the cycle where reinsurers accumulate correlated exposure that they cannot easily diversify away. Howden Re’s Cygenesis report flags this directly: a 1-in-200-year event is not required to dislocate the market, because a moderate property-catastrophe equivalent loss could dislocate the market given its concentration and limited diversification. Translation: the cyber book is short natural diversification relative to property cat, and a single coordinated event — a major cloud outage, a supply-chain compromise affecting thousands of policyholders, or a regulatory event triggering mass litigation — would expose every program simultaneously.

The same report warns that a shift toward longer-tailed third-party exposures may delay loss visibility, allowing softening to persist even as performance weakens. This is the actuarial version of the “slow fuse” problem: the rate adequacy you are quoting today is being evaluated against losses that will not emerge for three to seven years.

Implications for Coverage and Underwriting

For underwriters, the immediate task is to stop using rate adequacy as a proxy for risk selection. A cedant quoting 32% lower on a 115% loss-ratio attachment is not necessarily mispricing — the underlying pool may genuinely have shifted — but the deal terms have to be tested against scenario loss exceedance, not against last year’s loss ratio. Underwriters should be asking three questions on every renewal:

  1. What is the cedant’s net-of-reinsurance exposure at the 1-in-100 and 1-in-250 return periods, and how has that changed year over year?
  2. How concentrated is the cedant’s book by industry, revenue band, and technology stack? Concentration ratio is the single best predictor of a mega-loss tail.
  3. What is the cedant’s posture on ransomware payments and vendor risk? The 86% non-payment figure Coalition documents is masking severity, not preventing it.

For brokers, the work is at the placement layer. The widening gap between broker-reported and reinsurer-reported rate decreases (15–20% versus 10–15%) indicates that the best-performing programs are still extracting disproportionate concessions. Brokers should be transparent with clients about which side of that spread their placement sits on, and what it would take to move their cedant into the better-performing cohort. A useful diagnostic is to benchmark the cedant’s primary loss ratio, attritional loss ratio, and large-loss frequency against peers of comparable size. Resiliently’s broker scorecard is structured around exactly this kind of peer comparison and helps quantify where a placement is leaving rate on the table or, conversely, accepting inadequate terms.

For CISOs, the soft market is paradoxically a time to push on coverage quality. Lower premiums reduce the friction for buying higher limits, broader sublimits, and better-defined war and ransomware exclusions. A CISO whose carrier is profitable should be using this renewal to lock in multi-year terms where available, and to negotiate explicit coverage for systemic events (cloud provider outages, common software vulnerabilities) that the 2026 renewal cycle is quietly starting to carve out.

For risk engineers, the concentration signal is the most actionable. The same 4.7x frequency ratio Coalition documents across large versus small policyholders tells you that risk selection has been poor for at least two cycles. Engineering resources should be redirected from generic MFA-and-backup questionnaires toward industry-specific accumulation mapping — cloud tenancy, payroll provider concentration, legal vendor concentration, common ERP platforms — because those are the accumulations a moderate property-cat equivalent event would exploit.

Quantifying the Exposure Before the Market Dislocates

The Howden Re warning deserves operational follow-through, not just acknowledgment. A “moderate property-cat equivalent loss” in cyber means something specific: a single event generating correlated claims across a meaningful slice of the industry’s insured base. Historical reference points include the NotPetya event of 2017, which produced an estimated $10 billion in insured losses, and the MOVEit campaign, which produced thousands of separate claims against carriers over more than 18 months. Neither of those events was a 1-in-200-year shock; both were moderate by property-cat standards.

The actuarial response to this asymmetry is not new pricing — it is new modeling. Carriers and reinsurers that continue to evaluate cyber on annual aggregate loss ratios will mis-price the next dislocation by orders of magnitude. The shift to longer-tailed third-party exposures that Howden Re flags will make that mis-pricing worse by delaying loss emergence. Brokers and cedants who want to lead this market should be able to demonstrate that they are running scenario-based loss exceedance curves and accumulation modeling, not just historical loss ratio trending.

For risk-bearing entities evaluating their own exposure, structured quantification methods like FAIR (Factor Analysis of Information Risk) provide a defensible framework for translating threat frequency and severity assumptions into financial loss distributions. Resiliently’s FAIR risk report is one operational implementation that lets carriers and brokers produce comparable loss exceedance outputs across cedants, which is precisely the analytical standard the current market cycle is demanding.

Actionable Recommendations

For the next 90 days, three actions will materially improve positioning on either side of this market:

  • Map your accumulation exposure by technology vendor, cloud region, and industry vertical. This is the variable the rating agencies and reinsurers will increasingly require on submissions. Cedants who cannot answer accumulation questions in detail will find their renewal terms diverge from the 10–15% reinsurer-reported decline toward something worse.
  • Stress-test attachment points against a property-cat-equivalent scenario, not against last year’s losses. A program attaching at 115% looks generous in a benign year and punitive in a dislocation year. Stress-testing tells you which side of that trade you are on.
  • Track peril migration explicitly in your renewal submission. The BEC-versus-FTF shift Coalition documented is the kind of single-year peril movement that breaks pricing models built on two-year rolling averages. Cedants and reinsurers that surface this in negotiation will price more accurately than those that do not.

For primary insurers writing cyber directly, the soft reinsurance market is an opportunity to buy back into higher aggregate limits and lower attachments. For reinsurers, it is a warning that the next loss will arrive faster than the rate adequacy can adjust. Both of those readings are true simultaneously, and the underwriting decisions made in the next two renewal cycles will determine which side of the inflection each carrier ends up on.

Takeaway

Cyber reinsurance is cheaper than it has been in years. Underlying claims severity is rising. Ransomware incidents are surging. The Howden Re Cygenesis report’s warning — that a moderate property-catastrophe equivalent loss could dislocate the market — is the most important sentence in cyber insurance right now. Brokers, underwriters, and CISOs who treat the next renewal as a pricing exercise will misread the moment. The pricing exercise is downstream of the accumulation, concentration, and peril-migration analysis, and that analysis has to come first. The market is not in a downturn. It is in a quiet period before the next dislocation. How carriers and cedants use that quiet period will determine whether the soft cycle ends with a manageable correction or a market-shaping loss.

Sources

Michael Guiao Michael Guiao gründete Resiliently AI und schreibt Resiliently. Er hat CISM, CCSP, CISA und DPO-Zertifizierungen — aber sie verfallen lassen, denn im Zeitalter von KI ist Wissen billig. Worauf es ankommt, ist Urteilskraft — und die kommt aus acht Jahren Praxis bei Zurich, Sompo, AXA und PwC.

Get the full picture with premium access

In-depth reports, assessment tools, and weekly risk intelligence for cyber professionals.

Starter

€199 /month

Unlimited scans, submission packets, PDF downloads, NIS2/DORA

View Plans →
Best Value

Professional

€490 /month

Full platform — continuous monitoring, API access, white-label reports

Everything in Starter plus professional tools

Upgrade Now →
30-day money-back
Secure via Stripe
Cancel anytime

Free NIS2 Compliance Checklist

Get the free 15-point PDF checklist + NIS2 compliance tips in your inbox.

No spam. Unsubscribe anytime. Privacy Policy

blog.featured

AI Tooling RCE: The Sublimit Layer Underwriters Rarely Underwrite

Cyber Insurance ·

9 min read

SolarWinds SAML Bypass: The IT Ticketing Supply-Chain Path

Cyber Insurance ·

9 min read

AM Best and S&P Flag Cyber Pricing Risks: What Underwriters Should Do at Renewal

Cyber Insurance ·

7 min read

One Salesforce Integration Breach Just Hit 200 Cyber Insureds

Cyber Insurance ·

8 min read

Premium Report

2026 Cyber Risk Landscape Report

24 pages of threat analysis, claims data, and underwriting implications for European cyber insurance.

View Reports →

Verwandte Artikel

Abandoned WordPress Plugin Exposes 12,000+ Sites to Cyber Risk
Cyber Risk · · 5 min read

Abandoned WordPress Plugin Exposes 12,000+ Sites to Cyber Risk

CVE-2023-5336 in iPanorama 360 plugin creates systemic risk for small businesses. SQL injection vulnerability affects unpatched WordPress sites, highlighting third-party component gaps in cyber insurance coverage.

Acronis CVE-2022-46869: How Consumer Software Creates Enterprise Risk
Cyber Risk · · 5 min read

Acronis CVE-2022-46869: How Consumer Software Creates Enterprise Risk

Local privilege escalation vulnerability in Acronis backup software highlights underwriting risks from consumer-grade tools and patch management gaps.

Acronis Privilege Escalation Flaw Exposes Endpoint Security Gaps
Cyber Risk · · 5 min read

Acronis Privilege Escalation Flaw Exposes Endpoint Security Gaps

CVE-2023-41743 highlights critical endpoint protection weaknesses that expand attack surfaces and increase cyber insurance risk exposure for organizations.