
Cyber Insurance Got Cheaper. Yours Might Not.
Rates are drifting down across the market. What you pay isset by what an underwriter can verify, and the next question on the applicationis already visible.
Executive Summary
· Cyber pricing has been softening, but that is amarket-wide average, not a promise about your renewal. The softness rewardsbusinesses an underwriter can see clearly and quietly skips the rest.
· Claim volume is moving the other way. Nearly50,000 US cyber claims were reported in the 2024 data year, up roughly 40percent, while total premium collected fell. Gaps like that do not stay open.
· The controls that move your price are the sameshort list every year. What changed is that saying you have them is no longerenough. Underwriters want proof, and active vulnerability management is headedfor the application itself.
A Soft Market Is Not a Discount for Everyone
The softening is real. The Council of Insurance Agents andBrokers, which surveys commercial brokers quarterly, recorded an average cyberpremium decrease of 3.2 percent in the second quarter of 2026. WTW's 2026outlook calls cyber renewals roughly flat, in a band of negative 5 to positive5 percent. The National Association of Insurance Commissioners put US cyberdirect written premium at about 9.14 billion dollars for the 2024 data year,down roughly 7 percent and the first decline the market had recorded.
Then the other side of the ledger. NAIC counted nearly50,000 cyber claims reported that same year, an increase of almost 40 percent.Premium down, claims up. Insurers are not being generous. They are competinghard for accounts they consider well run and paying for it by getting farchoosier about who qualifies. WTW says it about as plainly as an insurancereport ever does: underwriting decisions are heavily influenced by the securitycontrols a company has in place. Two companies of the same size, industry, andrevenue get materially different quotes. The variable is what the underwritercan confirm.
What Actually Moves the Number
The control set has been stable for years, so you are notchasing a moving target. Most applications circle the same six things.
1. Multifactor authentication on email, remoteaccess, and administrator accounts. Partial coverage is the most common gap,and the one owners overstate without meaning to.
2. Endpoint detection and response on every companydevice, centrally managed. Legacy antivirus is a different answer, andunderwriters know it.
3. Backups held separately from live systems, withrestores actually tested. Owning backups and proving one comes back are not thesame claim.
4. Patching on a clock, with a shorter clock foranything reachable from the internet.
5. Phishing training and simulation, with recordsyou can produce on request.
6. A written incident response plan somebody haswalked through out loud.
For most small companies the cheapest premium reductionavailable is not a new product. It is closing the gap between what is true andwhat you can show is true. Brokers now ask for tenant screenshots, exportedreports, restore logs, training records. A business that answers in a day lookslike a different risk than one that goes quiet for three weeks, even when thesecurity underneath is identical. That takes a folder and a calendar, not aprogram: once a quarter, capture the evidence for those six items and put itwhere your broker can reach it.
The Question That Is Coming
Now the forecast, unhedged. Within the next couple ofrenewal cycles, active vulnerability management will become anapplication-level requirement for cyber coverage, sitting next to multifactorauthentication as a condition of getting quoted rather than a credit you earn.
The reasoning is arithmetic. NIST reported that submissionsto the CVE catalog, the public index of known software flaws, rose 263 percentbetween 2020 and 2025, and that NIST itself can no longer keep pace with thevolume. FIRST, the incident response industry body, forecasts a median ofroughly 59,000 new vulnerabilities published in 2026. Meanwhile the 2026Verizon Data Breach Investigations Report found that exploiting analready-published flaw is now the most common way attackers get in, at 31 percentof breaches, with only 26 percent of federally listed known-exploited flawsfully remediated and a median 43 days to close one.
Put yourself in the underwriter's chair. A loss drivergrowing fast, correlating directly with claims, and cheap to measure from theoutside. Carriers already do it. Coalition, one of the larger writers of smallbusiness cyber, scans every policyholder from the internet and alerts them whenit spots exposed remote desktop access or an unpatched mail server. Once aninsurer can measure something continuously, it prices it, and the applicationcatches up.
The patching question is about to change shape. Today itreads as yes or no: do you apply critical patches in a timely manner. Expect itto go quantitative. What is your median days to remediate. How manyknown-exploited flaws sit open past 30 days. Who runs your scanning, and may wesee the report. Businesses that answer with a number will pay less than thosethat answer with a paragraph, and eventually the paragraph will not get quoted.
The Takeaway
A soft market is a window, not a gift. Prices fall forbusinesses an underwriter can see clearly, and your renewal is a securityreview with a dollar figure attached. Build the evidence folder first. It isnearly free and it works immediately. Then get a real number for how fast youclose known flaws, because that question is coming.
How Simulint Helps with BlueSphere Shield and Fabric
BlueSphere Shield handles the part a small team cannotstaff. It scans continuously rather than periodically and ranks findings bywhat attackers are actively exploiting, not by severity score alone. BlueSphereFabric covers the other half, automating routine patching so the fix does notwait on a person. Together they produce the record your next application willwant: what was found, how fast it closed, what is open now. See it at https://bluesphere.co.
