Cyber insurance is cheaper than it was during the ransomware panic, but that does not mean every buyer is getting a bargain. The market has moved into a buyer-friendly phase while insurers quietly become more selective about which risks deserve the best terms. Today, the difference between a strong renewal and an ugly one often comes down to security controls, claims history, vendor exposure, and how intelligently the insurance program is structured. In about 15 minutes, you can understand who is winning, who is losing, where the pricing cycle may turn next, and what to do before your next cyber insurance renewal.
Where the Cyber Insurance Market Stands Now
The broad US cyber insurance market remains favorable to buyers in 2026, especially businesses with mature security controls and reasonably clean loss histories.
Marsh reported that US cyber insurance rates declined about 2% in the second quarter of 2026. That continued a run of falling US cyber rates that began in the second quarter of 2023. Globally, cyber pricing fell about 4% in Q2 2026, marking twelve consecutive quarters of global decreases in Marsh's measurement.
That sounds simple: premiums down, buyers win. Unfortunately, insurance markets enjoy making simple statements wear neckties.
The softer headline pricing sits beside a much less comfortable claims picture. The National Association of Insurance Commissioners reported roughly $9.14 billion of US cyber direct written premium for 2024, down about 7% from 2023, while reported claims climbed sharply to nearly 50,000.
In other words, insurers are competing hard for attractive accounts even while the underlying threat has not politely left the building.
- Average rates remain under downward pressure.
- Insurers still scrutinize controls, vendors, privacy exposures, and loss history.
- A soft market is an opportunity to improve coverage, not merely shave premium.
Apply in 60 seconds: Pull your last cyber renewal proposal and circle the premium, limit, retention, and major exclusions so you have a baseline for comparison.
The numbers that matter most
| Indicator | Recent Direction | What It Means for Buyers |
|---|---|---|
| US cyber insurance rates | Generally declining | More negotiating power for good risks |
| Insurer capacity | Broadly stable | Multiple carriers may compete for attractive accounts |
| Ransomware pressure | Persistent | Backup, recovery, MFA, and response controls still matter |
| Vendor concentration risk | Receiving more attention | Dependency mapping increasingly affects underwriting |
| AI-related exposure | Emerging underwriting issue | Expect new questions and policy wording |
I have seen buyers celebrate a 10% premium reduction while failing to notice that a critical sublimit was quietly tightened. The renewal technically became cheaper. The useful insurance became smaller. Champagne may be postponed.
The smarter question is therefore not, "Did my premium fall?" It is, "How much usable protection did I buy per dollar of retained risk?"
How the Cyber Insurance Pricing Cycle Works
Cyber insurance does not move in a straight line. It moves through insurance cycles.
A typical cycle begins with plentiful capacity and aggressive competition. Premiums fall, limits become easier to obtain, retentions decline, and insurers may broaden terms. Eventually claims or catastrophic events erode underwriting profit. Insurers respond by raising prices, restricting coverage, demanding stronger controls, or reducing capacity.
Then profitable pricing attracts capital back into the market. Competition increases. The wheel turns again.
Visual Guide: The Cyber Insurance Pricing Cycle
Insurers compete for attractive cyber accounts.
Rates fall and broader terms become negotiable.
Ransomware, privacy, outages, or systemic events hurt profitability.
Rates rise, underwriting tightens, and capacity becomes more selective.
Remember the 2020–2022 lesson
The previous hard cyber market was not subtle. Ransomware losses surged, insurers discovered that some portfolios had been priced far too casually, and underwriting requirements tightened dramatically.
Businesses that had once answered a short application suddenly faced questions about multifactor authentication, offline backups, endpoint detection, privileged accounts, remote access, employee training, incident response, and vendor dependencies.
A business owner once described the experience to me as going from "buying insurance" to "defending a dissertation about Microsoft 365." Slight exaggeration, perhaps. Emotionally accurate, absolutely.
Why the current soft phase may not last forever
Several forces are keeping the market competitive: insurer capacity, improved cyber controls among buyers, more underwriting data, growing insurance adoption, and sustained competition.
But a soft market contains its own pressure points.
- Ransomware actors continue to demand large amounts.
- Business email compromise remains a frequent source of loss.
- Cloud and software concentration can create correlated losses across many insureds.
- Privacy litigation can develop slowly and become expensive.
- Artificial intelligence may increase attack speed and social-engineering quality.
- Geopolitical events raise difficult questions around war and cyber-operation exclusions.
A major systemic event could therefore change underwriting sentiment remarkably quickly.
Show me the nerdy details
Insurance pricing is influenced by expected claim frequency, expected claim severity, operating expenses, reinsurance costs, capital requirements, investment assumptions, competition, and desired underwriting profit. Cyber adds another difficulty: correlated loss. One vulnerability in a widely used cloud service, security product, operating system, payment processor, or software platform can affect thousands of organizations simultaneously. That makes cyber accumulation modeling fundamentally important to insurers and reinsurers.
The Winners in the Current Market
The biggest winners are not simply large companies. They are organizations that make an underwriter comfortable enough to compete for the account.
Winner 1: Companies with strong identity controls
Credential theft sits at the center of many cyber incidents. Businesses that can document multifactor authentication, privileged-access controls, single sign-on governance, rapid account termination, and sensible administrative permissions generally present a cleaner underwriting story.
This is why the distinction between endpoint protection and identity protection matters. If that distinction is still fuzzy inside your organization, this practical guide to endpoint security vs. identity security is a useful companion read.
Winner 2: Companies with recoverable backups
Having backups is not the same thing as being able to restore operations.
An underwriter may care about isolation, immutability, restoration testing, recovery time, administrative separation, and whether ransomware can encrypt the backup environment along with production systems.
I once heard a technology manager proudly explain that the company had three backup copies. Ten minutes later, someone asked when the organization had last restored a critical production system from them. The room became extraordinarily interested in its coffee.
Winner 3: Businesses with a tested response plan
Incident-response maturity can lower the eventual cost of a cyber event even when prevention fails.
Fast containment can reduce business interruption. Rapid notification of fraudulent transfers can improve recovery odds. Prepared legal, forensic, communications, and restoration workflows reduce the expensive chaos that tends to appear at 2:14 a.m.
- Document MFA coverage rather than saying "we use MFA."
- Record backup restoration tests.
- Maintain an incident-response plan with named owners.
Apply in 60 seconds: Write down the date of your most recent backup restoration test. If nobody knows it, you just found useful renewal work.
Winner 4: Buyers willing to remarket intelligently
A soft market rewards competition, but indiscriminate quoting can create noise.
A broker who understands your security posture can approach appropriate insurers, explain improvements, contrast incumbent terms, and negotiate on more than premium.
The account that merely asks, "Can you beat this price?" may save money. The account that asks, "Can you improve the ransomware retention, dependent-business-interruption wording, sublimits, and incident-response options while maintaining pricing discipline?" is playing a better game.
Winner 5: Security providers tied to insurability
Cyber insurance increasingly creates economic demand for services that help policyholders demonstrate better risk.
That can favor managed security providers, identity-security vendors, backup and recovery services, attack-surface monitoring, managed detection and response, incident-response firms, and governance platforms.
For a broader business view of outsourced cybersecurity economics, see this guide to the managed security services and MSSP business model.
The Losers Paying More or Getting Worse Terms
A soft market is not equally soft for everyone.
Some businesses still receive expensive quotes, restrictive terms, large retentions, or outright declinations because their underlying risk does not meet insurer expectations.
Loser 1: Organizations treating MFA as optional
A company with exposed remote access, weak administrator protection, or inconsistent MFA can still look dangerous even when headline market pricing is falling.
Cyber insurance competition does not repeal arithmetic. An obvious attack path can erase much of the benefit of favorable market conditions.
Loser 2: Businesses with unknown vendor dependencies
Modern companies run on other companies' software.
Payroll, payments, customer databases, cloud infrastructure, productivity suites, authentication, backups, logistics, and communications may all depend on third parties.
If one critical provider disappears for five days, what stops?
Many organizations cannot answer that question cleanly. Insurers care because a single vendor outage can trigger losses across many policyholders at once.
Loser 3: Repeat-loss accounts without credible remediation
A past claim is not automatically fatal. A repeated pattern without meaningful correction is much harder to explain.
Suppose an organization experienced business email compromise, reimbursed the loss, but left payment verification procedures essentially unchanged. The next underwriter may reasonably wonder whether the first claim purchased a lesson or merely an invoice.
Loser 4: Companies buying insurance instead of security
Insurance transfers certain financial consequences. It does not install patches, restore systems, verify wire instructions, rotate credentials, investigate alerts, or negotiate with a furious customer whose personal data is circulating online.
If your organization has suffered an incident, the practical steps in what to do after a data breach complement the insurance discussion here.
A simple cyber insurability scorecard
Quick Risk Scorecard
Give yourself 1 point for every "yes."
- Is MFA required for email, remote access, privileged users, and critical cloud applications?
- Are critical backups isolated or immutable and regularly restoration-tested?
- Is endpoint detection or comparable monitoring deployed broadly?
- Are critical vulnerabilities patched through a defined process?
- Are privileged accounts tightly limited and reviewed?
- Is there a written incident-response plan tested at least periodically?
- Are wire and payment changes verified through a separate communication channel?
- Can you identify critical technology vendors and operational dependencies?
7–8 points: Stronger renewal story, subject to industry, size, loss history, and exposure.
4–6 points: Potentially insurable, but improvements may materially affect terms.
0–3 points: Fix control gaps before assuming the soft market will rescue the quote.
Security Controls That Move Pricing
Underwriters rarely price cyber risk from one magical checkbox. They combine company size, industry, revenue, data, technology, loss experience, security controls, and aggregation exposure.
Still, some controls consistently matter because they attack common causes of severe claims.
Identity and access management
- Multifactor authentication
- Privileged-access restrictions
- Removal of dormant accounts
- Strong administrative separation
- Conditional-access rules
- Controls around remote desktop and VPN access
Endpoint and network protection
- Endpoint detection and response
- Security monitoring
- Patch and vulnerability management
- Network segmentation
- Secure configuration
- Exposure management for internet-facing services
Recovery resilience
- Offline or immutable backups
- Separate backup credentials
- Routine restoration testing
- Documented recovery priorities
- Realistic recovery-time assumptions
Human and financial controls
- Security awareness training
- Phishing resistance
- Out-of-band verification of payment changes
- Dual approval for high-value transfers
- Clear escalation procedures
The useful mental shift is to stop thinking of the insurance application as paperwork. Treat it as a compressed audit of how financially survivable your security program appears.
If you are building that program from scratch, the site's guide to cybersecurity best practices provides additional groundwork.
- "We have backups" is weaker than a documented recovery process.
- "We use MFA" is weaker than knowing exactly which systems are covered.
- "We train staff" is weaker than repeatable verification controls.
Apply in 60 seconds: Replace one vague security statement in your renewal file with a measurable statement containing scope, frequency, or percentage coverage.
Limits, Retentions, and the Real Cost of Coverage
Premium gets the attention because premium arrives with a dollar sign. But the economics of a cyber policy extend far beyond the invoice.
You need to examine at least four moving parts:
- Premium
- Policy limit
- Retention
- Scope of usable coverage
Do not confuse cheaper premium with cheaper risk transfer
Imagine two quotes.
| Feature | Quote A | Quote B |
|---|---|---|
| Annual premium | $22,000 | $18,500 |
| Overall limit | $2 million | $2 million |
| Retention | $25,000 | $50,000 |
| Dependent business interruption | Broader | More restricted |
| Ransomware treatment | Standard retention | Higher ransomware retention |
Quote B saves $3,500 in premium. Whether it is economically superior depends on the probability and size of loss, the policy wording, the company's balance sheet, and how much retained loss it can comfortably absorb.
The lowest premium wins the beauty contest. The best risk-transfer structure wins after something catches fire digitally.
Mini retention calculator
Retention Trade-Off Calculator
This calculator is intentionally simple. A real decision should also consider frequency, aggregate retentions, coinsurance, sublimits, cash reserves, and policy wording.
Coverage tier map
Coverage Tier Map
Foundation: incident response, forensic costs, breach response, restoration, cyber extortion, and core liability coverage.
Operational: business interruption, dependent business interruption, system failure where available, and digital asset restoration.
Financial crime: social engineering, funds transfer fraud, invoice manipulation, and related sublimits where offered.
Complex exposure: privacy regulatory coverage, media liability, technology E&O, contingent exposures, cyber physical damage, and specialized endorsements where applicable.
Not every company needs every layer. A manufacturer, healthcare provider, software company, law firm, retailer, and nonprofit can have completely different loss pathways even at identical revenue.
Ransomware, Vendors, AI, and Systemic Risk
The biggest reason not to extrapolate falling premiums forever is systemic risk.
Cyber insurers do not merely worry about one company being hacked. They worry about one event hitting thousands of companies.
Ransomware is changing, not disappearing
Coalition's 2026 claims reporting found that initial ransom demands among its policyholders surged during 2025, even while most affected businesses refused to pay.
That combination matters. Organizations may be becoming more resilient, but attackers continue testing how much disruption and data theft can be monetized.
A strong backup can reduce the value of encryption. It cannot magically put stolen customer data back inside the server.
Business email compromise deserves more respect
Ransomware receives movie-trailer attention. Business email compromise often arrives wearing a boring invoice.
That makes it dangerous.
Attackers may impersonate executives, suppliers, employees, lawyers, or finance staff and request payments or changes to bank details. The technical sophistication can be modest. The financial consequences are not.
Third-party concentration is the giant shared fuse
Suppose 5,000 insured companies rely on the same software platform. A serious vulnerability in that provider can generate thousands of claims from one root event.
This is why insurers increasingly care about:
- Cloud concentration
- Managed service providers
- Critical SaaS vendors
- Identity providers
- Payment infrastructure
- Software supply chains
Zero-trust design cannot eliminate vendor concentration, but it can reduce unnecessary trust relationships inside your environment. For readers comparing architectures and platforms, see what zero-trust vendors and platforms actually do.
Artificial intelligence adds two underwriting questions
First: how are attackers using AI?
Better phishing, impersonation, automation, reconnaissance, malicious code assistance, and scalable social engineering can affect claim frequency.
Second: how is the insured using AI?
Organizations may expose confidential information through AI tools, deploy AI-generated code, automate decisions, or introduce new operational dependencies.
Insurers are beginning to ask more questions about AI exposure and controls. Expect that line of questioning to become more specific rather than less.
- Map critical vendors and cloud dependencies.
- Review dependent-business-interruption wording.
- Understand exclusions tied to systemic, infrastructure, and war-related events.
Apply in 60 seconds: Name the three outside technology providers whose failure would hurt revenue fastest.
Short Story: The Cheap Renewal That Wasn't Cheap
A midsize professional-services firm received a renewal roughly 12% below the prior year's premium. Everyone was pleased until the operations director compared the schedules line by line. The insurer had increased the ransomware retention, narrowed a dependent-business-interruption provision, and changed how one technology-provider outage would be treated. None of those changes guaranteed a future claim problem, but together they shifted substantially more uncertainty back to the company. The broker returned to the market with a cleaner explanation of the firm's MFA rollout, backup testing, vendor review, and incident-response exercise. A competing insurer offered slightly less headline premium savings but materially better terms. The company chose the second option. The lesson was wonderfully unglamorous: a renewal should be compared as a package of transferred risk, not as a single annual price. Spreadsheet boredom occasionally earns its keep.
How to Approach Your Next Renewal
The current buyer-friendly phase gives well-prepared organizations a rare opportunity: negotiate before the cycle becomes unfriendly again.
Start 90 to 120 days before expiration
Waiting until the final week removes optionality.
Your team needs time to identify control gaps, gather evidence, explain claims, negotiate wording, evaluate competing carriers, and obtain internal approval.
When a renewal becomes a three-day emergency, the insurer owns the clock. Clocks are surprisingly expensive negotiators.
Build a renewal evidence pack
Quote-Prep List
- Current policy and endorsements
- Prior-year premium, limits, retentions, and sublimits
- Three to five years of cyber claims history
- MFA deployment scope
- Endpoint security coverage
- Backup architecture and restoration-test evidence
- Incident-response plan and last exercise date
- Patch and vulnerability-management process
- Critical vendor inventory
- Payment-verification controls
- Major security improvements completed during the year
- Planned security projects with realistic completion dates
Negotiate more than rate
In a competitive market, ask what improvements may be available in:
- Retention
- Ransomware terms
- Business interruption
- Dependent business interruption
- Social-engineering sublimits
- Incident-response vendor choice
- Waiting periods
- Reinstatement options
- Prior acts
- Territory
- Regulatory coverage
- Technology E&O where relevant
Use security investments in the negotiation
A security improvement has two potential financial returns.
One is loss reduction.
The other is improved insurability.
If you recently deployed stronger identity controls, endpoint monitoring, immutable backups, network segmentation, or managed detection, make sure the underwriting submission explains what changed and when.
A beautiful control nobody tells the underwriter about has limited negotiating talent.
Common Cyber Insurance Buying Mistakes
Mistake 1: Shopping only on premium
A cheaper policy with a bigger retention, narrower wording, weaker sublimits, or less useful vendor coverage may be economically worse.
Compare the architecture of the policy, not only its sticker price.
Mistake 2: Assuming all cyber policies are interchangeable
Cyber insurance is not a commodity contract.
Definitions, exclusions, conditions, waiting periods, vendor provisions, ransomware treatment, social-engineering coverage, incident-response requirements, and sublimits can differ substantially.
Mistake 3: Giving vague answers on the application
Applications deserve technical verification.
If someone writes "100% MFA" because the company uses MFA somewhere, but a legacy remote-access system remains outside the rollout, the organization may create a serious problem.
Ask IT, security, finance, legal, and operations to validate material statements rather than routing the application through one exhausted person with a keyboard and optimism.
Mistake 4: Ignoring insurance requirements inside customer contracts
Customers may require particular cyber limits, technology E&O limits, additional terms, notification obligations, or evidence of coverage.
Buying $1 million because it "sounds normal" is poor strategy when your largest contract requires $5 million.
Mistake 5: Ignoring insurer services
Some cyber insurers offer attack-surface monitoring, vulnerability alerts, incident-response hotlines, tabletop resources, vendor access, or other risk-management services.
These services should not replace your security program, but unused prevention services are a peculiar kind of expensive furniture.
Mistake 6: Failing to understand notice obligations
When an incident appears, contact the appropriate broker, insurer, counsel, or response channel promptly according to the policy.
Insurance disputes about late notice can become painful in many coverage contexts. The broader principle is familiar from this discussion of insurance claims denied for late notice: know your policy's reporting conditions before an emergency.
- Compare wording and sublimits.
- Validate application answers.
- Know incident-notification procedures before an event.
Apply in 60 seconds: Find the cyber incident reporting contact shown on your policy or insurer materials and store it in your response plan.
Who This Is For and Not For
This guide is especially useful for
- Small and midsize US businesses preparing for cyber insurance renewal
- CFOs and controllers comparing premium against retained risk
- CISOs and IT leaders supporting insurance applications
- Business owners buying cyber insurance for the first time
- Risk managers evaluating limits, retentions, and carrier competition
- Managed service providers helping clients improve insurability
- Investors studying how cyber pricing cycles affect insurers and security vendors
This guide is not a substitute for
- Advice from a licensed insurance professional familiar with your business
- Legal interpretation of a specific insurance policy
- Actuarial analysis of expected losses
- A technical cybersecurity assessment
- A forensic investigation after an incident
Cyber risk is unusually company-specific. Two firms with identical revenue can have radically different exposures because one processes healthcare data while the other operates industrial machinery, or one writes software while the other holds customer funds.
When to Seek Professional Help
Cyber insurance deserves professional attention when a mistake could materially alter your balance sheet, contractual obligations, or ability to recover after an incident.
Talk with a qualified broker when
- Your revenue or cyber exposure has changed substantially.
- You are buying cyber coverage for the first time.
- You have experienced a recent cyber claim.
- Your incumbent insurer materially changes wording or retention.
- You require higher limits or a layered insurance tower.
- You operate in healthcare, finance, technology, critical infrastructure, or another high-exposure field.
- Major customer contracts impose insurance requirements.
Talk with coverage counsel when
- A substantial claim may be disputed.
- There is uncertainty around exclusions or policy conditions.
- Multiple policies may respond to the same event.
- A major ransomware, privacy, or business-interruption event occurs.
- You face regulatory or contractual notification issues.
Bring in cybersecurity specialists when
- You cannot verify the accuracy of underwriting answers.
- Critical systems lack MFA or modern endpoint protection.
- Backups have never been restoration-tested.
- You do not know which vendors are operationally critical.
- Your incident-response plan exists mainly as a file nobody has opened.
For companies wanting a simple visual method to communicate technical exposure to leadership, this related guide to cybersecurity risk heatmaps may also help.
Cyber Insurance Safety and Financial Disclaimer
This article is general educational information, not insurance, legal, cybersecurity, investment, accounting, or actuarial advice. Coverage depends on the actual policy language, endorsements, exclusions, facts of a loss, jurisdiction, insurer interpretation, and applicable law. Cybersecurity controls also vary by organization. Before changing coverage, limits, retentions, or security practices, consult appropriately qualified professionals who can evaluate your specific exposure.
FAQ
Is the cyber insurance market currently soft or hard?
As of 2026, the broad cyber insurance market remains relatively soft and buyer-friendly. Capacity is available, competition remains meaningful, and average rates have generally declined. However, underwriting remains selective. Companies with weak controls, poor loss histories, difficult industries, or unusual systemic exposures may not experience the same favorable conditions.
Are cyber insurance premiums going down in 2026?
Average cyber rates have continued to decline in major market indices. Marsh reported a roughly 2% decline in US cyber insurance rates in the second quarter of 2026 and a 4% decline globally. Individual accounts can move very differently depending on claims history, security posture, revenue, industry, limits, and coverage structure.
Why are cyber insurance rates falling when cyberattacks are still increasing?
Insurance prices reflect more than attack volume. Competition among insurers, available capital, underwriting improvements, better security controls among insured companies, loss experience, reinsurance, and growth objectives all matter. A market can therefore remain competitive even while the underlying threat environment stays serious.
What cybersecurity controls help lower cyber insurance premiums?
Commonly important controls include multifactor authentication, endpoint detection and response, secure backups, tested restoration procedures, patch management, privileged-access controls, employee training, payment verification, incident-response planning, and vendor-risk management. The exact impact depends on the insurer and the company's exposure.
Does MFA guarantee cheaper cyber insurance?
No. MFA is important, but pricing depends on the entire risk. An insurer may examine where MFA is deployed, whether administrators and remote users are protected, the company's loss history, industry, revenue, backups, endpoint security, vulnerability management, vendors, and other factors.
How much cyber insurance should a business buy?
There is no universal limit. A business should consider plausible incident-response costs, business interruption, data restoration, regulatory exposure, contractual obligations, customer claims, technology dependencies, ransomware scenarios, and balance-sheet capacity. Contractual insurance requirements can also create a minimum practical limit.
Is a higher cyber insurance retention worth the premium savings?
Sometimes. A financially strong company may choose a higher retention when the premium reduction adequately compensates it for retaining more predictable losses. A smaller company with limited liquidity may prefer a lower retention. The decision should consider both expected loss frequency and the company's ability to fund an incident immediately.
What is dependent business interruption coverage?
Dependent business interruption can cover qualifying losses when a covered cyber incident at certain third parties disrupts the insured company's operations. Definitions, covered providers, waiting periods, sublimits, triggers, and exclusions vary substantially, so the wording deserves careful review.
Does cyber insurance cover ransomware?
Many cyber policies provide some form of ransomware-related coverage, potentially including incident response, restoration, business interruption, negotiation, and extortion payments where legally permissible. Coverage is subject to policy terms, retentions, sublimits, exclusions, sanctions considerations, and insurer requirements.
Can cyber insurance cover business email compromise?
Some policies provide coverage for funds-transfer fraud, social engineering, or related losses, but the coverage may be subject to separate definitions, sublimits, conditions, or exclusions. Do not assume a standard cyber liability limit automatically applies to every fraudulent transfer.
Could cyber insurance prices rise again?
Yes. A significant ransomware wave, systemic cloud outage, software supply-chain event, worsening privacy losses, reinsurance pressure, capacity withdrawal, or unexpectedly poor insurer profitability could harden the market. Pricing cycles are normal in commercial insurance, which is why favorable markets are useful times to improve program structure rather than assuming cheaper conditions will continue indefinitely.
Should a small business buy cyber insurance?
A small business should at least evaluate the exposure if it depends on computers, cloud services, online payments, customer information, email, vendors, or electronic funds transfers. Small companies may have lower absolute losses than large enterprises, but they also frequently have less cash available to absorb incident response and downtime.
Conclusion
The cyber insurance market currently gives many US buyers something insurance rarely hands out for free: negotiating room.
Rates have been declining, capacity remains available, and strong risks can often seek better terms. Yet ransomware, business email compromise, vendor concentration, privacy claims, cloud dependence, and emerging AI exposures mean the underlying risk has not become gentle.
That resolves the apparent contradiction from the beginning. The winners are not merely the companies paying less. They are the companies using the soft market to buy better protection while improving the controls that keep them insurable when the pricing cycle eventually turns.
Your best next step takes less than 15 minutes: put your current premium, policy limit, retention, ransomware terms, business-interruption coverage, and three biggest technology dependencies on one page. That small document will immediately make your next renewal conversation sharper.
- Measure premium and coverage together.
- Document security improvements before renewal.
- Use competition to improve terms, not only price.
Apply in 60 seconds: Put a calendar reminder 120 days before your cyber policy expiration date and label it "Start cyber renewal evidence pack."
Last reviewed: 2026-09