Cyber Insurance in 2026: What Policies Cover, What Underwriters Check, and Where Claims Fail
How cyber insurance works in 2026: first- and third-party coverage, underwriting controls, sublimits, war and system-failure wording, and worked claim math.

A cyber insurance policy has more moving parts than most commercial coverage: a main limit, a set of sublimits, a retention, a waiting period, a panel of approved vendors, and exclusions whose wording has been tested in court. Two companies with the same "$2 million cyber policy" can collect very different amounts after the same incident. This guide explains what the parts do, what underwriters check, where claims tend to fail, and how to run the numbers before you buy.
The 2026 market in brief
Prices have been falling. Marsh's Q2 2026 Global Insurance Market Index showed global cyber rates down 4%, the twelfth straight quarterly decline, with US rates down 2%. The index leans toward larger accounts, so small businesses may see different numbers. Munich Re's 2026 cyber report put global cyber premiums at nearly $15 billion in 2025, with growth slowing, and projects around $28 billion by 2030.
Claims data shows where the money goes. Coalition's 2026 Cyber Claims Report, based on more than 100,000 policyholders in five countries, found for 2025:
- Claims frequency rose 3% while average severity fell 19% to $116,000.
- Business email compromise (BEC) and funds transfer fraud (FTF) made up 58% of claims.
- Ransomware was the most expensive claim type, averaging $269,000. FTF averaged $141,000, and 52% of FTF claims began with a BEC.
- Coalition recovered $21.8 million in stolen funds for policyholders, and early reporting made recovery more likely.
A soft market is a good time to negotiate wording, since insurers competing on price will often concede on sublimits and exclusions too.
What a cyber policy covers

| Coverage | What it pays | What to check |
|---|---|---|
| Incident response | Breach counsel, forensics, public relations | Whether you must use panel vendors, and whether your own firms can be pre-approved |
| Notification and monitoring | Letters, call centers, credit monitoring | Whether these costs erode the main limit |
| Data restoration | Rebuilding systems and data | Exclusion for upgrades beyond the original state |
| Business interruption | Lost net income and continuing expenses during an outage at your own systems | Waiting period in hours, maximum period of restoration |
| Dependent business interruption | Your losses when a vendor's systems go down | Whether it covers all IT vendors or only named ones, and non-malicious outages |
| System failure | Outages with no attack behind them, such as a bad update or human error | Not in every policy |
| Cyber extortion | Ransom payments and negotiators | Sublimit, coinsurance, insurer consent |
| Funds transfer fraud and social engineering | Money wired to criminals | Usually a sublimit well below the main limit; callback verification conditions |
| Privacy and network security liability | Defense and settlements with customers and partners | Hammer clause, consent to settle |
| Regulatory | Investigation costs, and fines where insurable by law | Many jurisdictions bar insuring fines as a matter of public policy |
| Payment card (PCI) | Card brand fines and assessments | Separate sublimit |
| Media liability | Defamation and IP claims over published content | Overlap with other policies |
What underwriters check
Applications have grown from a page of yes-or-no questions into detailed security questionnaires. Expect questions about:
- MFA on email, remote access, and every privileged account
- Endpoint detection and response on servers and laptops
- Backups kept offline or immutable, and when a restore was last tested
- How fast critical vulnerabilities on internet-facing systems get patched, and whether any end-of-life software remains
- Privileged access management and separate admin accounts
- Email security and phishing training
- Your incident response plan and who is on it
Many insurers also scan your internet-facing systems for exposed remote desktop, unpatched VPNs, and leaked credentials before quoting, and some keep scanning during the policy year.
The application is part of the contract. In 2022 Travelers sued International Control Services, an Illinois electronics manufacturer, to rescind its $1 million cyber policy after a ransomware attack, saying the company's application claimed MFA protected its servers and admin access when it did not. The two sides agreed to a judgment voiding the policy from inception. Have the person who runs security review every answer before an executive signs, and tell the insurer if a control changes mid-term.
The same controls that lower premiums reduce the chance you need the policy. Our CSPM guide covers cloud configuration, and our zero trust guide covers identity and access.
Clauses that decide the payout
Sublimits and coinsurance
An illustration: a company buys a $2 million policy with a $500,000 extortion sublimit and 50% coinsurance on ransomware. A ransomware incident costs $1.2 million in ransom and negotiation fees. The insurer's 50% share would be $600,000, but the sublimit caps it at $500,000, so the company pays $700,000 plus its retention. The headline $2 million limit never comes into play.
Waiting periods for business interruption
Business interruption coverage starts after a waiting period, typically 4 to 12 hours.
An illustration: an online retailer loses $40,000 a day in net income and continuing expenses, about $1,667 an hour, during a 72-hour outage. With a 12-hour waiting period, 60 hours are covered, or $100,000. If a $25,000 retention also applies, the payment is $75,000. An 8-hour waiting period would cover 64 hours, about $106,667 before the retention.
The July 19, 2024 CrowdStrike outage showed how this works at scale. Early estimates put insured losses between about $300 million and $1.5 billion, against Parametrix's estimate of $5.4 billion in direct losses for Fortune 500 companies alone. The gap came from large retentions, policies without system failure coverage, and companies that recovered before their waiting periods ended.
The hammer clause
If you reject a settlement the insurer recommends, the hammer clause limits what it pays afterward. An illustration: the insurer recommends settling a privacy claim for $400,000. You refuse, and the case eventually costs $900,000 in defense and judgment.
- Under a full hammer, the insurer pays $400,000 and you pay the $500,000 excess.
- Under a 70/30 soft hammer, the insurer pays $400,000 plus 70% of the excess, $750,000 in total, and you pay $150,000.
War and state-backed attack exclusions
Merck claimed about $1.4 billion in NotPetya losses under its property policies. Its insurers cited a "hostile or warlike action" exclusion, and in May 2023 the New Jersey Appellate Division held that the exclusion required military action and did not apply. The case settled in January 2024, shortly before the state Supreme Court was due to hear it.
Insurers responded with explicit cyber-war wording. Since March 31, 2023, Lloyd's has required standalone cyber policies written in its market to exclude state-backed cyber attacks that seriously impair a country's functioning or security. The standard model clauses, LMA5564 to LMA5567, range from broad to narrow; LMA5567, the most widely used, applies only when a state has suffered a "major detrimental impact." Ask your broker which clause your policy uses and how it decides attribution.
Retroactive date
Most cyber policies are written on a claims-made basis, and many have a retroactive date: an intrusion that began before that date is excluded even if it is discovered during the policy. IBM's 2026 Cost of a Data Breach report found breaches took 247 days on average to identify and contain, so an attacker already inside your network when you switch insurers can surface months later. Ask for full prior acts coverage, or a retroactive date carried forward from your first continuous cyber policy, and disclose any incidents you already know about, since known incidents are excluded regardless.

Ransom payments and sanctions
The US Treasury's Office of Foreign Assets Control warned in its September 2021 advisory that paying a ransom to a sanctioned person or group can violate sanctions law, and that insurers, negotiators, and incident response firms that help can face exposure too. OFAC treats prompt reporting to law enforcement and full cooperation as mitigating factors. Your insurer will not reimburse a payment that breaks the law, and most policies require its consent before any payment.
Paying is also less common than it was. Verizon's 2026 Data Breach Investigations Report found 69% of ransomware victims did not pay, and the median payment among those who did was $139,875. Tested backups are what make refusing a realistic option.
Risk that arrives through vendors
Some of the costliest recent incidents hit companies through a supplier. The June 2024 ransomware attack on CDK Global took down dealer management software used by about 15,000 car dealerships for roughly two weeks. The February 2024 attack on Change Healthcare disrupted claims processing for health care providers for weeks, and UnitedHealth later put the number of people whose data was affected at about 190 million.
Two protections apply. Dependent business interruption coverage pays your own lost income when a vendor goes down; check whether it covers all IT providers or only named ones, and whether non-malicious outages count. Contracts with vendors that hold your data or run critical systems should require their own cyber and technology errors and omissions coverage, prompt breach notice, and cooperation with your investigation. Our SaaS vendor management guide covers vendor due diligence.
After an incident: protecting the claim
- Call the insurer's breach hotline first, before hiring outside firms, unless you have pre-approved your own.
- Let breach counsel hire the forensic firm, which helps keep its findings privileged.
- Record every cost and every hour of lost revenue from the start; business interruption claims need evidence.
- Do not pay a ransom, admit liability, or agree to a settlement without the insurer's consent.
- For a fraudulent wire, call your bank immediately and file a report with the FBI's IC3; recovery odds fall quickly.
- Check disclosure deadlines. US public companies must file Form 8-K, Item 1.05, within four business days of deciding an incident is material, under SEC rules adopted in 2023. Privacy laws have their own notification clocks; see our data privacy guide.
Buying checklist
- Model a bad but plausible incident: a week of downtime at your daily loss rate, notification costs for your largest customer dataset, and a ransom demand. Set limits from that, not from a round number.
- Use a broker who places cyber risk regularly and compare policy wording side by side, not just premiums.
- Get every sublimit in writing: extortion, funds transfer fraud, social engineering, dependent business interruption, system failure, PCI, and regulatory.
- Check the retention, the waiting period, and any coinsurance.
- Confirm the retroactive date and prior acts terms before switching insurers.
- Ask which war exclusion clause applies.
- Ask to pre-approve the law firm and incident response firm you would want to use.
- Review the application answers with your security lead, and revisit coverage after acquisitions, new data types, or expansion into new jurisdictions.
A small business with little sensitive data may be offered a cyber endorsement on a business owner's policy instead of a standalone policy. Endorsements are cheaper, but their limits and coverage are usually far narrower, so compare them line by line against the table above.
For the data you are insuring, see our cloud data governance guide and SaaS security guide.
This guide is for informational purposes only and is not insurance, legal, or financial advice. Policy terms, exclusions, and prices vary by insurer and jurisdiction. Consult a licensed insurance broker, an attorney, and qualified security professionals before buying or claiming on a policy.



