#cybersecurity insurance#risk management#business security#data privacy#cyber liability#incident response

Cyber Insurance in 2026: What Policies Cover, What Underwriters Check, and Where Claims Fail

How cyber insurance works in 2026: first- and third-party coverage, underwriting controls, sublimits, war and system-failure wording, and worked claim math.

📅 January 10, 2026✏️ Updated: September 27, 2026⏱ 10 min read✍ Web3 Listicle Editorial Team

A futuristic network dashboard displaying cybersecurity shields, encrypted data pipelines, and cyber liability indicators.

A cyber insurance policy has more moving parts than most commercial coverage: a main limit, a set of sublimits, a retention, a waiting period, a panel of approved vendors, and exclusions whose wording has been tested in court. Two companies with the same "$2 million cyber policy" can collect very different amounts after the same incident. This guide explains what the parts do, what underwriters check, where claims tend to fail, and how to run the numbers before you buy.

The 2026 market in brief

Prices have been falling. Marsh's Q2 2026 Global Insurance Market Index showed global cyber rates down 4%, the twelfth straight quarterly decline, with US rates down 2%. The index leans toward larger accounts, so small businesses may see different numbers. Munich Re's 2026 cyber report put global cyber premiums at nearly $15 billion in 2025, with growth slowing, and projects around $28 billion by 2030.

Claims data shows where the money goes. Coalition's 2026 Cyber Claims Report, based on more than 100,000 policyholders in five countries, found for 2025:

  • Claims frequency rose 3% while average severity fell 19% to $116,000.
  • Business email compromise (BEC) and funds transfer fraud (FTF) made up 58% of claims.
  • Ransomware was the most expensive claim type, averaging $269,000. FTF averaged $141,000, and 52% of FTF claims began with a BEC.
  • Coalition recovered $21.8 million in stolen funds for policyholders, and early reporting made recovery more likely.

A soft market is a good time to negotiate wording, since insurers competing on price will often concede on sublimits and exclusions too.

What a cyber policy covers

A leadership team discussing IT risk categories, insurance limits, and disaster recovery plans.

Coverage What it pays What to check
Incident response Breach counsel, forensics, public relations Whether you must use panel vendors, and whether your own firms can be pre-approved
Notification and monitoring Letters, call centers, credit monitoring Whether these costs erode the main limit
Data restoration Rebuilding systems and data Exclusion for upgrades beyond the original state
Business interruption Lost net income and continuing expenses during an outage at your own systems Waiting period in hours, maximum period of restoration
Dependent business interruption Your losses when a vendor's systems go down Whether it covers all IT vendors or only named ones, and non-malicious outages
System failure Outages with no attack behind them, such as a bad update or human error Not in every policy
Cyber extortion Ransom payments and negotiators Sublimit, coinsurance, insurer consent
Funds transfer fraud and social engineering Money wired to criminals Usually a sublimit well below the main limit; callback verification conditions
Privacy and network security liability Defense and settlements with customers and partners Hammer clause, consent to settle
Regulatory Investigation costs, and fines where insurable by law Many jurisdictions bar insuring fines as a matter of public policy
Payment card (PCI) Card brand fines and assessments Separate sublimit
Media liability Defamation and IP claims over published content Overlap with other policies

What underwriters check

Applications have grown from a page of yes-or-no questions into detailed security questionnaires. Expect questions about:

  • MFA on email, remote access, and every privileged account
  • Endpoint detection and response on servers and laptops
  • Backups kept offline or immutable, and when a restore was last tested
  • How fast critical vulnerabilities on internet-facing systems get patched, and whether any end-of-life software remains
  • Privileged access management and separate admin accounts
  • Email security and phishing training
  • Your incident response plan and who is on it

Many insurers also scan your internet-facing systems for exposed remote desktop, unpatched VPNs, and leaked credentials before quoting, and some keep scanning during the policy year.

The application is part of the contract. In 2022 Travelers sued International Control Services, an Illinois electronics manufacturer, to rescind its $1 million cyber policy after a ransomware attack, saying the company's application claimed MFA protected its servers and admin access when it did not. The two sides agreed to a judgment voiding the policy from inception. Have the person who runs security review every answer before an executive signs, and tell the insurer if a control changes mid-term.

The same controls that lower premiums reduce the chance you need the policy. Our CSPM guide covers cloud configuration, and our zero trust guide covers identity and access.

Clauses that decide the payout

Sublimits and coinsurance

An illustration: a company buys a $2 million policy with a $500,000 extortion sublimit and 50% coinsurance on ransomware. A ransomware incident costs $1.2 million in ransom and negotiation fees. The insurer's 50% share would be $600,000, but the sublimit caps it at $500,000, so the company pays $700,000 plus its retention. The headline $2 million limit never comes into play.

Waiting periods for business interruption

Business interruption coverage starts after a waiting period, typically 4 to 12 hours.

An illustration: an online retailer loses $40,000 a day in net income and continuing expenses, about $1,667 an hour, during a 72-hour outage. With a 12-hour waiting period, 60 hours are covered, or $100,000. If a $25,000 retention also applies, the payment is $75,000. An 8-hour waiting period would cover 64 hours, about $106,667 before the retention.

The July 19, 2024 CrowdStrike outage showed how this works at scale. Early estimates put insured losses between about $300 million and $1.5 billion, against Parametrix's estimate of $5.4 billion in direct losses for Fortune 500 companies alone. The gap came from large retentions, policies without system failure coverage, and companies that recovered before their waiting periods ended.

The hammer clause

If you reject a settlement the insurer recommends, the hammer clause limits what it pays afterward. An illustration: the insurer recommends settling a privacy claim for $400,000. You refuse, and the case eventually costs $900,000 in defense and judgment.

  • Under a full hammer, the insurer pays $400,000 and you pay the $500,000 excess.
  • Under a 70/30 soft hammer, the insurer pays $400,000 plus 70% of the excess, $750,000 in total, and you pay $150,000.

War and state-backed attack exclusions

Merck claimed about $1.4 billion in NotPetya losses under its property policies. Its insurers cited a "hostile or warlike action" exclusion, and in May 2023 the New Jersey Appellate Division held that the exclusion required military action and did not apply. The case settled in January 2024, shortly before the state Supreme Court was due to hear it.

Insurers responded with explicit cyber-war wording. Since March 31, 2023, Lloyd's has required standalone cyber policies written in its market to exclude state-backed cyber attacks that seriously impair a country's functioning or security. The standard model clauses, LMA5564 to LMA5567, range from broad to narrow; LMA5567, the most widely used, applies only when a state has suffered a "major detrimental impact." Ask your broker which clause your policy uses and how it decides attribution.

Retroactive date

Most cyber policies are written on a claims-made basis, and many have a retroactive date: an intrusion that began before that date is excluded even if it is discovered during the policy. IBM's 2026 Cost of a Data Breach report found breaches took 247 days on average to identify and contain, so an attacker already inside your network when you switch insurers can surface months later. Ask for full prior acts coverage, or a retroactive date carried forward from your first continuous cyber policy, and disclose any incidents you already know about, since known incidents are excluded regardless.

An abstract network padlock graphic representing data privacy and risk mitigation systems.

Ransom payments and sanctions

The US Treasury's Office of Foreign Assets Control warned in its September 2021 advisory that paying a ransom to a sanctioned person or group can violate sanctions law, and that insurers, negotiators, and incident response firms that help can face exposure too. OFAC treats prompt reporting to law enforcement and full cooperation as mitigating factors. Your insurer will not reimburse a payment that breaks the law, and most policies require its consent before any payment.

Paying is also less common than it was. Verizon's 2026 Data Breach Investigations Report found 69% of ransomware victims did not pay, and the median payment among those who did was $139,875. Tested backups are what make refusing a realistic option.

Risk that arrives through vendors

Some of the costliest recent incidents hit companies through a supplier. The June 2024 ransomware attack on CDK Global took down dealer management software used by about 15,000 car dealerships for roughly two weeks. The February 2024 attack on Change Healthcare disrupted claims processing for health care providers for weeks, and UnitedHealth later put the number of people whose data was affected at about 190 million.

Two protections apply. Dependent business interruption coverage pays your own lost income when a vendor goes down; check whether it covers all IT providers or only named ones, and whether non-malicious outages count. Contracts with vendors that hold your data or run critical systems should require their own cyber and technology errors and omissions coverage, prompt breach notice, and cooperation with your investigation. Our SaaS vendor management guide covers vendor due diligence.

After an incident: protecting the claim

  1. Call the insurer's breach hotline first, before hiring outside firms, unless you have pre-approved your own.
  2. Let breach counsel hire the forensic firm, which helps keep its findings privileged.
  3. Record every cost and every hour of lost revenue from the start; business interruption claims need evidence.
  4. Do not pay a ransom, admit liability, or agree to a settlement without the insurer's consent.
  5. For a fraudulent wire, call your bank immediately and file a report with the FBI's IC3; recovery odds fall quickly.
  6. Check disclosure deadlines. US public companies must file Form 8-K, Item 1.05, within four business days of deciding an incident is material, under SEC rules adopted in 2023. Privacy laws have their own notification clocks; see our data privacy guide.

Buying checklist

  • Model a bad but plausible incident: a week of downtime at your daily loss rate, notification costs for your largest customer dataset, and a ransom demand. Set limits from that, not from a round number.
  • Use a broker who places cyber risk regularly and compare policy wording side by side, not just premiums.
  • Get every sublimit in writing: extortion, funds transfer fraud, social engineering, dependent business interruption, system failure, PCI, and regulatory.
  • Check the retention, the waiting period, and any coinsurance.
  • Confirm the retroactive date and prior acts terms before switching insurers.
  • Ask which war exclusion clause applies.
  • Ask to pre-approve the law firm and incident response firm you would want to use.
  • Review the application answers with your security lead, and revisit coverage after acquisitions, new data types, or expansion into new jurisdictions.

A small business with little sensitive data may be offered a cyber endorsement on a business owner's policy instead of a standalone policy. Endorsements are cheaper, but their limits and coverage are usually far narrower, so compare them line by line against the table above.

For the data you are insuring, see our cloud data governance guide and SaaS security guide.


This guide is for informational purposes only and is not insurance, legal, or financial advice. Policy terms, exclusions, and prices vary by insurer and jurisdiction. Consult a licensed insurance broker, an attorney, and qualified security professionals before buying or claiming on a policy.

Frequently Asked Questions

First-party coverage pays your own costs: breach counsel, forensics, notification and credit monitoring, data restoration, business interruption, and cyber extortion. Third-party coverage pays claims against you: privacy and network security lawsuits, regulatory investigations (and fines where the law allows them to be insured), payment card assessments, and media liability. Most of these carry their own sublimits, so the headline limit rarely applies to every loss type.
Most applications ask about MFA on email, remote access, and privileged accounts; endpoint detection and response; offline or immutable backups that have been tested; patching of internet-facing systems; and privileged access management. Many insurers also scan your internet-facing systems before quoting. Answer accurately: in Travelers v. International Control Services (2022), a $1 million policy was rescinded and declared void from inception after the insurer said the company's application misstated its MFA use.
Down, for most buyers. Marsh's Global Insurance Market Index showed global cyber rates falling 4% in Q2 2026, the twelfth consecutive quarterly decline, with US rates down 2%. The index leans toward larger accounts, and your own price depends on revenue, industry, controls, claims history, and the limits you buy.
A clause that limits the insurer's payment if you refuse a settlement it recommends. Under a full hammer, you pay all costs above the rejected offer. Under a soft hammer, the insurer shares those extra costs at an agreed split, commonly 50% to 80% insurer. For example, if you reject a $400,000 settlement and the case finally costs $900,000, a 70/30 soft hammer leaves you paying $150,000 of the $500,000 excess.
Only if the policy included system failure coverage for non-malicious events, extended it to outages at your IT vendors (dependent or contingent business interruption), and the outage outlasted the waiting period, typically 4 to 12 hours. Many affected companies were back online before their waiting periods ended. Early estimates of insured losses ranged from about $300 million to $1.5 billion.
Many policies cover extortion payments, usually under a sublimit, sometimes with coinsurance, and only with the insurer's consent. No insurer will reimburse a payment that breaks the law. The US Treasury's OFAC warned in its September 2021 advisory that paying a sanctioned group can violate sanctions, and that insurers and negotiators who help can be exposed too.

Share this article