September 23, 2026 Global Pulse

Cyber Insurance Has Grown Into a Serious Underwriting Market and Ransomware Is Its Defining Peril

By Isabelle Fontaine | Senior Analyst, Cross-Sector Equity & Market Intelligence
8 min read

The Insurance Product That Ransomware Built

Cyber insurance began as a niche financial product in the late 1990s, initially designed to cover the liability exposure of companies whose websites collected personal data that could be breached and give rise to regulatory fines, notification costs, and third-party claims from affected individuals. The product's commercial transformation from a minor professional liability endorsement into a standalone insurance category generating approximately $16 billion in annual global premium by 2026 was driven almost entirely by the ransomware epidemic whose industrial-scale deployment against businesses across every sector since approximately 2018 has created the cyber loss frequency and severity that has made cyber risk a mainstream insurance purchasing decision rather than a specialist technical purchase. Ransomware, whose criminal business model of encrypting the victim organisation's files and demanding payment in cryptocurrency for the decryption key whose availability determines whether the organisation can restore its operations within days or weeks, rather than the months of data reconstruction from degraded backups that the alternative involves, generates the insured loss events whose business interruption, ransomware payment, incident response costs, and data restoration expenses create the cyber insurance claims that have tested and in many cases exceeded the loss assumptions that cyber insurers used when pricing the first generation of policies at premium rates that turned out to be inadequate for the claims environment that materialised between 2019 and 2024.

The cyber insurance market, valued at approximately $16.2 billion in global written premium in 2026 and growing at over twenty percent annually toward $45 billion by 2031, has undergone the underwriting discipline correction that its claims experience demanded through the 2021 to 2024 hard market cycle whose premium increases of one hundred to three hundred percent, coverage restriction through ransomware sublimits and co-insurance requirements, and mandatory security control attestation requirements have transformed the cyber underwriting environment from the growth-at-any-price posture of 2018 to 2020 into the technically rigorous risk selection approach that the loss experience demonstrated was necessary for sustainable commercial results.

Coalition and the Active Risk Management Model

Coalition, the US cyber insurance company, has built the most commercially differentiated cyber underwriting model in the market by combining its insurance product with its own cyber security monitoring platform that provides policyholders with continuous monitoring of their internet-facing attack surface, vulnerability scanning, dark web monitoring for compromised credentials, and automated threat intelligence alerts that allow the insured organisation to remediate the security exposures that insurers identify before they become the entry points for ransomware attacks. Its Active Insurance model, which uses the security telemetry from its monitoring platform to both price each risk more accurately than insurers relying solely on application questionnaire responses and to actively reduce the claims frequency of its portfolio by improving policyholders' security posture, has produced the loss ratio outperformance relative to the broader cyber insurance market that its $5 billion-plus coverage in force and its Lloyd's and Swiss Re reinsurance backing reflect. Beazley, the Lloyd's specialist insurer, has built the largest cyber insurance portfolio of any traditional specialty insurer through its data breach response and technology insurance products whose loss experience, claims handling capability, and incident response panel of cyber security firms create the institutional cyber insurer whose market position in the large enterprise and mid-market segments complements Coalition's SME-focused distribution model.

AIG's CyberEdge, one of the earliest comprehensive standalone cyber insurance products and the one whose claims experience through the 2017 to 2021 ransomware surge created some of the most significant cyber underwriting losses in the market, has been restructured with the mandatory security controls, ransomware sublimits, and premium calibration that the claims experience required, demonstrating the underwriting correction cycle that the entire cyber insurance market has undergone as the loss data accumulated to the point where the actuarial basis for sustainable pricing became available. The Lloyd's market's 2022 requirement that all Lloyd's cyber policies contain war exclusion clauses specifically addressing state-sponsored cyberattacks, and its subsequent clarification guidance on the precise wording whose systemic cyber event exclusion language creates the coverage boundary between commercial ransomware attacks whose insurance coverage is maintained and nation-state cyberattacks whose potential for correlated systemic losses the market is not prepared to cover, represents the most significant policy coverage boundary development in cyber insurance's short history.

The Aggregation Problem and Systemic Cyber Risk

The most commercially significant unresolved challenge in cyber insurance underwriting is the correlated loss aggregation problem, whose potential for a single cyber event to simultaneously trigger claims across a large proportion of the insurer's portfolio creates the tail risk that makes cyber different from the property catastrophe perils whose geographic concentration limits the proportion of an insurer's portfolio that any single earthquake or hurricane can affect. A ransomware group's simultaneous attack on a widely used software platform, or a critical infrastructure cyberattack that disrupts the cloud services, payment systems, or communications networks that the majority of businesses depend on, could create the correlated cyber loss event whose magnitude is not bounded by geography and whose simultaneous impact across thousands of policyholders could exhaust the reinsurance capacity and capital buffers that the cyber insurance market has assembled.

Top 10 Companies in Cyber Insurance Underwriting and Technology Globally

  1. Coalition: US cyber insurance company with Active Insurance model combining coverage with continuous attack surface monitoring; its security telemetry-informed underwriting and its SME-focused distribution create the cyber insurer whose integrated security monitoring and insurance product is the most commercially differentiated model in the market for reducing both pricing uncertainty and loss frequency simultaneously.
  2. Beazley: UK Lloyd's specialist insurer with the largest traditional specialty cyber insurance portfolio globally; its incident response panel and its large enterprise and mid-market cyber underwriting create the institutional cyber insurer whose data breach response service and claims handling capability create the service quality that large enterprise cyber buyers value alongside coverage terms.
  3. AIG (CyberEdge): US insurance company with CyberEdge standalone cyber product and restructured underwriting following ransomware losses; its global distribution and its restructured risk selection criteria create the multinational insurer whose cyber insurance repricing represents the market's underwriting correction from the insufficiently priced 2018 to 2020 portfolio whose loss experience drove the hard market correction.
  4. Chubb: US-Swiss insurer with Cyber Enterprise Risk Management product for large commercial accounts; its financial strength and its large account cyber underwriting capability create the specialty insurer whose coverage capacity for very large technology, financial services, and healthcare organisations serves the enterprise cyber insurance segment whose per-risk limits require the capital scale that specialist cyber MGAs cannot provide.
  5. AXA XL: French-UK specialty insurer with cyber liability and technology E&O coverage for international commercial accounts; its Lloyd's market presence and its European corporate cyber underwriting create the European specialty insurer whose cyber product serves the continental European corporate market where cyber insurance penetration is lower than the US but growing most rapidly.
  6. Corvus Insurance: US cyber insurance company with AI-powered underwriting and dynamic cyber risk scoring; its machine learning risk assessment and its broker-focused distribution create the InsurTech cyber underwriter whose data-driven risk selection complements the continuous monitoring approach of Coalition with a different technology-enabled underwriting methodology.
  7. Cowbell: US cyber insurance company with Cowbell Prime continuous underwriting for SME cyber risk; its API-connected risk assessment that updates coverage terms as the insured's security posture changes and its SME market focus create the adaptive underwriting platform whose continuous reassessment model addresses the policy period mismatch between annual insurance terms and the continuously evolving cyber risk environment.
  8. Resilience: US cyber insurance company with security operations and insurance integration for mid-market accounts; its combination of cyber security advisory, incident response, and insurance coverage and its reinsurance backing from institutional partners create the integrated cyber risk management company whose holistic approach to cyber risk reduction and financial risk transfer serves the mid-market segment between Coalition's SME focus and the large account capability of AIG and Chubb.
  9. Zurich Insurance: Swiss insurer with global cyber liability and data breach coverage; its multinational corporate client relationships and its European regulatory compliance expertise create the global insurer whose cyber product serves the international corporate market whose cross-border cyber risk exposure requires the policy coverage consistency and claims service capability that local national cyber insurers cannot provide across multiple jurisdictions.
  10. Lloyd's of London: UK insurance market with cyber syndicate capacity and the market-standard war exclusion clause for systemic cyber events; its aggregation management requirements and its systemic cyber event exclusion framework create the insurance market whose underwriting governance and capacity limits for cyber risk define the outer boundary of what commercial cyber insurance will and will not cover for the systemic tail events that the market is not prepared to insure.

Back to All Insights
×