The Rough Notes Company Inc.
  • Home
  • About
  • Publications
  • RN Newsletter
  • Products & Solutions
  • Media Kits
  • Contact Us
  • Shop
    • Catalog
    • Enter Promo Code
    • Pay Your Existing Bill Here
No Result
View All Result
  • Home
  • About
  • Publications
  • RN Newsletter
  • Products & Solutions
  • Media Kits
  • Contact Us
  • Shop
    • Catalog
    • Enter Promo Code
    • Pay Your Existing Bill Here
No Result
View All Result
The Rough Notes Company Inc.
No Result
View All Result

3 CYBER CLAIMS TRENDS THAT INSURANCE PROFESSIONALS CAN’T AFFORD TO IGNORE

August 31, 2026
3 CYBER CLAIMS TRENDS THAT INSURANCE PROFESSIONALS CAN’T AFFORD TO IGNORE

Insights into where your clients

may be vulnerable to a cyber event

By Rob Jones


Cyber risk is becoming more expensive, more interconnected, and harder for businesses to ignore. Analysts at Gartner project that global cybersecurity expenditures will climb 24% to $240 billion this year, but businesses face twice the likelihood of experiencing a cyber incident compared to five years ago, according to Check Point Research. This creates a paradox: Spending is rising, but businesses are not necessarily becoming more secure.

This disconnect should matter to insurance professionals. It tells us that more technology alone is not solving the problem. To break through, businesses need to understand how current cyber claims trends are changing and ensure that they are investing in the right measures to protect against today’s more sophisticated attacks.

Better preparedness, stronger controls, and a clearer understanding of how claims are changing can mean the difference between recovering quickly or suffering lasting financial damage.

For brokers, agents, and carriers, claims data offers one of the clearest views into where clients remain vulnerable. It also shows where the market is shifting. Three trends in Coalition’s 2025 cyber claims data stand out in particular, and each has important implications for how insurance professionals advise clients, assess controls, and help businesses build a more resilient, multi-layered defense.

  1. Ransom demands rose, but more businesses are refusing to pay. Ransomware remains one of the costliest cyber threats in the market, but the story is no longer just about rising attacker demands. It is also about changing victim behavior.

In 2025, ransom demands increased 47% year over year. Threat actors escalated pressure during ransom negotiations, even going as far as to cite victims’ cyber insurance policies and argue that the targets can afford to pay. These tactics show the growing sophistication of the cybercrime ecosystem.

This manipulation aims to force businesses into a quick payout. However, the data shows that businesses are increasingly resisting attacks. Even though ransom demands increased, a record 86% of victims refused to pay. That figure signals something important for the insurance industry. Better preparation is changing outcomes.

With data backups and cyber incident response plans, more businesses are able to refuse ransom demands. They have options, including recovery protocols and access to professional negotiators and legal support, which puts them in a position of greater control. This demonstrates a significant improvement in organizational resilience and defenses.

Now, even when a victim considers paying, the attackers’ initial demand is rarely the final number. In 2025, professional negotiators cut demands by an average of 65%. These trends show increased leverage for victims.

Overall, there has been a growing shift from payment as the default option to a focus on preparation and prevention instead. For insurance professionals, the takeaway is straightforward: Resilience is not theoretical—it is measurable in claims outcomes.

This is also where the broker’s role becomes especially valuable. Clients often think of cyber insurance as a source of reimbursement after a loss. In reality, the strongest outcomes tend to arise when businesses pair coverage with preparation before a loss can occur.

The conversation should not be limited to whether a client has ransomware coverage. It should address whether the client has the operational readiness to avoid defaulting to payment.

  1. Data theft now drives ransomware severity more than encryption alone. When it comes to ransomware severity, encryption is no longer the driving factor. In 2025, attacks involving both data encryption (locking systems) and data exfiltration (stealing data) accounted for 70% of all ransomware claims. Even more troublesome, these dual-extortion tactics doubled the costs of ransomware attacks, resulting in an average loss of $299,000.

Many businesses are aware of encryption as a tactic of ransomware attacks and may have resiliency measures already in place. So now, attackers are responding by leaning harder on data theft, which can still create legal, operational, and reputational damage even when organizations can restore systems from backups.

This is a critical point for insurance professionals advising clients. Many insureds have made progress on business continuity and recovery. Fewer have fully adjusted to the reality that data theft can create a second, and often more expensive, layer of loss. The result is that a client may feel operationally prepared but still be financially exposed.

The underlying access paths are also becoming clearer. Virtual private networks (VPNs) were the entry point in 59% of ransomware claims, and organizations with exposed VPN log-in panels were three to four times more likely to experience a cyber incident. Those numbers reinforce that cyber claims are often tied to very practical security decisions.

For brokers and underwriters, this trend highlights the value of focusing on controls that reduce attack surface, not just post-loss response. Moving away from exposed VPNs and toward zero-trust network architecture can materially reduce risk. More broadly, this is a reminder that cyber insurance works best when paired with active risk management. If claims are increasingly driven by preventable exposures, then the market must reward insureds that address them.

Organizations that understand evolving

claims trends and adapt their defenses will

be better positioned to mitigate emerging

cyber risks before they lead to costly disruptions.

  1. Email compromise remains the front door for most financial losses. Ransomware may have been the costliest type of claim in 2025, but business email compromise (BEC) and funds transfer fraud (FTF) accounted for the majority (58%) of cyber incidents.

What makes this trend especially important for insurance professionals is that it often starts with behavior that clients underestimate. Threat actors still favor email as a gateway for larger attacks, and they’re getting better and faster at conducting them. Often, the loss starts with a convincing message, a compromised inbox, or a payment instruction that appears legitimate.

What makes BEC especially dangerous is that it often becomes a gateway to more severe attacks like FTF. Of note, 52% of all FTF claims in 2025 originated from BEC, indicating a growing connection between the two kinds of attacks. BEC is not a prerequisite for FTF, but it often acts as a catalyst.

First, organizations need stronger controls around email, identity, and finance workflows, not just endpoint security. Multi-factor authentication (MFA) and tools such as Microsoft Entra ID can help prevent credential theft. Second, employee awareness remains essential, particularly for finance teams and executives with payment authority. Third, reporting FTF within 72 hours can significantly improve the odds of recovering stolen funds.

For agents and brokers, this trend creates an opportunity to deliver concrete, high-value guidance. Conversations with insureds should cover approval processes, segregation of duties, finance-specific credential protection, and how quickly a suspected fraud event gets escalated. These are practical risk controls, but they are also claims controls.

What this means for the market: the need for active cyber insurance

Given the varied ways that threat actors behave, having a layered defense against cyberattacks is crucial. These three trends point to a broader shift in cyber insurance. The market is moving away from a passive model that responds after a loss and toward a more active model centered on preparedness, prevention, and rapid response.

Bolstering cybersecurity doesn’t just involve increasing spending; it requires that organizations and their insurers partner to take an active approach to enhancing security procedures. Best practices like moving files to a secure cloud location, strengthening phishing awareness, and enacting MFA protections can make a big difference.

Organizations that understand evolving claims trends and adapt their defenses will be better positioned to mitigate emerging cyber risks before they lead to costly disruptions. By strengthening core controls, understanding key loss drivers, and partnering closely with brokers and carriers, clients can better avoid the most severe outcomes.

The author

Robert Jones leads Coalition’s global claims function, overseeing the development and growth of the claims team, managing Coalition’s vendor network of external panel providers, and helping internal underwriting teams develop risk selection strategy. Before joining Coalition, Jones spent 32 years at AIG, where he served as Executive Vice President of Financial Lines, Specialty Claims.

Tags: cyber insuranceinsuranceSpecialty & Excess Lines
Previous Post

AI IMPLEMENTATION

Next Post

A TEAMMATE, NOT A TOOL

Next Post
A TEAMMATE, NOT A TOOL

A TEAMMATE, NOT A TOOL

FEATURES/ COLUMNS/ DEPARTMENTS

  • Agency Management & Marketing (1)
  • Agency of the Month (114)
  • Agency Partners (41)
  • Alternative Risk Transfer (28)
  • Benefits & Financial Services (168)
  • Benefits Lead (112)
  • Commercial Lines (138)
  • Court Decisions (386)
  • Coverage Concerns (192)
  • Excess and Specialty Lines (118)
  • From The Latest Issue (671)
  • General Articles (287)
  • Management (930)
  • Marketing (7)
  • Organizational Profiles (96)
  • Personal Lines (113)
  • Producers Blog (53)
  • RN Blog Top Q&A For Agents (99)
  • Specialty Lines (266)
  • Technology (204)
  • Trending Blogs (213)
  • Young Professionals (116)
  • Home
  • About
  • Publications
  • RN Newsletter
  • Products & Solutions
  • Media Kits
  • Contact Us
  • Shop

By continuing to browse the site, you agree to the data collection and processing practices disclosed in our recently updated privacy policy.

©The Rough Notes Company. No part of this publication may be reproduced, translated, stored in a database or retrieval system, or transmitted in any form by electronic, mechanical, photocopying, recording, or by other means, except as expressly permitted by the publisher. For permission contact Samuel W. Berman.

Sitemap

The Rough Notes Company Inc.
No Result
View All Result
  • Home
  • About
  • Publications
  • RN Newsletter
  • Products & Solutions
  • Media Kits
  • Contact Us
  • Shop
    • Catalog
    • Enter Promo Code
    • Pay Your Existing Bill Here

By continuing to browse the site, you agree to the data collection and processing practices disclosed in our recently updated privacy policy.

©The Rough Notes Company. No part of this publication may be reproduced, translated, stored in a database or retrieval system, or transmitted in any form by electronic, mechanical, photocopying, recording, or by other means, except as expressly permitted by the publisher. For permission contact Samuel W. Berman.

Sitemap