As exposure grows, premium
levels off. What gives?
By Joseph S. Harrington, CPCU
This century’s fastest growing line of property/casualty insurance stopped growing in 2024 and grew only slightly in 2025. If that’s a sign of things to come, then premium for cyber insurance is likely to fall far short of the giddy projections made in the 2000s and 2010s.
Total U.S. direct written premium for cyber coverage fell more than 7% in 2024, from $9.8 billion to $9.1 billion, after growing only tepidly in 2023, according to figures from the National Association of Insurance Commissioners (NAIC). The latest NAIC figures, in its 2025 Memorandum, which entail results from admitted, surplus lines, and non-U.S. insurers, are in stark contrast to the robust growth earlier in the decade.
Since then, AM Best reports, insurers domiciled in the United States (admitted and E&S) saw their share of annual cyber direct written premium barely grow from $7.1 billion in 2024 to $7.5 billion in 2025, with much of the growth a result of carriers simply shifting premium from offshore to domestic entities.
According to AM Best, two “sub-markets” have developed within the U.S. cyber insurance market. One is dominated by surplus lines carriers writing primary and excess policies specifically addressing cyber risk and accounting for nearly two-thirds of all U.S. cyber premium. The other sub-market is dominated by admitted insurers concentrating on endorsements to commercial lines policies.
Best adds that E&S carriers have a lower paid loss ratio and higher incurred loss ratio than their admitted counterparts, suggesting that E&S carriers are writing more complex business with longer loss tails.
Commercial lines agents and brokers will find interest in an observation by Fitch Ratings, which reported in April 2026 that “[cyber] premium growth in 2025 was primarily volume-driven, with approximately 34% growth in policies in force more than offsetting softer aggregate pricing. This shift reflects greater awareness of cyber exposure and a more competitive underwriting environment.”
Stable premium
People in the cyber insurance market will vouch for the fact that the price of coverage has stabilized.
“The premium rate has never really stabilized consistently since the inception of the line,” says J. Kevin Sneed, cyber team leader for R.E. Chaix & Associates Insurance Brokers. Besides the normal occurrence of targeted cyber attacks, Sneed says that several large scale, high-profile events over the past decade have caused “turbulence” for the line, most recently with the 2024 CDK Global attack.

More recently, however, Sneed sees that “some renewals are leveling off, especially among smaller accounts within preferred classes. All of the markets are vying for the same easy opportunities.
“More importantly, this leveling off trend in pricing has been driven primarily by the infusion of venture capital into the creation of new insurtech companies, as well as into mergers and acquisitions of existing firms,” he says. “This has sparked aggressive competition to lower the pricing across the board while returning profits through cost-cutting measures such as implementing API interface with aggregator platforms.”

“Cyber premiums are leveling off or, in fact, coming down, while claim costs are increasing,” says Larry Harb, founder and CEO of IT Risk Managers, Inc. “What’s causing this? It’s supply and demand. Capacity is increasing; while at the same time, the bad guys are getting a lot smarter.”
As for limits and deductibles, Harb says carriers are “cautious about putting up large numbers” and will increase deductibles as they increase limits. “We are seeing carriers asking insureds to put more skin in the game,” he says.
Sneed sees the same. “More of our buyers are purchasing higher limits,” he says. “Concerns are growing that $1 million in coverage, previously the standard limit, is probably not enough coverage.
“Perhaps the greatest change ever in cyber insurance is [the insurance firm] CFC’s move to reinstate limits for all first-party coverage parts,” he adds. “This ‘each claim’ approach is ingenious, since it is highly unlikely that several different claims will be made in a single year by the same insured. It’s the reason we make CFC our recommended market more than 50% of the time.”
New exclusions
Even as rates for cyber coverage stabilize, Sneed finds that coverage conditions sometimes reflect “knee-jerk” reactions to high profile cyber events. He cites two relatively new but rapidly growing coverage restrictions involving “wrongful collection” and “non-IT contingent business interruption.”
Wrongful collection exclusions are being added to exclude coverage for claims against an insured that allege it improperly collected or disseminated users’ information through use of web cookies, Meta Pixels, chat records, or other means.
For cyber insurance purposes, non-IT business interruption is distinguished from “IT-related business interruption.” The latter refers to business interruption (BI) losses incurred by the insured due to outages at third-parties providing system support, such as cloud hosts and software vendors. This exposure is now commonly covered in the wake of cyber attacks causing widespread system shutdowns.
Non-IT BI refers to a suspension of operations caused by a cyber event at a third party, but without direct impact on the insured’s network or systems. For example, non-IT BI would entail a loss of key components because a supplier suffered a cyber attack. According to Sneed, carriers are avoiding this exposure.
Underwriting and loss control
If cyber insurance has not achieved the premium levels observers expected, one reason is that the loss control requirements for coverage are so rigorous that applicants that can implement them often retain elevated levels of exposure.
Now cyber insurers are expanding their involvement in client cyber security, according to Harb. “While requiring insureds to increase their computer security, carriers have also taken it upon themselves to do security assessments and penetration testing, and to provide training resources,” he says.
“A second change we are seeing is more and more carriers using artificial intelligence to underwrite a risk,” he adds. “While this might be adequate for Main Street-type businesses, those with more complicated exposures still require human intervention.”
In regard to coverage for artificial intelligence (AI) risk exposures, Harb finds that some cyber policies are starting to address the possibility, “but most are still silent on the topic.”
To date, concerns over AI are “much ado about nothing,” says Sneed. “There is hysteria among some buyers and some caution at the carrier and producer level,” he adds, “but for others, including me, the question is whether use of AI could trigger one of a policy’s coverages. So far, most AI has not been used in a way that would create breach security or compromise privacy.”
For more information:
IT Risk Managers, Inc.
ITRiskmanagers.com
R.E. Chaix & Associates
Insurance Brokers
rechaixinsurance.com
The author
Joseph S. Harrington, CPCU, is an independent business writer specializing in property and casualty insurance coverages and operations. For 21 years, Joe was the communications director for the American Association of Insurance Services (AAIS), a P&C advisory organization. Prior to that, Joe worked in journalism and as a reporter and editor in financial services.




