2026 Cyber Insurance Trends: What’s Changed & What to Know

The best offense is a good defense. That's even more true in 2026 when the rules around cyber insurance keep changing, attackers keep evolving, and the line between "covered" and "not covered" keeps moving under your feet.

Cyber insurance may not be at the top of every business's priority list, but all it takes is one incident you didn't see coming to see catastrophic results. The true cost of a cyberattack can exceed $250,000 - which most businesses without insurance absolutely can't afford. Despite this reality, our December 2024 survey found that 22% of companies still don't have cyber insurance.

And for the 78% that do? The coverage landscape has fundamentally changed in the last 18 months.

This Huntress survey reveals critical cyber insurance trends you need to know in 2026, including new regulatory mandates that are reshaping policies, the tactical shift in how attackers operate, and why the buyer's market that defined 2024-2025 is coming to an end. We'll also show you how the gap between cybersecurity and cyber insurance is finally starting to close and what that means for your business.

Key Takeaways

  • The cyber insurance landscape shifted hard in 2026. New federal reporting mandates (CIRCIA) are live. Attackers stopped encrypting and started stealing. Business email compromise (BEC) now drives more claims than ransomware. And after three years of falling premiums, rates are climbing again.

  • 58% of businesses with cyber insurance report some level of decrease in their coverage over the past five years, even as threats intensified

  • Not understanding coverage options is the main reason organizations don't have cyber insurance (38%)

  • 61% of respondents say AI-powered attacks are the biggest threat to their cyber insurance premiums

  • New federal and EU regulations (CIRCIA, NIS2) are creating compliance requirements that many existing policies weren't designed to cover

  • Data exfiltration has replaced encryption as the primary ransomware tactic, and it's twice as expensive

What's changed since 2025

Before we dig into the data, here's what shifted in 2026:

  • CIRCIA implementation: Federal incident reporting requirements now in effect for critical infrastructure entities

  • A significant majority of ransomware attacks now include data exfiltration, and these attacks are substantially more expensive

  • BEC represents a significant portion of claims, often more than ransomware

  • Premium softening is showing signs of ending: Many companies report cost increases on recent renewals

  • Manufacturing represents a significant portion of claims, one of the most targeted industries

  • Most businesses now refuse to pay ransoms, a significant shift from earlier years

The threats evolved. The regulations tightened. And the insurance market is responding.

58% of respondents report coverage has decreased

The majority of respondents (58%) noted a reduction in the scope of their cyber insurance coverage over the past five years, while 25% said there hadn't been any significant changes.

This is the uncomfortable truth: cyber insurance costs keep going up, which means some organizations are getting priced out of full coverage. They're taking out lower-limit policies or accepting higher deductibles just to stay insured. The result? Coverage that may not adequately reflect the evolving threat landscape, leaving businesses exposed when something actually happens.

Nearly 4 out of 5 businesses have cyber insurance

One of the more surprising cyber insurance trends is that most organizations surveyed have cyber insurance. While 79% may seem high, it varies a lot by company size. Roughly 74% of companies with 500 or fewer employees have cyber insurance, with that number dropping as low as 56% for those with fewer than 50 employees. 

Cost is the main factor in why many organizations (26%) choose not to get cyber insurance, so it's not surprising that small and medium-sized businesses are less likely to invest in protecting themselves.

The majority of cybersecurity professionals feel they have the budget to protect their orgs

The majority of respondents (55%) strongly agreed that their organization has the budget to protect itself against cybersecurity threats. Only 2% strongly disagreed, while 38% somewhat agreed and 5% somewhat disagreed.

Given that cyberattacks are becoming more severe and happening more often - with the potential for crippling financial and reputational damage - investing in comprehensive cyber insurance isn't a nice-to-have anymore. It's a requirement.

The real question isn't whether you can afford insurance. It's whether you can afford not to have it.

Not understanding coverage options is the biggest barrier

As cyber insurance coverage requirements change and costs go up by as much as 25.5% year over year, businesses that already have cyber insurance struggle to keep up. Those without it may not even know where to start.

The majority of respondents without cyber insurance (38%) say "not understanding coverage options" is the main reason they haven't purchased a plan. Perceived low risk is the next consideration (28%), while cost comes in third (26%). Other factors (7%) include things like managing cyber events in-house.

Here's the problem: the cyber insurance market has gotten more complex, not simpler. Policies that made sense in 2023 may not cover the exposures that matter in 2026. If you don't understand what you're buying, you can't know if you're actually covered when something happens.

2026 regulatory changes are reshaping coverage requirements

If you thought cyber insurance was just about covering losses after an incident, 2026 changed the game.

New federal and international regulations are turning cyber insurance into a compliance necessity, not just a financial backstop. And if your policy doesn't explicitly cover regulatory defense costs, dual-reporting obligations, and incident notification timelines, you may be exposed in ways you didn't expect.

CIRCIA: Incident Reporting Requirements for Critical Infrastructure

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is establishing new reporting requirements for covered critical infrastructure entities. Key aspects include:

  • Covered entities in 16 critical infrastructure sectors are expected to report qualifying cyber incidents and ransomware payments on tight timelines

  • Sectors include healthcare, finance, energy, manufacturing, water, transportation, and more

  • At publication, final implementation dates, covered-entity counts, and penalty structures should be confirmed with your legal and compliance teams, as they may evolve over time

What does this mean for cyber insurance?

Your incident response timeline is tightening. If you're covered by CIRCIA, you need immediate access to forensics, legal counsel, and breach response resources, and your insurance policy needs to cover those costs.

Many policies written before these regulations took effect don't explicitly account for CIRCIA compliance. If your coverage doesn't include regulatory defense, notification costs, and forensic investigation support, you may be paying out of pocket for the help you need most.

NIS2: Raising the Bar for Cybersecurity Accountability

In the EU, the NIS2 Directive raises board-level accountability for cybersecurity in covered entities, including potential administrative fines and other sanctions for management bodies. Key aspects include:

  • Management bodies are expected to approve and oversee cybersecurity risk-management measures

  • Executives may face accountability measures, including administrative sanctions

  • Many organizations expect to increase security budgets to meet these requirements

  • Be sure to validate the latest guidance and enforcement practices with counsel

If you're an executive at a covered entity, this isn't just an IT problem. It's a governance issue. And traditional Directors & Officers (D&O) insurance may not fully address your exposure if regulators determine cybersecurity obligations weren't met.

The Dual-Reporting Challenge

Here's where it gets complex: organizations operating in multiple jurisdictions may face stacked reporting obligations.

A financial services firm with operations in both the US and EU might need to navigate multiple regulatory frameworks simultaneously, each with their own timelines and requirements. This includes CIRCIA reporting in the US, NIS2 notifications in the EU, and sector-specific financial regulator reporting.

The incident response team managing a ransomware attack must coordinate multiple regulatory submissions to different jurisdictions, while also managing containment and communicating with executive leadership.

If your cyber insurance policy doesn't cover the legal and forensic costs associated with dual-reporting compliance, you're absorbing those expenses yourself.

What to Ask About Your Policy

If you're subject to CIRCIA, NIS2, or other regulatory mandates, ask your broker or insurer:

  • Does the policy cover regulatory defense costs for incident reporting compliance?

  • Are forensic investigation and legal counsel fees covered within the first 72 hours?

  • Does the policy include notification costs for dual-reporting scenarios?

  • What are the sub-limits for regulatory response? (Some policies cap these costs separately from general breach response.)

Regulatory compliance is now a core part of the claims process. Make sure your coverage reflects that reality.

Insurers Require Several Cybersecurity Measures to Access Coverage

Our team has seen how cyber insurance has evolved over the years. Businesses are more interested than ever in buying cyber insurance, but there's also more of a burden on the company needing coverage to have certain protections in place.

"Cyber insurance is becoming a lot more expensive, cyber insurers are covering less, and they're requiring you to have more safeguards in place to be covered," Geftic says.

For organizations that have coverage now, cyber insurer compliance requires:

  • Security awareness training: 81% of organizations have this as a prerequisite for coverage

  • Identity Threat Detection and Response (ITDR): Most ransomware and BEC attacks now start with compromised credentials, not exploited vulnerabilities, making identity the primary breach vector insurers screen for.

  • Multi-factor authentication: 79%

  • Endpoint detection and response (EDR) / managed detection and response: 65%

  • Vulnerability management: 65%

  • Air gap backups: 33%

  • Other, such as log data storage: 1%

The insurers' logic is simple: they won't pay for a claim if you didn't lock the door. Just like home insurance requires you to have a deadbolt, cyber insurance requires you to have EDR, MFA, and awareness training. If you don't have those controls in place, you're either not getting coverage or you're paying significantly more for it.

Data recovery is the most commonly covered cyber event

The majority of respondents (81%) were covered for data recovery, followed closely by data breaches (80%) and ransomware (63%). Some respondents also had coverage for business interruption/lost revenue (62%) and legal costs (59%).

On the other hand, less than half of cybersecurity plans included coverage for:

  • Third-party claims (50%)

  • Forensic investigation costs (43%)

  • Fines and penalties (42%)

  • Public relations costs (40%)

What's covered under a standard cyber insurance plan varies widely by provider, so it's important to shop around for the right plan for your organization. Always carefully review the policy documents to understand exactly what cybersecurity threats are covered and excluded.

The shift from encryption to data exfiltration

Ransomware used to be simple: attackers encrypted your files, demanded payment, and either gave you the decryption key or didn't. Businesses with good backups could restore systems without paying. Insurers could estimate the cost of downtime and recovery.

Not anymore.

In 2026, ransomware has shifted toward data theft without encryption, with many threat actors exfiltrating sensitive data first and then using the threat of public leaks—on top of encryption—to force payment.

Numbers tell the story

According to recent industry reports and threat intelligence:

  • A significant majority of ransomware incidents now involve data exfiltration in addition to or instead of encryption

  • Attacks with data exfiltration are substantially more expensive than encryption-only attacks

  • Initial ransom demands have increased significantly

  • Most businesses now refuse to pay ransoms, a dramatic shift from earlier years when payment rates were much higher

Why threat actors changed tactics

Better backups dramatically weakened the traditional ransomware model and pushed many attackers toward data theft and extortion.

Organizations got smarter about backup strategies - air-gapped backups, offline copies, tested recovery procedures. When attackers encrypted systems, many businesses could restore operations without paying. Ransom payment rates dropped significantly.

So attackers adapted. They realized that stealing data is often faster, easier, and creates stronger leverage than encryption alone. You can't restore stolen data from a backup. And the threat of leaking sensitive customer information, intellectual property, or financial records creates leverage that encryption alone doesn't.

Data exfiltration has become a primary lever in many modern ransomware operations. Encryption is increasingly optional.

Why this matters for insurance

Traditional cyber insurance was built around the "encrypt and extort" model. Policies covered:

  • System restoration costs

  • Business interruption losses

  • Ransom payments (in some cases)

But the new "steal and extort" model creates long-tail costs that extend far beyond system recovery:

  • Forensic investigations: Determining what data was stolen, when, and how

  • Legal liability: GDPR, CCPA, HIPAA, and other privacy compliance regulations impose fines and notification requirements

  • Regulatory fines: Average data breach cost hit an all-time high of almost $5 million in 2024, driven by stricter data privacy regulation

  • Notification costs: Informing customers, regulators, and partners about the breach

  • Credit monitoring services: Often required by law for affected individuals

  • Reputational damage: Harder to quantify, but the loss of customer trust can be devastating

Many policies written before 2024-2025 don't adequately cover data exfiltration events that don't involve encryption. If your policy defines ransomware narrowly as "encryption-based attacks," you may not be fully covered when attackers steal your data and threaten to leak it.

What to look for in your policy

Ask your broker or insurer:

  • Does the policy cover data exfiltration events without encryption?

  • Are forensic mining and legal liability costs covered under the data breach response section?

  • What are the sub-limits for notification costs, regulatory fines, and credit monitoring?

  • Does the policy cover extortion payments related to data theft (even if no encryption occurred)?

The threat evolved. Your coverage needs to reflect that reality.

Business email compromise: A major claims driver

Ransomware gets the headlines. But in 2026, business email compromise (BEC) and funds transfer fraud (FTF) are a major driver of cyber insurance claims, even if they don't generate the same headlines as ransomware.

The numbers

According to recent industry reports:

  • Business email compromise and funds transfer fraud represent a significant portion of cyber insurance claims in some analyses, a majority of claim volume

  • Many FTF claims originate as BEC attacks, with substantial average losses

  • The majority of FTF claims result from social engineering tactics that exploit human trust

How BEC creates risk

Business email compromise attacks exploit human trust and business processes, not just technical vulnerabilities. Attackers compromise email accounts, monitor communication patterns, and impersonate trusted parties to request fraudulent funds transfers.

The technical controls may be in place, but the human layer remains vulnerable. That's why identity protection, email security, and awareness training are critical components of both prevention and insurance eligibility.

Why time matters

If you catch a BEC attack quickly, there may be a chance of recovering funds through rapid coordination with financial institutions and law enforcement. The window for recovery narrows significantly as time passes.

This is where cyber insurance makes a tangible difference. Some insurers with in-house fraud response teams and established relationships with banks can act immediately to freeze accounts, trace transfers, and work toward fund recovery.

What to look for in your policy

Ask your broker or insurer:

  • Does the policy cover business email compromise and funds transfer fraud?

  • Are there sub-limits on FTF coverage? (Some policies cap these separately from other losses.)

  • What's the claims reporting timeline for FTF? (Some policies require reporting within 24-72 hours.)

  • Does the insurer have in-house fraud response teams and clawback capabilities?

BEC is the silent killer. It doesn't make headlines like ransomware, but it's driving the majority of claims volume and it's preventable with the right identity protections and email security controls.

AI-powered attacks are the biggest emerging threat

When asked which emerging cyber threats will have the biggest impact on the cyber insurance industry in 2026, the majority of respondents (61%) were most concerned about AI-powered attacks. This was followed by cloud security breaches (24%), IoT device vulnerabilities (14%), and other factors like ransomware attacks (1%).

But here's the thing: AI isn't creating sci-fi-style super-attacks. It's quietly multiplying attacker efficiency.

How threat actors are using AI in 2026

Threat actors are using AI tools to:

  • Automate reconnaissance: Scraping LinkedIn, company websites, and social media to identify targets, map organizational structures, and find vulnerable entry points

  • Customized AI phishing campaigns: Generating personalized emails at scale that bypass traditional spam filters

  • Gain initial access faster: Using AI to identify and exploit vulnerabilities across large attack surfaces

  • Create deepfake voice and video: Making impersonation attacks (like CEO fraud and BEC) more convincing increasing success rates for phishing and funds transfer fraud

  • Sift stolen data for maximum leverage: After exfiltrating data, attackers use AI to identify the most sensitive information to threaten in ransom negotiations

The Deepfake Problem

Deepfake fraud attempts have surged significantly. Attackers are using AI-generated voice and video to impersonate executives, vendors, and trusted contacts making social engineering attacks harder to detect.

A CFO receives a video call from the CEO requesting an urgent wire transfer. The voice sounds right. The video looks right. But it's a deepfake. By the time the fraud is discovered, the money is gone.

Traditional security controls such as email filters, spam detection, endpoint protection - don't stop this. The attack bypasses technology entirely and targets human trust.

How insurers are responding

Insurers are also using AI, for underwriting, risk assessment, and claims processing. They're analyzing:

  • Real-time security telemetry to identify risk patterns

  • Incident response data to predict claim severity

  • Attack trends to adjust coverage requirements and pricing

This creates an "AI vs. AI" dynamic. Attackers use AI to scale attacks. Insurers use AI to detect risk and price policies accordingly.

The businesses caught in the middle need to ensure they have AI-resistant controls in place:

  • Multi-factor authentication (MFA): Prevents account takeover even if credentials are stolen

  • Identity threat detection and response (ITDR): Monitors for suspicious activity in Microsoft 365, Google Workspace, and other identity platforms

  • Email authentication (DMARC, DKIM, SPF): Prevents domain spoofing and email impersonation

  • User security awareness training: Educates your employees to verify unusual requests, even if they appear to come from trusted sources

Insurers have started to adapt their policies to better reflect the growing concern that AI is changing the threat landscape. Businesses need to adapt by strengthening their security posture, particularly around identity and email security and staying informed about the evolving terms and conditions of cyber insurance policies.

Which industries are insurers watching most closely?

Not all industries face the same cyber risk. And in 2026, insurers are paying close attention to which sectors are driving the most claims.

Manufacturing: A High-Risk Sector

According to recent industry reports, manufacturing has represented a significant portion of cyber insurance claims, making it one of the most targeted industries. This follows substantial increases in attacks against the manufacturing sector.

Why manufacturing?

  • Operational technology (OT) and IT convergence: Legacy industrial systems connected to modern networks create attack surface

  • Supply chain dependencies: Disrupting one manufacturer can cascade across entire industries

  • Lower security maturity: Many manufacturers invested in production efficiency first, security second

  • High ransom payment potential: Downtime in manufacturing is expensive, creating pressure to pay ransoms

If you're in manufacturing, insurers are scrutinizing your security controls more closely than ever. Expect underwriting questions about:

  • OT/IT segmentation

  • Backup and recovery procedures

  • Incident response capabilities

  • Vendor risk management

Other High-Risk Sectors

Beyond manufacturing, insurers are closely watching:

  • Healthcare: HIPAA breach notification requirements + CIRCIA dual-reporting creates complex claims scenarios

  • Finance: High-value targets with strict regulatory obligations (SEC, FINRA, federal banking regulators)

  • State and local government: Budget constraints, legacy infrastructure, and public visibility make these attractive targets

  • Technology and software companies: High-value intellectual property and customer data create extortion leverage

If you operate in one of these sectors, your industry-specific risk profile is already baked into your premium. The question is whether your security investments are strong enough to offset that risk or whether you're paying more for coverage than you need to.

What to look for in a cyber insurance policy

The coverage you'll need depends on your organization's specific needs, the size of your business, and your industry. Here are key factors to consider when choosing a cyber insurance plan:

  • Coverage scope: Make sure the coverage is comprehensive for data breach response costs (legal fees, investigations, etc.), business interruption losses, cyber extortion (including data theft without encryption), third-party liability, and regulatory fines.

  • Deductibles: Choose a deductible that balances cost with the potential for frequent, smaller claims.

  • Complete underwriting accurately: The policy and premium you receive are based on your responses, and overstating your security measures will risk a full payout of the policy in the event of an incident.

  • Insurer reputation: Pick an insurer with a strong track record in cyber insurance and a deep understanding of cyber threats.

  • Exclusions: Make sure you understand your policy's limitations and that the limits are sufficient to cover potential losses based on your organization's size and industry.

  • Claims process: Ask about the insurer's claims-handling process to determine if it's compatible with your organization's needs - and whether they have in-house response teams for rapid support.

  • Regulatory coverage: Verify that the policy covers regulatory defense costs, dual-reporting obligations, and incident notification requirements (especially if you're subject to CIRCIA, NIS2, or other mandates).

  • Data exfiltration coverage: Confirm that the policy covers extortion events involving data theft - even without encryption.

How managed cybersecurity and cyber insurance go hand in hand

Geftic notes how cyber insurance is similar to other types of coverage in that insurers won't provide coverage (or cover less) unless you have proper security in place - like EDR, ITDR, or a SIEM.

"Yes, someone robbed your house, but you didn't have a deadbolt, so we're not paying," he says - or at least, not covering the full claim amount.

In the same way that home insurance requires a homeowner to lock their doors, not leave any open flames unattended, and generally behave safely, cyber insurance providers require the same from their policyholders.

To qualify for plans and receive coverage when needed, cyber insurance increasingly requires organizations to have fail-safes already in place - like regular cybersecurity training, multi-factor authentication, and Managed EDR.

That's the context for what Huntress and Acrisure are building together.

Turn better security into better insurance outcomes

The gap between cybersecurity and cyber insurance has always been awkward. Insurers ask for proof of controls. Security vendors promise protection. Business owners get stuck in the middle, trying to translate technical capabilities into underwriting language.

Huntress and Acrisure are closing that gap.

Through the Huntress × Acrisure Cyber Insurance Program, eligible organizations running Huntress Managed EDR and Managed ITDR can access primary cyber and Tech E&O insurance with:

  • Simplified Statement-of-Fact application: Streamlined process focused on your Huntress deployment

  • $0 deductible: No out-of-pocket costs on covered losses

  • Accessible coverage: Designed for businesses using Huntress managed security

This isn't a product warranty or a marketing gimmick. It's real primary cyber insurance coverage, placed through Acrisure, one of the fastest-growing insurance brokers in history.

The program is designed for:

  • MSPs and IT providers looking for better Tech E&O coverage that rewards their security investments

  • Businesses of all sizes that want cyber insurance aligned with the protections they've already deployed

When you invest in 24/7 managed endpoint and identity protection, the insurance market should recognize that effort. Now it does.

FAQ

Is Cyber Insurance Growing?

Yes, the cyber insurance market has been growing significantly in recent years. The increasing frequency and severity of cyberattacks, along with evolving regulations and more awareness of data privacy risks, are driving demand. However, the market is also maturing, with growth rates moderating as the market reaches greater scale and competition increases.

How Much Is Cyber Insurance?

On average, businesses pay a minimum of $25,000 per year for cyber insurance, ranging anywhere from $10,000 or less to more than $100,000. The actual cost depends on:

  • Company size (revenue and employee count)

  • Industry sector (manufacturing, healthcare, and finance typically pay more)

  • Security controls in place (EDR, MFA, awareness training, backups)

  • Claims history

  • Coverage limits and deductibles

How Big Is the Cyber Insurance Market in 2026?

The cyber insurance market continues to grow and is projected by various industry analysts to reach significant scale in coming years, though exact figures vary by source and methodology. Market growth reflects increasing awareness of cyber risk across all business sizes.

What Percentage of Companies Have Cyber Insurance?

According to our survey data, 79% of companies have cyber insurance. This percentage varies depending on the specific size and industry of the organization:

  • 74% of companies with 500 or fewer employees have coverage

  • 56% of businesses with fewer than 50 employees have coverage

  • In the UK, 62% of businesses had cyber insurance in 2025 (up from 49% in 2024)

What Is CIRCIA and How Does It Affect Cyber Insurance?

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) establishes reporting requirements for covered critical infrastructure entities. Organizations in 16 critical infrastructure sectors are expected to report qualifying cyber incidents and ransomware payments according to defined timelines.

For cyber insurance, this means:

  • Faster incident response timelines (you need immediate access to forensics and legal counsel)

  • Potential for higher costs related to regulatory defense and compliance

  • Consideration of dual-reporting obligations for organizations operating in multiple jurisdictions (CIRCIA, NIS2, HIPAA, state breach laws, and sector-specific requirements)

At publication, final implementation dates and covered-entity details should be confirmed with your legal and compliance teams, as they may evolve over time. Verify that your policy includes regulatory defense, notification expenses, and forensic investigation support to address reporting requirements.

Why Are Data Exfiltration Attacks More Expensive?

Attacks involving data exfiltration are significantly more expensive than encryption-only ransomware because they create long-tail costs beyond system recovery:

  • Forensic investigations to determine what data was stolen

  • Legal liability and regulatory fines (GDPR, CCPA, HIPAA)

  • Notification costs for customers, regulators, and partners

  • Credit monitoring services for affected individuals

  • Reputational damage and loss of customer trust

Unlike encryption (where you can restore from backups), stolen data can't be "un-stolen." The threat of public disclosure creates ongoing extortion leverage, and the legal and regulatory consequences extend far beyond the initial incident.

See how Huntress can support your organization's cyber safety and help you qualify for cyber insurance for added protection.