Cyber insurance premiums are falling even as ransomware recovery costs climb

Cyber insurance premiums have fallen for four consecutive years — down roughly 5% globally in 2026 alone, with European markets seeing even steeper drops from intense price competition. At the same time, ransomware payout rates have hit a multi-year low of around 23%. On paper, that looks like a market getting safer. It isn't. The actual cost of surviving a ransomware attack is climbing fast, and the gap between what insurers charge and what breaches actually cost is widening every quarter.
The premium paradox
The global cyber insurance market is valued between roughly $16 billion and $33 billion depending on the estimate, growing at a steady 5% compound annual rate since 2022. Yet in the U.S., pricing has declined for eight consecutive quarters even as loss ratios rise — insurers are collecting less premium relative to the claims they're paying out. That's not sustainable math, and insurers know it: 70% of organizations report higher premiums at application or renewal despite the headline rate drops, because underwriters are pricing individual risk more aggressively even as market-average rates fall.
The mechanism is stricter underwriting. Nearly all organizations seeking coverage — 99.5% — are now required to demonstrate specific controls: mature identity security, documented incident response plans, and enforced access controls. Insurers aren't cutting prices because risk is falling; they're cutting prices for the subset of buyers who can prove they've reduced their own exposure, while raising them sharply for everyone else. The average masks a bifurcating market.
Fewer victims pay, but recovery costs more
Ransomware payout rates falling to 23% looks like good news for defenders, and directionally it is — mature backup systems, insurer requirements, and sanctions risk are all pushing organizations away from paying. The median ransom demand has dropped 65% over two years to $698,000, and the median amount actually paid fell from $1 million to $769,000.
But recovery cost — the money spent whether or not a ransom gets paid — rose 11% year-over-year to $1.7 million per incident in 2026. Downtime, device replacement, network remediation, and lost revenue now dwarf the ransom itself for most victims. Paying the attacker was never the biggest line item; it's becoming an even smaller share of total loss as recovery gets more expensive and more organizations refuse to pay.
There's a second distortion hiding in the averages. While the median ransom payment fell, the average payment surged 176% in Q2 2026 to $1.88 million — driven by a small number of large, data-exfiltration cases rather than traditional encryption attacks. Large enterprises are increasingly refusing to pay for stolen-data suppression, recognizing it buys little real protection. Meanwhile, high-volume ransomware-as-a-service operations have pivoted toward mid-market targets with smaller demands and a higher success rate — a volume play that produces less dramatic headlines but more total incidents.
Why insurers are underpricing the real risk
Insurers are betting that AI-driven attacks remain a modeling problem they can solve incrementally. That bet looks increasingly shaky. AI is already amplifying existing attack techniques and compressing attack timelines — the interval between initial access and full compromise — which makes claims more frequent and more severe simultaneously. Industry analysts expect a 15% increase in written premiums in 2026 specifically because the buyer base is expanding faster than the risk models are improving, a mismatch insurers describe internally as unresolved "silent cyber" exposure — AI-enabled losses that existing policy language wasn't written to price.
Identity-based attacks are now the dominant entry point for ransomware, with phishing and malicious email together accounting for half of all incidents. That's a shift insurers have been slow to price into premiums, because identity compromise is harder to detect pre-breach than the network-perimeter failures that dominated underwriting models five years ago.
What security and finance teams should do
Three concrete moves follow from this data. First, budget for recovery cost, not ransom cost — $1.7 million in downtime and remediation dwarfs any realistic ransom negotiation outcome, and tabletop exercises should model that number, not the headline ransom figure. Second, treat insurer control requirements as a floor, not a ceiling: the 99.5% compliance rate on baseline controls means differentiated pricing now rewards organizations that exceed minimums, particularly on identity security and access controls, which insurers are underweighting relative to actual incident data. Third, negotiate ransom payments as a last resort with eyes open — 51% of organizations that did pay successfully negotiated a lower amount, so if you're forced into that position, budget time and expertise for negotiation rather than paying the initial demand.
The insurance market's declining headline rates are a signal about competitive pressure among carriers, not a signal that ransomware risk is shrinking. Treat the premium trend and the recovery-cost trend as two separate data points — because insurers are increasingly treating them that way too.