Insurance market tightening is forcing enterprises to demonstrate measurable security posture improvements before renewal. We outline the specific controls carriers are now requiring as a condition of coverage.
Key Takeaways
The 2025 ransomware cost figures, compiled from aggregate claims data submitted to the ten largest cyber insurance carriers operating in North American and European markets, represent a grim milestone. Total insured ransomware losses crossed $2.1 billion for the first time, a 34% increase over 2024 and the fourth consecutive year of record losses. Average per-incident payments reached $1.2 million in the first quarter of 2026, driven by a shift in threat actor tactics toward double and triple extortion models that layer data theft and threatened public disclosure on top of the encryption-and-ransom mechanic that originally defined the category. The insurance market has absorbed several years of these escalating losses, and it has reached the point where the underwriting response is no longer incremental premium adjustment. It is structural change in the conditions under which coverage is offered at all.
The implications for enterprise security teams are direct and immediate. Cyber insurance has become a core component of enterprise risk transfer strategy, and its availability at acceptable terms now depends on a security posture that can be technically validated, not merely attested to on a form. For CISOs who have spent years arguing for security investment in the face of competing budget priorities, the insurance market has provided an unexpected instrument of leverage: specific, carrier-mandated technical controls now carry the weight of a coverage prerequisite, giving security leaders a concrete business justification that transcends internal risk tolerance debates. That leverage is real, but it also means that organisations that have not made the requisite investments are facing either prohibitive premium levels or outright denial of the coverage they need to satisfy board-level risk governance requirements.
The underwriting methodology employed by the major carriers has undergone a fundamental transformation over the past 18 months. Where questionnaire-based self-attestation was the standard as recently as 2023, the largest carriers now conduct technical validation exercises as a condition of binding coverage. These exercises vary in depth by carrier and policy size, but at the enterprise tier they commonly include review of EDR deployment coverage logs, backup test result documentation, privileged access management configuration audits, and in some cases, scanning of external attack surfaces using third-party security rating platforms. The carriers are not taking applicants at their word. They are verifying the controls they are being asked to cover against the risk of their absence.
The premium trajectory reflects this new reality. A 31% year-over-year increase in average premiums represents a sustained market correction, not a transient spike. Carriers are also deploying sublimits and coinsurance requirements with increasing frequency: policies that once provided full coverage for ransomware events now commonly include ransomware-specific sublimits that cap exposure at 50 to 70% of the policy face value, or coinsurance provisions that require the policyholder to absorb 20 to 30% of any ransomware loss. The practical effect is that the total risk transfer available through cyber insurance is contracting even as the nominal premiums rise. Organisations are paying more and receiving coverage for a smaller proportion of their potential loss. The only reliable path to reversing this dynamic is demonstrating the technical controls that carriers have identified as the primary drivers of loss frequency and severity.
Third-party security ratings have become embedded in underwriting workflows in a way that warrants direct management attention. Platforms that aggregate publicly observable security signals, including certificate management practices, exposed service indicators, known vulnerability data, and DNS configuration hygiene, now provide carriers with a continuous external view of an organisation's security posture between renewal cycles. A rating deterioration triggered by an unpatched public-facing system or an expired certificate can now influence both renewal terms and mid-term policy conditions. Security teams that have not yet built ongoing monitoring of their own external security ratings into their operational cadence are managing a risk that their insurers are already pricing and that their competitors are likely already tracking.
Across the major carriers, six technical controls have crystallised as the baseline prerequisites for ransomware coverage at the enterprise tier. These are not suggestions or best practices in the carrier documentation; they are conditions of coverage, and their absence is cited as a basis for declination or material premium loading in underwriting guidelines issued over the past twelve months.
"Two years ago, a CISO could get cyber insurance by completing a questionnaire. Today, the largest carriers are running technical validation exercises, reviewing your EDR deployment logs, and asking to see your backup test results. The bar has risen substantially."
Jordan Reyes, Head of Cyber Underwriting, Axis Capital
The organisations best positioned in the current insurance environment are those that implemented these controls for operational security reasons before insurance compliance made them mandatory. For those organisations, the carrier validation process is an affirmation of existing practice rather than a remediation sprint. Their premium trajectories are more favourable, their coverage terms are more comprehensive, and their underwriting relationships are stronger because they can provide documentation that validates the security claims in their renewal submissions with specificity and depth.
For organisations that are currently remediating gaps under renewal deadline pressure, the immediate priority should be the two controls that correlate most strongly with loss severity in carrier data: offline backup integrity and privileged access management. These are not the easiest controls to implement under time pressure, but they are the ones that determine whether a ransomware event results in a contained, recoverable incident or a full-environment catastrophe requiring months of reconstruction. Carriers know this, which is why both controls appear in declination rationale more frequently than any of the other four. An organisation that can demonstrate tested offline backups and a functional PAM programme, even if other controls remain in progress, is in a substantially different position at renewal than one that cannot demonstrate either.
The broader lesson for security budget conversations is that the insurance market has done something that internal risk management frameworks rarely achieve: it has attached a concrete financial consequence to the absence of specific technical controls. That consequence, expressed as a 40 to 60% premium increase or an outright coverage declination, is a number that translates directly into board-level budget language. Security leaders who bring the insurance calculus into their budget discussions are working with a more powerful instrument than a threat landscape briefing. They are presenting their boards with a choice between funding the controls and absorbing the insurance cost of not having them, a comparison that tends to resolve in favour of the controls when the arithmetic is laid out clearly.
Analysis of security incident data across 500 enterprises reveals zero trust organisations experience 61% fewer lateral movement incidents.
Quantitative analysis of 800 breach events reveals the regulatory fine represents less than 30% of total breach cost.