Read the free interactive preview of AI Security From PsyOps to CyberOps Start Reading Free →
LIVE DISCLOSURES + CURATED CLAIMS DATA

Cyber Insurance Claims & Market Trends

Actual cyber insurance claims data, including claim counts, payouts, and loss ratios, is proprietary to insurers and brokers and isn't published through a public API. What's below is the honest version of this page: a live feed of SEC-disclosed material cybersecurity incidents, and current figures from the industry reports that do publish real claims and market data, each dated and sourced.

THE INSURER'S VANTAGE POINT

What Cyber Insurance Knows That You Don't

Insurers sit on top of more real-world loss data than almost anyone else in security: every claim, every payout, every incident that actually cost someone money. Cyber insurance is evolving from a financial backstop into a genuine lens on real-world risk: what's actually happening across nation-state, criminal, and systemic incidents, and which controls actually reduce the odds of a claim. The numbers on this page are a start. What follows is how we read them.

AI & AUTONOMOUS THREATS

Underwriting hasn't caught up to agentic risk

Insurers are starting to ask about AI chatbots, RAG systems, and agentic workflows in renewal questionnaires. Most underwriting models still treat "AI risk" as a single checkbox rather than three distinct surfaces with different failure modes. Expect this to tighten fast: the same way ransomware controls became mandatory for coverage, agent-specific access controls and red-team evidence are likely to become underwriting requirements within a few renewal cycles, not a decade.

CYBER CONFLICT

Nation-state activity blurs the "war exclusion" line

State-linked and state-tolerated threat actors increasingly look like organized crime in their tooling and targeting, which makes the traditional insurance war exclusion harder to apply cleanly. Insurers are responding with narrower, more specific exclusion language and closer attribution scrutiny after a claim; this means your incident response and forensics quality can directly affect whether a claim gets paid, not just how fast you recover.

SYSTEMS UNDER STRESS

Concentration risk is the thing keeping underwriters up at night

A single cloud provider, identity platform, or widely-used vendor failing doesn't cause one claim; it causes hundreds, simultaneously. Insurers are increasingly pricing and capping exposure around this systemic, single-point-of-failure risk rather than treating each policyholder as an independent event, which is part of why large-account pricing and terms have moved differently than SME pricing over the past two years.

Connecting to SEC EDGAR…

The panel below calls SEC EDGAR's full-text search directly from your browser. If your network blocks it, the panel falls back to a direct search link instead of stale data.

Recent material cybersecurity incident disclosures

Source: SEC EDGAR full-text search · 8-K filings, Item 1.05 · live
Querying efts.sec.gov…

Since December 2023, U.S. public companies must disclose material cybersecurity incidents to the SEC within four business days under Item 1.05 of Form 8-K. This is a real-time proxy for large-scale disclosed incidents: not claims data itself, but the kind of event that typically triggers a significant cyber insurance claim for companies large enough to be SEC registrants.

CURRENT INDUSTRY CLAIMS & MARKET DATA

What the actual claims reports say right now.

Curated from the most recent published reports from each source, refreshed periodically as new studies come out, not on page load.

PRIVATE CARRIER CLAIMS DATA

NetDiligence 2025 Cyber Claims Study

Published September 2025 · 10,402 claims from incidents occurring between 2020 and 2024
$264KSME AVG INCIDENT COST, 2024
$10.3MLARGE CO. 5-YR AVG INCIDENT COST
8CLAIMS OVER $100M IN DATASET
  • 98% of claims came from SMEs (under $2B revenue); large companies were 2% of claims but over half of total incident costs.
  • Ransomware and business email compromise accounted for roughly 50% to 55% of all claims.
  • Ransom demands reached as high as $150M; ransoms paid as high as $75M.
netdiligence.com →
U.S. REGULATORY MARKET DATA

NAIC 2025 Cybersecurity Insurance Report

Published late 2025 · covers 2024 annual statement data
$9.14BU.S. DIRECT WRITTEN PREMIUM, 2024
-7%PREMIUM CHANGE YOY (FIRST-EVER DECLINE)
+40%CLAIMS FREQUENCY CHANGE YOY
  • Nearly 50,000 U.S. cyber insurance claims reported in 2024, even as premiums fell.
  • Claims closed without payment outnumbered paid claims by more than 20-to-1.
  • 218 U.S. insurers reported direct cyber written premium in 2024.
naic.org →
GLOBAL MARKET DATA

Munich Re: Global Cyber Insurance Risks & Trends

2025 report · covers 2024 global market
$15.3BGLOBAL PREMIUM, 2024
69%SHARE WRITTEN IN NORTH AMERICA
47%OF ELIGIBLE ORGS ACTUALLY INSURED
  • Global cyber insurance premium remains under 1% of the total global P&C insurance market.
  • North America: $10.6B; Europe: $3.3B; Asia-Pacific and Latin America still underpenetrated.
  • The "protection gap," meaning eligible organizations without coverage, remains the majority of the market.
Cited via secondary source: see note →
LOSS DATA (CRIME REPORTS, NOT INSURANCE CLAIMS)

FBI IC3 2024 Internet Crime Report

Published early 2025 · covers calendar year 2024
$3.1B+REPORTED BEC LOSSES, 2024
  • Business Email Compromise remains one of the largest reported loss categories tracked by IC3; it is also one of the top two causes of loss in cyber insurance claims data above.
  • IC3 tracks reported crime losses, not insurance claims: useful as a directional signal, not a claims figure.
ic3.gov →
THE INSIDE VIEW

Where organizations are failing.

Across nation-state, criminal, and systemic incidents, the same handful of gaps show up in claim after claim. None of them are exotic.

Identity is the common thread, not malware.

A large share of the large-scale claims in the data above trace back to compromised or over-privileged identities: a stolen credential, an over-permissioned service account, or a standing agent credential, not a novel exploit. This is exactly why we treat agentic security as an access-management problem first.

Business interruption costs more than the breach itself.

Claims with a business interruption component run dramatically higher than claims without one. Organizations underinvest in resilience and recovery testing relative to how much it actually costs when systems go down, not just when data leaks.

Third-party and systemic exposure is rising faster than direct exposure.

A growing share of claims originate from a vendor, platform, or supply-chain partner failing rather than the policyholder's own systems; that share is growing faster than direct-cause claims. Vendor risk isn't a footnote anymore; it's a primary loss driver.

Attribution and response quality affect whether a claim gets paid.

As nation-state and criminal activity blur together, the quality of your incident response and forensics, not just your defenses, increasingly shapes coverage outcomes, particularly where war exclusions or state-actor language is in play.

FOR CISOS

Align security strategy to resilience, insurability, and what insurers are actually seeing.

Underwriting is increasingly a proxy for real-world risk assessment: the controls insurers reward (least-privilege access, tested incident response, vendor risk management, and now AI-specific governance) are largely the same ones that reduce your actual odds of a costly incident. Treating insurability as a byproduct of good security, rather than a compliance exercise run separately from it, is the fastest way to align the two.

Where this comes from, and where it doesn't

The SEC panel above is a genuine live API call: nothing cached, nothing proxied. The four cards are curated by us from the current published reports linked above and refreshed as new studies are released, not fetched live, because none of these organizations publish a public API for this data. The Munich Re figures are cited via a secondary source that aggregates the original report, noted explicitly above; treat that one card as directionally accurate rather than primary-source-verified, and check the linked report for anything decision-critical. The commentary sections above ("What Cyber Insurance Knows," "Where Organizations Are Failing," and the CISO guidance) are SecuredAI's own analysis connecting the data on this page to what we see in engagements; they're informed by the reports linked here, not quoted from any single source. None of this is a substitute for your own broker's loss data or a specific carrier's underwriting numbers.