Skip to content

US Cyber Insurance Sees Decline in Premiums Amid Pricing Cuts

    The NAIC overhauled the cyber supplement to the annual statement for 2024 filings, changing from a two-way standalone/packaged split to a there-way primary / excess / endorsement split, according to AM Best’s Report. Beinsure analyzed the report and highlighted the key points.

    This report is based solely on companies that have filed any NAIC cyber supplement. Any cyber business written by alien insurers is not included. Also, there were changes to the NAIC filing in 2024. As such, year-over-year comparisons may not always be applicable.

    “Packaged” was intended primarily as an endorsement only, but some entities were not making that distinction, including a cyber policy as part of a package of policies.

    The change in wording from the NAIC is now a clear distinction between policies covering only cyber versus policies for which cyber is an endorsement to another policy.

    Key Highlights

    • The NAIC shifted from a two-way (standalone / packaged) to a three-way classification—primary, excess, and endorsement—providing clearer insight into cyber policy structures and premium allocation.
    • Direct premiums written for cyber insurance fell by 2.3% to $7.075bn in 2024, marking the first decline since NAIC began tracking in 2015. The drop aligns closely with a 1.6% pricing reduction, indicating stable demand.
    • Surplus lines carriers maintained and slightly increased their share of cyber premiums, especially in complex and excess risk segments. Nearly all endorsement policies remain on admitted paper, while primary and excess are dominated by surplus lines.
    • First-party claims account for 75% of all cyber claims. Increased litigation and ransomware activity have extended the claims tail, driving higher loss and defense costs.
    • Roughly 50% of cyber premiums are ceded to reinsurers. While insurance-linked securities provide some capital (~$1bn), the sector remains vulnerable to reinsurance market shifts.

    The result is a better picture as to what types of policies are being issued and the premium paid for cyber coverage.

    For the first time since the NAIC began collecting data on cyber insurance, total direct premiums written (DPW) for the industry decreased.

    The premium decline was nearly identical to the year-over-year decline in pricing, indicating there was little change in cyber risk exposure from 2023 to 2024 (see 2025 Global Cyber Risk Report).

    With an increase in claims accompanying the drop in premium, the loss ratio, including defense and cost containment (DCC) expenses, did increase.

    Direct Premiums Written for Cyber Insurance

    Direct Premiums Written for Cyber Insurance

    In 2024, direct premiums written (DPW) for cyber insurance declined by 2.3% to $7.075bn, down from $7.244bn in 2023. U.S. cyber insurance premium rates decline in 2025. This marks the first annual decrease in cyber insurance premiums since the NAIC began collecting this data in 2015.

    Despite this drop, the direct loss ratio remained below 50%, indicating continued profitability for insurers underwriting cyber risk, even with inflationary pressure on losses and lower premium levels.

    The decline in DPW primarily reflects reductions in pricing rather than changes in exposure.

    According to data from the Council of Insurance Agents and Brokers (CIAB), cyber insurance pricing decreased by an average of 1.6% during the final three quarters of 2024.

    Surplus Lines as Share of all Cyber DPW

    Surplus Lines as Share of all Cyber DPW
    Source: AM Best

    The similarity between the decline in pricing and the overall drop in premium suggests that demand for cyber coverage remained stable, according to Global Cyber Insurance Industry Trend.

    The reduction in premium may also be linked to a trend among large organizations shifting their cyber risk coverage to single-parent captive insurers.

    Firms with strong cybersecurity practices and favorable historical loss experience often prefer to retain premiums within their own corporate structure.

    Admitted vs Surplus Cyber Paid Loss and DCC Ratio

    Admitted vs Surplus Cyber Paid Loss and DCC Ratio
    Source: AM Best

    By using captives, these organizations retain the financial benefit of their own performance. Since such captives typically do not report to the NAIC, this activity is not reflected in the cyber insurance supplement.

    During the hard market phase, premium growth significantly exceeded pricing increases, indicating rising demand for cyber insurance.

    In contrast, the current premium decrease aligns closely with the decline in pricing, further supporting the view that demand remains steady despite the overall market contraction.

    Cyber Insurance Market Totals

    CategoryPremiums 2024 ($mn)Chg (%)Market Share (%)Comb Ratio
    Top 52,153.1-5.830.471.6
    Top 103,509.22.349.675.2
    Top 205,393.32.776.278.1
    Total P/C Market7,075.2-2.3100.072.7
    Source: AM Best / Edited by Beinsure

    Surplus Lines Carriers Increase Market Position

    Much of the new capacity during the hard market came from surplus lines writers. Those carriers have held—and marginally increased—their market share even as the total premium slightly contracted. This increase in market share is not from any new growth.

    Total DPW among surplus writers was essentially unchanged, down by less than 0.1%, leaving most of the decrease to the admitted carriers.

    Surplus lines paper remains the prime vehicle for complicated cyber risks, and this is evident through the split among primary, excess, and endorsement coverage.

    Endorsement coverage, which is typically coverage added to the insured’s existing policy, is almost exclusively on admitted paper, 97%.

    Comparison of Surplus Lines Writers vs. Admitted Carriers

    Category2020–2022 Hard Market2023–2024 Market Conditions
    Market EntryNew surplus lines writers entered with favorable pricingNo significant new entrants reported
    Legacy LossesNot applicable to new writersOngoing for existing carriers
    Pricing TrendElevated pricing across most commercial segmentsPricing leveled off or decreased
    Target MarketLarger commercial entitiesContinued focus on large entities
    Edited by Beinsure

    The larger risks tend to buy surplus lines coverage for policy language tailored to the insured’s needs. On primary cyber policies, surplus writers account for a majority of the premium.

    This split is even more pronounced for the larger risks purchasing excess limit, where over three-quarters of the premium is written by surplus lines carriers.

    Top 20 U.S. Cyber Insurance Groups

    RankCompanyPremiums 2024 ($mn)Chg (%)Market Share (%)Comb Ratio
    1Chubb INA Group560.6-2.37.960.5
    2Travelers Group535.439.17.689.4
    3Fairfax Financial (USA) Group360.6-22.15.171.3
    4Tokio Marine US PC Group356.0-5.85.073.1
    5XL America Companies340.4-30.14.862.1
    6Arch Insurance Group285.01.04.074.0
    7At-Bay Specialty Insurance Co.280.6344.94.086.2
    8American International Group272.6-0.63.974.0
    9Sompo Holdings US Group262.7-0.13.783.9
    10Starr International Group255.1-1.93.6112.9
    11CNA Insurance Companies240.35.23.4103.7
    12AXIS US Operations204.612.92.953.8
    13AmTrust Group202.519.12.984.1
    14Berkshire Hathaway Insurance Group187.6-35.22.7113.2
    15Hartford Insurance Group185.66.12.643.4
    16Beazley USA Insurance Group184.923.52.641.9
    17QBE North America Insurance Group184.1137.92.6121.1
    18Liberty Mutual Insurance Companies169.8-4.82.4102.2
    19Zurich Insurance US PC Group168.2-15.62.4102.4
    20Ascot Insurance U.S. Group156.8-10.22.277.5
    Source: AM Best / Edited by Beinsure

    The new NAIC cyber supplement provides detailed information along with the new separation of primary, excess, and endorsement coverage.

    Excess policies, offering larger limits and typically covering larger entities with more exposure, are more expensive than either primary policies or endorsements to other policies.

    Cyber Insurance Claims

    Claims increased significantly in 2024 and are also consistent with the AM Best cyber questionnaire; first-party claims are about 75% of all claims.

    Ransomware attacks began accelerating about 5 years ago, and data for traditional actuarial analysis in the form of early development patterns is now becoming available.

    We believe there is still a tail on these losses, as litigation and discovery could be more protracted and hacks could be latent for a long time before they are exploited.

    Rising litigation activity may extend the claims tail, even for first-party cyber claims, increasing both claim costs due to inflation and legal expenses.

    Cyber Claims by Type

    Cyber Claims by Type
    Source: AM Best

    Third-party cyber risk presents growing challenges

    Policyholders now face exposure not only from their own operations but also through vendor relationships.

    Subrogation against a vendor responsible for a loss can be difficult if the vendor lacks sufficient assets, making recovery efforts uneconomical.

    Additionally, pursuing subrogation may strain the insured’s vendor relationship. As part of effective cyber risk management, insureds should conduct thorough due diligence on third-party vendors and prepare for such contingencies.

    Support from the insurance-linked securities (ILS) market signals some confidence in cyber risk models, but total capacity remains limited, with only around $1bn in coverage.

    The cyber insurance market remains heavily reliant on reinsurance, with approximately 50% of direct premiums written ceded to reinsurers.

    This reliance leaves the primary market vulnerable to shifts in reinsurance capital allocation. If reinsurers redirect capital elsewhere, the cyber market may face supply constraints and disruption.

    FAQ

    What changed in the NAIC’s cyber insurance reporting requirements?

    The NAIC replaced its previous two-way classification (standalone vs. packaged) with a three-way split: primary, excess, and endorsement, improving clarity on policy types and premium allocation.

    Why are year-over-year comparisons limited in the 2024 data?

    Due to changes in the NAIC reporting structure and exclusions of cyber business from alien insurers, direct year-over-year comparisons may not be fully reliable.

    What drove the decline in cyber insurance premiums in 2024?

    Direct premiums written declined by 2.3% to $7.075bn, mainly due to a 1.6% drop in pricing, indicating steady demand rather than reduced exposure.

    What is the role of surplus lines in the cyber insurance market?

    Surplus lines writers have maintained and slightly increased market share, focusing on complex risks and holding the majority of primary and excess cyber policy premiums.

    How are cyber insurance claims trending?

    Claims rose significantly in 2024. About 75% are first-party claims, with ransomware and litigation contributing to longer claims development and increased costs.

    Why is third-party cyber risk increasingly difficult to manage?

    Insureds are exposed through vendors. Subrogation is often not pursued due to vendors’ lack of assets or business relationships, stressing the need for vendor due diligence.

    How dependent is the cyber insurance market on reinsurance and ILS?

    About 50% of cyber premiums are ceded to reinsurers. While ILS participation is growing, coverage remains limited (~$1bn), leaving the market exposed to reinsurance capacity shifts.

    AUTHOR: Steve Robinson – Area President & National Cyber Practice Leader for Risk Placement Services