PRACTITIONER GUIDE | RISK MANAGEMENT
Practitioner Guide10 min read

Cyber Insurance in 2026: Why Ransom Payments Are Down 44% but Claims Are Up 40%

40%
Increase in cyber insurance claims volume year over year (Cowbell 2026)
44%
Reduction in average ransom payment amounts (Cowbell 2026)
65%
Average reduction in ransom demands achieved through negotiation (Cowbell 2026)
18-19%
Share of total claims attributable to ransomware/extortion, 2022-2025 (Cowbell 2026)

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

Two numbers from Cowbell's 2026 claims report look like they contradict each other. Claims volume is up roughly 40% year over year, which reads like a market getting worse. Average ransom payment amounts are down about 44%, which reads like a market getting better. Both are true at the same time, and the gap between them is not noise. It reflects a set of specific, identifiable mechanisms: better incident response and negotiation compressing what actually gets paid out, wider adoption of ransomware-as-a-service lowering the cost of launching an attack and therefore raising the number of attempts, and insurers responding to both trends by hardening what they will underwrite in the first place. For a security team, the practical question is not whether cyber insurance is a good idea in the abstract. It is how this specific shift in claims behavior should change what you ask your broker for, what controls you prioritize before your next renewal, and how much weight you put on risk transfer versus direct control investment.

What the 2026 claims data actually shows

Cowbell's 2026 claims report is the most concrete public data point behind the payments-down, claims-up framing, and it is worth being precise about what each number measures, because they are not measuring the same thing.

Claims volume rose approximately 40% year over year. That is a frequency number: more policyholders filed more claims. Separately, Cowbell reports that its average ransom payment amount fell approximately 44%, and that proactive negotiation reduced initial ransom demands by an average of 65% before any payment was made. That is a severity number on the ransomware subset of claims specifically, not a statement about overall claims payouts across the whole book.

Ransomware and extortion together made up roughly 18 to 19% of total claims from 2022 through 2025 in Cowbell's data, with data breaches (around 33.5%) and other cybercrime (around 31.8%) making up the larger share of claims volume. That matters for interpreting the headline: the 40% rise in claims is a whole-book trend across breach, cybercrime, and extortion claims combined, while the 44% payment reduction is specific to the ransomware slice of that book. The two trends are related but they are not the same measurement applied to the same population of incidents, and conflating them overstates how directly comparable the figures are.

A separate insurer data point adds useful contrast: Coalition has reported claims frequency actually decreasing for its own policyholder base, which it attributes to the effect of pairing required security controls with coverage. That is not inconsistent with Cowbell's rising frequency figure. Different insurers underwrite different segments of the market with different control requirements, and a book with stricter controls at binding can show a different frequency trend than a book with looser requirements. The market is not moving as a single uniform trend line.

Mechanism one: negotiation and incident response are compressing what gets paid

The 44% drop in average ransom payment is not primarily a story about victims refusing to pay. It is a story about the payment process itself becoming more disciplined. Insurers with dedicated incident response panels now routinely bring in professional ransomware negotiators before any payment decision is made, and Cowbell attributes an average 65% reduction in initial demand to that negotiation step alone. A ransom demand is an opening position set by the attacker with no visibility into the victim's actual backup posture, cyber insurance coverage limits, or willingness to walk away. A negotiator who can credibly demonstrate recoverability, or who simply has the experience to recognize an inflated demand, routinely brings that number down substantially before a check is ever considered.

Faster claims handling compounds this. The longer a ransomware incident drags on without a clear resolution path, the more leverage shifts toward the attacker, because downtime costs keep accumulating on the victim's side. Insurers that can mobilize forensics, legal, and negotiation resources within hours rather than days shrink that leverage window, which shows up directly in the eventual payment amount.

The practical implication for a security team is not that you no longer need backups or endpoint controls because insurers will just negotiate the ransom down. It is that your insurer's incident response panel and your organization's own recovery capability are now working the same problem from two directions, and your program should be built so both actually apply when an incident happens, not just on paper in the policy documents.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Mechanism two: better backup and recovery is removing the need to pay at all in some cases

The clearest lever a victim organization controls directly is whether paying a ransom is even necessary. An organization with immutable, tested, offline-capable backups and a rehearsed restoration process can decline to pay in scenarios where a less prepared organization would have no real alternative. This does not show up as a single number in the claims data, but it is consistent with the broader shift toward faster resolution and lower average payments: every incident where recovery from backup replaces a ransom payment removes a full-price payment from the average entirely, rather than just negotiating an existing payment down.

This is also where the claims-up trend and the payments-down trend connect rather than contradict each other. An organization can still file a claim (for incident response costs, business interruption, forensics, legal, and notification expenses) without a ransom payment being part of that claim at all. Rising claims frequency alongside falling ransom payment amounts is consistent with more organizations experiencing an incident that triggers coverage, while fewer of those incidents actually require paying an attacker to get data back.

Mechanism three: ransomware-as-a-service is raising attack volume faster than defenses can absorb it

The rising claims frequency side of the split has a straightforward driver: the cost and skill required to launch a ransomware attack keep falling. Ransomware-as-a-service and affiliate models let operators with limited technical sophistication rent access to functional ransomware, initial-access broker services, and negotiation playbooks, and CFC's 2026 market analysis identifies this lowered barrier to entry as a direct contributor to rising attack volume. More attackers attempting more intrusions, even at a lower average sophistication per attempt, produces more claims. This is a volume story, not a severity story, and it is a big part of why claims frequency can rise even as the security posture of individual defended organizations, on average, improves.

CFC's analysis also points to a parallel shift in attacker tactics that plays into the payments-down trend: a move toward data-only extortion, where attackers skip encryption entirely and instead threaten to leak stolen data. Skipping encryption is cheaper and faster for the attacker to execute, and it also sidesteps a defended organization's backup and recovery controls, since there is no encrypted system to restore from backup in the first place. Whether this shift lowers or raises average payment amounts depends heavily on the specific data stolen and the victim's exposure to regulatory or contractual consequences from a leak, so it cuts in more than one direction, but it is a documented change in how claims materialize and it should factor into how a team thinks about which controls matter for which attack pattern.

Mechanism four: insurers are hardening underwriting requirements in response

The most directly actionable mechanism for a practitioner is the one CFC is most explicit about: insurers are increasingly treating specific security controls as a precondition for coverage rather than a factor that simply adjusts premium. CFC's 2026 analysis describes three distinct outcomes for an applicant that cannot demonstrate required controls: outright denial of coverage, exclusion of specific incident types from the policy (ransomware being the most common exclusion target), or, worst of all, denial at claim time on grounds of material misrepresentation about the organization's actual security posture at binding.

That third outcome deserves its own emphasis, because it is where a program's risk-transfer strategy can fail silently. An organization that represents MFA as universally enforced, or backups as tested and immutable, at the time it applies for coverage, and then experiences an incident that reveals those controls were not actually in place as described, can have a claim denied specifically because of that gap between the application and the reality, independent of the underlying incident itself. A policy that looks fully bound on paper provides no actual risk transfer if the controls backing that binding do not hold up under claim-time scrutiny.

This is consistent with what insurers are asking for at renewal generally. Phishing-resistant MFA on remote access and privileged accounts, EDR with active monitoring rather than a license sitting unused, tested and immutable backups with documented restoration exercises, and formal incident response retainers are now closer to baseline requirements than differentiators for a growing share of the market. For a full walkthrough of what underwriters typically ask for at application and renewal, see our cyber insurance requirements checklist. For what actually happens operationally once a ransomware incident triggers a claim, including where negotiation and claims handling fit into the timeline described above, see our guide on the ransomware cyber insurance claim process.

What this means for risk transfer versus control investment

The 2026 data supports a specific reframing of how to think about cyber insurance, rather than a simple verdict for or against it. Insurance is not becoming less useful. Claims frequency rising 40% means more organizations are actually using their coverage, and the mechanisms above show that the payout side of that coverage is being managed more effectively than in prior years through negotiation and faster response. But the market's own behavior is telling you where the coverage boundary actually sits: increasingly, on whether your controls are real and demonstrable, not just represented on an application form.

That changes the calculus for where to put security budget relative to insurance premium. A control investment that both reduces the likelihood of a claim-triggering incident and satisfies an insurer's binding requirement is doing double duty: it lowers your actual risk and it protects your ability to collect if something happens anyway. A control gap that would trigger a coverage exclusion or a material-misrepresentation denial is not a risk your insurance is actually transferring, no matter what the policy schedule says, so closing that specific gap should usually outrank incremental limit increases on the same policy.

Concretely, before your next renewal conversation: ask your broker exactly which controls are binding conditions versus rating factors on your specific policy, ask what your insurer's incident response panel and negotiation process actually looks like in practice (not just what the policy language says it provides), and confirm that whatever you represented about MFA, EDR, and backup posture at application time is still true today, since that representation is what a claim-time review will be measured against.

Ask your broker which controls are binding conditions, not just rating factors

A rating factor changes your premium. A binding condition, if unmet or misrepresented, can void coverage for specific incident types or the entire policy. Get this distinction in writing for your actual policy, not a generic industry summary.

Re-verify your application representations before renewal, not after an incident

If your renewal application states MFA is enforced organization-wide or backups are tested quarterly, confirm that is still literally true today. A claim-time discovery that it is not true is the scenario CFC describes as material misrepresentation denial.

Ask what your insurer's incident response and negotiation process looks like operationally

Confirm the panel firm, expected activation time, and who controls the negotiation decision, before you need it. The payment reductions described in Cowbell's data come from this process actually functioning quickly, not from the policy simply existing.

Prioritize control investment that closes coverage-exclusion gaps first

If a specific gap (unenforced MFA on privileged accounts, untested backups, no formal incident response retainer) would trigger a ransomware exclusion or claim denial, treat closing it as higher priority than increasing policy limits on coverage that gap would already undermine.

The bottom line

Cyber insurance in 2026 is not getting weaker because claims are up, and it is not getting stronger just because average ransom payments are down. The two numbers describe different mechanisms: negotiation, faster claims handling, and better recovery capability are compressing what gets paid out on ransomware claims specifically, while a lower barrier to entry for attackers is driving up claims volume across the whole book. The part of this shift a security team can act on directly is the underwriting side, where insurers are increasingly treating MFA, EDR, tested backups, and incident response readiness as binding preconditions rather than optional upgrades. Confirm what your policy actually requires, verify your representations are still accurate, and prioritize the control gaps that would void coverage over the ones that would merely raise your premium.

Frequently asked questions

Does the 44% drop in cyber insurance ransom payments mean insurers are paying out less overall?

Not directly. Cowbell's 2026 data reports a 44% reduction in the average ransom payment amount specifically within the ransomware and extortion slice of claims, driven mainly by negotiation and faster claims handling. It is not a statement about total insurer payouts across all claim types, which include data breach and cybercrime claims that make up a larger share of overall claims volume.

Why are cyber insurance claims up 40% if security controls are improving industry-wide?

Rising claims frequency is largely a volume effect. Ransomware-as-a-service and affiliate models have lowered the cost and skill required to launch an attack, so more attackers are attempting more intrusions even where individual organizations' defenses have improved. More attempts against a large population of organizations produces more claims, independent of whether average defensive posture is better than in prior years.

Can an insurer deny a ransomware claim even if the organization has cyber insurance coverage?

Yes. CFC's 2026 market analysis identifies claim-time denial for material misrepresentation as a real outcome, where an organization represented controls like MFA or tested backups as being in place at application time and a claim investigation later shows they were not actually implemented as described. This is distinct from a coverage exclusion, which can also apply to ransomware specifically for organizations that could not demonstrate required controls at underwriting.

Should a security team spend more on controls or more on cyber insurance coverage in 2026?

The 2026 data suggests this is not an either-or decision. Controls that satisfy an insurer's binding requirements do double duty: they reduce the likelihood of a claim-triggering incident and they protect the organization's ability to actually collect on a claim if an incident happens anyway. A control gap that would trigger a coverage exclusion or claim denial makes additional policy limits on that same coverage largely theoretical, so closing binding-requirement gaps should generally take priority over increasing limits.

How does ransomware negotiation actually reduce the amount an organization ends up paying?

Cowbell's 2026 data reports an average 65% reduction in initial ransom demands achieved through proactive negotiation before any payment is made. Attackers set an opening demand with no visibility into the victim's actual backup posture, insurance limits, or willingness to walk away, and a professional negotiator engaged through an insurer's incident response panel routinely brings that number down substantially before a payment decision is finalized.

What is data-only extortion and why does it matter for cyber insurance claims?

Data-only extortion is when an attacker steals data and threatens to leak it without encrypting the victim's systems at all. CFC's 2026 analysis identifies this as a growing tactic because it is cheaper and faster for the attacker to execute and it bypasses backup and recovery controls entirely, since there are no encrypted systems to restore. It matters for insurance because it shifts risk toward regulatory and contractual exposure from a data leak rather than business interruption from downtime, which affects what a claim actually covers.

Sources & references

  1. Cowbell 2026 Cyber Insurance Claims Report
  2. CFC, "The US cyber market in 2026: your questions answered"

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.