ZeroHour
Huntresspublished ()ingested 1

2026 Cyber Insurance Trends Report: What's Changed and What You Need to Know

infoIndustryimportance 30
AI summary · glm-5.3-flash

Huntress survey: CIRCIA reporting mandates now live, BEC claims exceed ransomware, exfiltration-heavy attacks cost twice as much, premiums rising.

Huntress's 2026 cyber insurance trends report, based on its own survey, finds 79% of respondents carry cyber insurance while 58% report shrinking coverage over five years. New CIRCIA federal reporting mandates and EU NIS2 requirements are reshaping policies, business email compromise now drives more claims than ransomware, and data exfiltration has replaced encryption as the dominant ransomware tactic at roughly twice the cost. After three years of declining premiums, rates are climbing again, and most businesses now refuse to pay ransoms.

  • CIRCIA incident-reporting requirements are now in effect for critical infrastructure
  • BEC represents a larger share of insurance claims than ransomware
  • Data exfiltration is now the primary ransomware tactic and is twice as expensive
  • 58% of insured businesses report decreased coverage over five years
  • AI-powered attacks viewed by 61% as the biggest threat to premiums
VendorsHuntress
OrganizationsCISA
Full article2,962 words · extracted from huntress.com · click to collapse

The best offense is a good defense. That's even more true in 2026 when the rules around cyber insurance keep changing, attackers keep evolving, and the line between "covered" and "not covered" keeps moving under your feet.

Cyber insurance may not be at the top of every business's priority list, but all it takes is one incident you didn't see coming to see catastrophic results. The true cost of a cyberattack can exceed $250,000 - which most businesses without insurance absolutely can't afford. Despite this reality, our December 2024 survey found that 22% of companies still don't have cyber insurance.

And for the 78% that do? The coverage landscape has fundamentally changed in the last 18 months.

This Huntress survey reveals critical cyber insurance trends you need to know in 2026, including new regulatory mandates that are reshaping policies, the tactical shift in how attackers operate, and why the buyer's market that defined 2024-2025 is coming to an end. We'll also show you how the gap between cybersecurity and cyber insurance is finally starting to close and what that means for your business.

Key Takeaways

The cyber insurance landscape shifted hard in 2026. New federal reporting mandates ( CIRCIA ) are live. Attackers stopped encrypting and started stealing. Business email compromise (BEC) now drives more claims than ransomware. And after three years of falling premiums, rates are climbing again.

58% of businesses with cyber insurance report some level of decrease in their coverage over the past five years, even as threats intensified

Not understanding coverage options is the main reason organizations don't have cyber insurance (38%)

61% of respondents say AI-powered attacks are the biggest threat to their cyber insurance premiums

New federal and EU regulations (CIRCIA, NIS2) are creating compliance requirements that many existing policies weren't designed to cover

Data exfiltration has replaced encryption as the primary ransomware tactic, and it's twice as expensive

What's changed since 2025

Before we dig into the data, here's what shifted in 2026:

CIRCIA implementation : Federal incident reporting requirements now in effect for critical infrastructure entities

A significant majority of ransomware attacks now include data exfiltration , and these attacks are substantially more expensive

BEC represents a significant portion of claims , often more than ransomware

Premium softening is showing signs of ending : Many companies report cost increases on recent renewals

Manufacturing represents a significant portion of claims , one of the most targeted industries

Most businesses now refuse to pay ransoms , a significant shift from earlier years

The threats evolved. The regulations tightened. And the insurance market is responding.

58% of respondents report coverage has decreased

The majority of respondents (58%) noted a reduction in the scope of their cyber insurance coverage over the past five years, while 25% said there hadn't been any significant changes.

This is the uncomfortable truth: cyber insurance costs keep going up, which means some organizations are getting priced out of full coverage. They're taking out lower-limit policies or accepting higher deductibles just to stay insured. The result? Coverage that may not adequately reflect the evolving threat landscape, leaving businesses exposed when something actually happens.

Nearly 4 out of 5 businesses have cyber insurance

One of the more surprising cyber insurance trends is that most organizations surveyed have cyber insurance. While 79% may seem high, it varies a lot by company size. Roughly 74% of companies with 500 or fewer employees have cyber insurance, with that number dropping as low as 56% for those with fewer than 50 employees.

Cost is the main factor in why many organizations (26%) choose not to get cyber insurance , so it's not surprising that small and medium-sized businesses are less likely to invest in protecting themselves.

The majority of cybersecurity professionals feel they have the budget to protect their orgs

The majority of respondents (55%) strongly agreed that their organization has the budget to protect itself against cybersecurity threats. Only 2% strongly disagreed, while 38% somewhat agreed and 5% somewhat disagreed.

Given that cyberattacks are becoming more severe and happening more often - with the potential for crippling financial and reputational damage - investing in comprehensive cyber insurance isn't a nice-to-have anymore. It's a requirement.

The real question isn't whether you can afford insurance. It's whether you can afford not to have it.

Not understanding coverage options is the biggest barrier

As cyber insurance coverage requirements change and costs go up by as much as 25.5% year over year, businesses that already have cyber insurance struggle to keep up. Those without it may not even know where to start.

The majority of respondents without cyber insurance (38%) say "not understanding coverage options" is the main reason they haven't purchased a plan. Perceived low risk is the next consideration (28%), while cost comes in third (26%). Other factors (7%) include things like managing cyber events in-house.

Here's the problem: the cyber insurance market has gotten more complex, not simpler. Policies that made sense in 2023 may not cover the exposures that matter in 2026. If you don't understand what you're buying, you can't know if you're actually covered when something happens.

2026 regulatory changes are reshaping coverage requirements

If you thought cyber insurance was just about covering losses after an incident, 2026 changed the game.

New federal and international regulations are turning cyber insurance into a compliance necessity , not just a financial backstop. And if your policy doesn't explicitly cover regulatory defense costs, dual-reporting obligations, and incident notification timelines, you may be exposed in ways you didn't expect.

CIRCIA: Incident Reporting Requirements for Critical Infrastructure

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is establishing new reporting requirements for covered critical infrastructure entities. Key aspects include:

Covered entities in 16 critical infrastructure sectors are expected to report qualifying cyber incidents and ransomware payments on tight timelines

Sectors include healthcare, finance, energy, manufacturing, water, transportation, and more

At publication, final implementation dates, covered-entity counts, and penalty structures should be confirmed with your legal and compliance teams, as they may evolve over time

What does this mean for cyber insurance?

Your incident response timeline is tightening. If you're covered by CIRCIA, you need immediate access to forensics, legal counsel, and breach response resources , and your insurance policy needs to cover those costs.

Many policies written before these regulations took effect don't explicitly account for CIRCIA compliance. If your coverage doesn't include regulatory defense, notification costs, and forensic investigation support, you may be paying out of pocket for the help you need most.

NIS2: Raising the Bar for Cybersecurity Accountability

In the EU, the NIS2 Directive raises board-level accountability for cybersecurity in covered entities, including potential administrative fines and other sanctions for management bodies. Key aspects include:

Management bodies are expected to approve and oversee cybersecurity risk-management measures

Executives may face accountability measures , including administrative sanctions

Many organizations expect to increase security budgets to meet these requirements

Be sure to validate the latest guidance and enforcement practices with counsel

If you're an executive at a covered entity, this isn't just an IT problem. It's a governance issue. And traditional Directors & Officers (D&O) insurance may not fully address your exposure if regulators determine cybersecurity obligations weren't met.

The Dual-Reporting Challenge

Here's where it gets complex: organizations operating in multiple jurisdictions may face stacked reporting obligations .

A financial services firm with operations in both the US and EU might need to navigate multiple regulatory frameworks simultaneously, each with their own timelines and requirements. This includes CIRCIA reporting in the US, NIS2 notifications in the EU, and sector-specific financial regulator reporting.

The incident response team managing a ransomware attack must coordinate multiple regulatory submissions to different jurisdictions, while also managing containment and communicating with executive leadership.

If your cyber insurance policy doesn't cover the legal and forensic costs associated with dual-reporting compliance, you're absorbing those expenses yourself.

What to Ask About Your Policy

If you're subject to CIRCIA, NIS2, or other regulatory mandates, ask your broker or insurer:

Does the policy cover regulatory defense costs for incident reporting compliance?

Are forensic investigation and legal counsel fees covered within the first 72 hours?

Does the policy include notification costs for dual-reporting scenarios?

What are the sub-limits for regulatory response? (Some policies cap these costs separately from general breach response.)

Regulatory compliance is now a core part of the claims process. Make sure your coverage reflects that reality.

Insurers Require Several Cybersecurity Measures to Access Coverage

Our team has seen how cyber insurance has evolved over the years. Businesses are more interested than ever in buying cyber insurance, but there's also more of a burden on the company needing coverage to have certain protections in place.

"Cyber insurance is becoming a lot more expensive, cyber insurers are covering less, and they're requiring you to have more safeguards in place to be covered," Geftic says.

For organizations that have coverage now, cyber insurer compliance requires :

Security awareness training : 81% of organizations have this as a prerequisite for coverage

Identity Threat Detection and Response (ITDR) : Most ransomware and BEC attacks now start with compromised credentials, not exploited vulnerabilities, making identity the primary breach vector insurers screen for.

Multi-factor authentication : 79%

Endpoint detection and response (EDR) / managed detection and response : 65%

Vulnerability management : 65%

Air gap backups : 33%

Other, such as log data storage : 1%

The insurers' logic is simple: they won't pay for a claim if you didn't lock the door . Just like home insurance requires you to have a deadbolt, cyber insurance requires you to have EDR , MFA, and awareness training. If you don't have those controls in place, you're either not getting coverage or you're paying significantly more for it.

Data recovery is the most commonly covered cyber event

The majority of respondents (81%) were covered for data recovery, followed closely by data breaches (80%) and ransomware (63%). Some respondents also had coverage for business interruption/lost revenue (62%) and legal costs (59%).

On the other hand, less than half of cybersecurity plans included coverage for:

Third-party claims (50%)

Forensic investigation costs (43%)

Fines and penalties (42%)

Public relations costs (40%)

What's covered under a standard cyber insurance plan varies widely by provider, so it's important to shop around for the right plan for your organization. Always carefully review the policy documents to understand exactly what cybersecurity threats are covered and excluded.

The shift from encryption to data exfiltration

Ransomware used to be simple: attackers encrypted your files, demanded payment, and either gave you the decryption key or didn't. Businesses with good backups could restore systems without paying. Insurers could estimate the cost of downtime and recovery.

Not anymore.

In 2026, ransomware has shifted toward data theft without encryption , with many threat actors exfiltrating sensitive data first and then using the threat of public leaks—on top of encryption—to force payment.

Numbers tell the story

According to recent industry reports and threat intelligence:

A significant majority of ransomware incidents now involve data exfiltration in addition to or instead of encryption

Attacks with data exfiltration are substantially more expensive than encryption-only attacks

Initial ransom demands have increased significantly

Most businesses now refuse to pay ransoms , a dramatic shift from earlier years when payment rates were much higher

Why threat actors changed tactics

Better backups dramatically weakened the traditional ransomware model and pushed many attackers toward data theft and extortion.

Organizations got smarter about backup strategies - air-gapped backups, offline copies, tested recovery procedures. When attackers encrypted systems, many businesses could restore operations without paying. Ransom payment rates dropped significantly.

So attackers adapted. They realized that stealing data is often faster, easier, and creates stronger leverage than encryption alone . You can't restore stolen data from a backup. And the threat of leaking sensitive customer information, intellectual property, or financial records creates leverage that encryption alone doesn't.

Data exfiltration has become a primary lever in many modern ransomware operations. Encryption is increasingly optional.

Why this matters for insurance

Traditional cyber insurance was built around the "encrypt and extort" model. Policies covered:

System restoration costs

Business interruption losses

Ransom payments (in some cases)

But the new "steal and extort" model creates long-tail costs that extend far beyond system recovery:

Forensic investigations : Determining what data was stolen, when, and how

Legal liability : GDPR, CCPA, HIPAA, and other privacy compliance regulations impose fines and notification requirements

Regulatory fines : Average data breach cost hit an all-time high of almost $5 million in 2024, driven by stricter data privacy regulation

Notification costs : Informing customers, regulators, and partners about the breach

Credit monitoring services : Often required by law for affected individuals

Reputational damage : Harder to quantify, but the loss of customer trust can be devastating

Many policies written before 2024-2025 don't adequately cover data exfiltration events that don't involve encryption . If your policy defines ransomware narrowly as "encryption-based attacks," you may not be fully covered when attackers steal your data and threaten to leak it.

What to look for in your policy

Ask your broker or insurer:

Does the policy cover data exfiltration events without encryption ?

Are forensic mining and legal liability costs covered under the data breach response section?

What are the sub-limits for notification costs, regulatory fines, and credit monitoring?

Does the policy cover extortion payments related to data theft (even if no encryption occurred)?

The threat evolved. Your coverage needs to reflect that reality.

Business email compromise: A major claims driver

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.huntress.com/blog/cyber-insurance-trends