Skip to main content

The cyber market in 2026: Your questions answered

The 2026 cyber market is being shaped by shifts in pricing, claims, ransomware, AI and new broker opportunities. Find the latest insights from our expert panel session.

Cyber Article 1 min ven., mars 20, 2026

Cyber risk is shifting rapidly as new technologies, threat actors and market pressures reshape the landscape. AI‑enabled attacks are accelerating, ransomware continues to evolve, and concerns around systemic events are influencing how cyber exposure is assessed and priced.  

Below, you’ll find key trends and developments shaping the cyber market in 2026. Insights are drawn from our Inside Cyber Scoop webinar featuring Lindsey Maher, James Burns, Jason Hart and Kelly McGuinness – now available to watch on demand. 

  1. What does the cyber insurance market look like right now?

    It no longer makes sense to talk about the cyber market as one global whole market. Conditions vary widely by region. 

    Outside the US, the market looks relatively balanced – that includes the UK, Europe, Canada and Australia. These regions have generally remained profitable and cyber insurance is still underpenetrated, particularly among SMEs. While some rate softening is happening, it has stayed within reasonable bounds. That has helped make cyber insurance more accessible and driven demand. 

    The US is a different story. Competition remains intense, with a large number of insurers and MGAs chasing the same business. This has kept pricing under pressure for several years, even as claims activity has increased. As a result, profitability has taken a hit and some insurers are now pushing through rate increases, especially on renewals. While there are early signs of hardening, the US market has not fully tipped into hard market territory yet. 

  2. What is influencing cyber pricing the most in 2026?

    Pricing is being shaped by three main factors: capacity, competition and claims. 

    Reinsurance capacity is at an all-time high. That has fuelled the launch of new cyber MGAs, new Lloyd’s syndicates and expanded cyber offerings from established insurers. More capacity has naturally led to more competition, which has driven innovation and broader cover, but also put downward pressure on prices. 

    At the same time, claims activity has increased, particularly in the US. This has acted as a brake on continued rate softening and, in some cases, has led to selective price rises. Today’s pricing reflects a push and pull between abundant supply and rising loss activity. 

  3. How are insurers thinking about systemic cyber risk?

    Systemic risk is still an important topic, but the industry’s focus has shifted compared to a few years ago. When ransomware surged and profitability came under pressure, systemic exposure was front and centre. Today, insurers are much more focused on growth and increasing cyber adoption, especially among SMEs. 

    Greater reinsurance capacity has allowed insurers to transfer some perceived systemic exposure, and so far the market has been able to absorb major events. However, the panel emphasized the importance of being realistic about which systemic scenarios the private market can handle – and where its limits may lie. 

    High profile supply chain incidents, such as the Jaguar Land Rover cyber event, have shown just how severe the knock-on effects can be for smaller businesses that rely heavily on a single customer or supplier. These events are a useful reminder of why systemic and supply chain risk matter to brokers and their clients. 

  4. Are ransomware attacks increasing or changing?

    Unfortunately, ransomware continues to rise year on year, alongside other attack types such as business email compromise. 

    Several factors are driving this. Ransomware-as-a-service has lowered the barrier to entry, allowing less experienced attackers to operate through affiliate models. Automation and AI are also helping attackers scale phishing, credential theft and social engineering more efficiently. 

    Another notable shift is the growth of data extortion, where attackers skip encryption altogether and focus on stealing and threatening to leak sensitive data. At its core, the problem remains the same. Cybercrime is still highly profitable. 

  5. How does CFC’s security capability support underwriting and reduce claims?

    In today’s world, most organizations have dozens of vulnerabilities. But only a small number of these are actively exploited by threat actors. 

    CFC’s cyber security team work closely with underwriting and actuarial colleagues to identify the threats that genuinely matter, using exclusive threat intelligence, threat hunting, vulnerability scanning and real-time claims data. By cutting through the noise, insureds can focus on remediation that actually reduces risk, while underwriters gain a clearer view of exposure. 

    This close alignment between security and insurance plays a key role in helping to stop incidents before they turn into claims. 

  6. Are AI-enabled attacks materially changing the risk landscape?

    AI is speeding up cyber attacks, but not by inventing entirely new techniques. Instead, it is dramatically accelerating activities that used to take attackers weeks or months. 

    Tasks like mapping an organization’s attack surface, identifying employees and crafting targeted phishing emails can now happen in seconds. That increases both the speed and scale of attacks. 

    The flip side is that AI is also strengthening defence. Security teams and insurers are using the same technology to detect exploitation, identify zero-day vulnerabilities and respond faster. AI is reshaping both attack and defence, and cyber insurance needs to reflect that reality. 

  7. What separates a good cyber risk from a bad one in 2026?

    From an underwriting perspective, strong risks to insure tend to have a few things in common. They understand their cyber exposure, invest in controls year after year and treat cyber risk as an operational and business risk, not just a compliance exercise. 

    Expectations vary by size and industry. For SMEs, fundamentals like multi-factor authentication, tested backups and employee awareness training remain critical. Larger organizations are expected to show more mature controls, stronger governance and clear remediation processes. 

    A previous claim is not necessarily a deal breaker. A lack of improvement afterwards often is. 

  8. Where are the biggest opportunities for brokers?

    Cyber insurance remains significantly underpenetrated, especially among SMEs. Brokers who are successful in selling cyber insurance, tend to raise cyber earlier and more often in client conversations, not just at renewal, and focus on making risk tangible through real world claim scenarios. 

    There are also strong opportunities in industry focused approaches, program business and bulk quoting. Brokers who build confidence in specific sectors and keep the conversation simple are well placed to drive organic growth. 

Staying ahead in a fast-moving market 

Cyber is now a business-critical risk, and staying informed and proactive is key to keeping pace with as the landscape continues to shift at speed. If you’d like to explore any of these topics further or need clarity on how they apply to your work, our team is here to help – just get in touch. 

Watch the full webinar for a deeper dive into all the discussion points, and take your knowledge further by completing our Cyber Masterclass training. 

↑