🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Cyber Insurance Comparison: Carriers, Cost, and What the Data Actually Shows

September 15, 2026 · PlayCISO
TL;DR

U.S. cyber insurance just had its first-ever annual decline in total premium — direct written premium fell 7.11% in 2024 to $9.14B, average premium per policy dropped to $1,523, and Marsh reported a 5% Q4 rate decrease, the first quarterly drop after seven straight years of rising rates (NAIC, Aon, Marsh). At the same time, the industry loss ratio climbed to 49% from 42%, and claims volume rose roughly 40% — a market softening on price while the underlying risk hardens. This comparison covers what incidents actually cost by company size (NetDiligence), how the top 10 carriers stack up by market share and loss ratio (NAIC), what MGAs like Coalition, At-Bay, Cowbell and Resilience actually differentiate on, and what is and isn’t knowable about pricing — with every figure traced to a live source.

Two hosts discuss this article — generated on demand.

Search "cyber insurance comparison" and most of what comes back either repeats a per-control discount percentage no insurer has ever published, or quietly stops at "get a quote." This one is built the other way: only claims we could trace to a live primary source — a regulator filing, a claims study, a market report an insurer or broker actually published — stayed in. Where the data doesn’t exist, we say so instead of filling the gap with something that sounds plausible. Try the companion cyber insurance premium & cost calculator to see the same sourced figures interactively.

The market right now: rates falling, risk not

Two things are true about U.S. cyber insurance in 2024–25, and they point in different directions. Pricing is falling: average premium per policy dropped to $1,523 in 2024, down from $1,784 in 2023 and $1,645 in 2022 (Aon). Marsh reported U.S. cyber rates fell 5% in Q4 2024 — the first quarterly decrease after seven straight years of rising rates. Total U.S. cyber direct written premium, including alien surplus lines, fell 7.11% to $9.14 billion in 2024, the market’s first-ever annual decline (NAIC).

Underlying risk did not soften at the same pace. Claims reported climbed roughly 40% year over year to about 50,000 in 2024, and the industry’s overall loss ratio (incurred losses plus defense/cost-containment, all policy types) rose to 49%, up from 42% in 2023 (NAIC, cross-verified independently by Aon against the same underlying statutory data). Globally, Howden has reported cyber rates down roughly 22% from their mid-2022 peak, with premium growth slowing to about 6% annually in 2022–2024 versus a roughly 40% CAGR during the 2020–2022 hard market, and combined ratios averaging around 70% — figures cited via NAIC’s 2025 report; verify against Howden’s own 2025 Cyber Report before relying on the global number.

A falling premium against a rising loss ratio is historically the leading edge of a market turning — not a promise that prices keep falling. Insurers price primarily off trailing loss experience; 2024’s claims and loss-ratio data will show up in 2025–2026 renewal pricing, not in the numbers already booked.

What an incident actually costs, by company size

NetDiligence’s Cyber Claims Study 2024 Report — built from 10,464 real claims reported by insurers and breach coaches, 2019–2023 — is the closest thing to a primary-sourced, revenue-banded dataset on incident cost:

  • Under $50M revenue: 3,891 claims, average incident cost $139,000
  • $50M–$300M revenue: 1,584 claims, average $317,000
  • $300M–$2B revenue: 405 claims, average $1.8 million
  • $2B–$10B revenue: 112 claims, average $4.7 million
  • $10B–$100B revenue: 42 claims, average $33.3 million
  • Over $100B revenue: 3 claims, average $26.1 million

A newer, higher-level cut (NetDiligence’s 2025 study, as reported by RSM US) puts the five-year average at $246,000 for SMEs (under $2B revenue — 98% of claims) versus $10.3 million for large companies (over $2B — just 2% of claims but 51% of total claimed cost). Read this as claim/incident cost, a proxy for the risk carriers underwrite against — not a premium figure. There is a meaningful difference, and conflating them is the single most common error in "premium calculator" content online.

The top 10 U.S. cyber insurers by market share

NAIC’s 2025 market report gives a real, regulator-published table of 2024 direct written premium, loss ratio and market share, excluding alien surplus lines:

Carrier2024 DWPLoss ratioMarket share
1. Chubb$560.6M36.06%7.92%
2. Travelers$535.4M53.97%7.56%
3. Fairfax Financial$360.6M39.66%5.09%
4. Tokio Marine$356.0M43.47%5.03%
5. AXA$340.4M36.03%4.81%
6. Arch Insurance$285.0M41.67%4.03%
7. At-Bay Specialty$280.6M55.78%3.96%
8. AIG$276.6M49.26%3.91%
9. Sompo$262.7M57.84%3.71%
10. Starr$255.1M96.26%3.60%

Starr’s 96.26% loss ratio stands out — a carrier paying out 96 cents of every premium dollar in claims and defense costs is running close to unprofitable on the line, worth knowing if you’re evaluating renewal stability. Chubb and AXA’s loss ratios in the mid-30s, by contrast, suggest room to be more competitive on price relative to peers.

How the carriers and MGAs actually differ

The items below are drawn from each company’s own public materials — vendor self-description, clearly labeled as such, not independent research — except where a third-party source is cited.

  • Coalition bundles "Coalition Control," free attack-surface monitoring, login-anomaly blocking, a cyber health rating and third-party risk monitoring into every policy, and has reported 73% fewer claims than the industry average across its book, which requires MFA, encryption and security-awareness training.
  • At-Bay positions itself as "InsurSec" — insurance plus active risk monitoring from an in-house security team — and has previously reported 7x-below-industry ransomware frequency and 5x-faster vulnerability remediation for insureds; that specific stat appears to date to roughly 2021 based on the events it references, so treat it as historical rather than current.
  • Cowbell explicitly segments by size (Prime 100/100 Pro for small business, Prime One/250 for middle market) and runs continuous underwriting via a proprietary risk score ("Cowbell Factors") and monitoring platform, positioning against the industry’s traditional annual-only underwriting cycle.
  • Resilience targets middle-market and large enterprise, pairing cyber-risk-quantification software with paper backed by A-rated P&C carriers, and offers limits reported up to $20M primary or excess.
  • Corvus is now part of Travelers, which completed a $435 million acquisition of Corvus Insurance on January 2, 2024, folding Corvus’s underwriting, scanning and claims-support capabilities into Travelers’ cyber line.
  • Chubb runs "Cyber Enterprise Risk Management," reports insuring 95% of Fortune 1000 companies, and offers a 24/7 incident-response hotline plus complimentary vulnerability-management and awareness tooling on top of the policy.
  • Hiscox markets a CyberClear product for small and mid-size businesses and a complimentary automated anti-ransomware platform ("Paladin Shield") for policyholders.

Beazley, AIG/Lexington and Travelers’ legacy (pre-Corvus) cyber line each have real market presence — Beazley in particular is a long-standing cyber-market leader — but we couldn’t independently verify a specific current differentiator claim for them at the time of writing and would rather leave the gap than guess.

What actually moves underwriting — and what doesn’t have a public number

Here is the honest state of the evidence: no citable primary source publishes a specific premium discount tied to any individual security control. If you’ve seen a claim like "MFA saves you 8% on premium," it did not come from a carrier filing, a regulator report, or a claims study we could find — it’s an invented number, and this article deliberately doesn’t repeat one.

What is real and citable: MFA, EDR/managed detection, offline or immutable backups, privileged access management and a tested incident response plan have become underwriting preconditions at most carriers — lacking them more often gets an application declined or non-renewed than merely surcharged. Coalition’s reported 73%-fewer-claims outcome for its controls-required book is the strongest available evidence that these controls correlate with better loss outcomes at the portfolio level, even without an isolated per-control number. Ransomware negotiation specialists, separately, have been reported (via NAIC’s citation of Arctic Wolf) to reduce ransom payments by 64% on average and avoid payment entirely in 70% of negotiated cases — a claims-outcome lever, not a control, but relevant to any insurer’s loss math.

Check your own posture against the controls carriers actually ask about on PlayCISO’s free Cyber Insurance Readiness check — it scores the same MFA/EDR/backup/PAM/IR questions underwriting applications use, without pretending to output a premium number either.

What we couldn’t verify — and left out

In the interest of the same honesty this article asks of the industry: several commonly repeated cyber-insurance statistics could not be traced to a live, primary source and are deliberately absent above — including specific small-business annual premium ranges (multiple broker marketing pages cite figures with no underlying dataset), a widely repeated social-engineering sub-limit figure, and a claimed AIG ransomware co-insurance requirement. If you’ve seen those numbers elsewhere, ask for the primary source before using them in a board deck.

How to actually compare quotes

  1. Get at least three quotes spanning a traditional carrier (Chubb, Travelers, AXA), an MGA with a security platform (Coalition, At-Bay, Cowbell), and your broker’s excess/surplus market if you’re large enough to need it.
  2. Compare loss ratio, not just price. A cheap quote from a carrier running a 96% loss ratio (like Starr’s 2024 figure) is a renewal-stability risk — that pricing may not hold.
  3. Read what’s bundled. Coalition, At-Bay and Cowbell fold monitoring/scanning tools into the policy price; a traditional carrier’s lower headline premium may not include equivalent tooling.
  4. Confirm the controls gate before you shop. If you can’t attest to MFA everywhere, EDR on all endpoints, and tested offline backups, expect declines or unfavorable terms regardless of carrier — fix the gate first.
  5. Ask what a loss would actually cost you using real claims data for your size (see the incident-cost table above), not a vendor’s worst-case pitch, to size the limit you’re actually buying.

Frequently asked questions

Is cyber insurance getting cheaper right now? Yes, based on the most recent published data. Average U.S. premium per policy fell to $1,523 in 2024 from $1,784 in 2023 (Aon), and Marsh reported a 5% rate decrease in Q4 2024 — the first quarterly decrease after seven consecutive years of rising rates. Total U.S. cyber direct written premium fell 7.11% in 2024 to $9.14B, the market’s first-ever annual decline (NAIC).

Why are rates falling if claims are going up? They’re not moving in the same direction for long — that’s the tension worth watching. Claims reported rose roughly 40% year over year in 2024 and the industry loss ratio climbed to 49% from 42% (NAIC), even as premiums fell. A rising loss ratio against falling premium is historically what precedes a market hardening; underwriters price off trailing loss experience, so 2024’s numbers are a leading indicator for 2025–2026 renewals, not a guarantee prices keep falling.

Which carrier is the "best" for cyber insurance? There isn’t a single answer — it depends on your size and what you value. Chubb and Travelers lead by market share and DWP with comparatively low loss ratios (36% and 54% respectively in 2024). MGAs like Coalition, At-Bay and Cowbell bundle a security-monitoring platform into the policy and target small-to-middle-market accounts with usage-based, continuously underwritten pricing. Resilience and the excess/surplus lines market serve large enterprise. Compare based on what your broker actually gets quoted, not marketing claims — including the ones in this article, which are labeled as vendor self-description where that’s what they are.

Does having MFA, EDR or backups actually lower my premium? No public, citable source ties a specific dollar or percentage discount to any single control. What is real: virtually every carrier now requires MFA, EDR and offline/immutable backups as a precondition to bind coverage at all — lacking them gets you declined or non-renewed more often than it gets you a worse price. Coalition has reported that its policyholders, who are required to run these controls, see 73% fewer claims than the industry average — a real aggregate outcome from one carrier’s book, not a premium formula.

What actually costs the most when a cyber incident happens? Scale matters enormously. NetDiligence’s claims data (2019–2023) shows average incident cost ranging from $139K for companies under $50M in revenue up to $33.3M for companies in the $10B–$100B band — not a straight line, since a handful of catastrophic large-company incidents pull the average up sharply relative to claim frequency. A 2025 update (via RSM’s reporting on NetDiligence) put the five-year average at $246K for SMEs versus $10.3M for large companies, with the 2% of claims from large companies accounting for 51% of total claimed cost.

Ready to practise the decisions these articles describe?

Run a free War Room →
Cyber Insurance Comparison: Carriers, Cost, and What the Data Actually Shows | PlayCISO Blog · PlayCISO