Skip to main content
VA Horizon
Book a Call
Statistics

Cyber Insurance Claims Frequency and Severity Statistics 2026

Quick answer

NetDiligence’s 15th annual 2025 Cyber Claims Study analyzed 10,402 total cyber insurance claims spanning incidents from 2020 through 2024, adding 4,108 new claims in 2025 alone, including 1,691 tied to 2024 incidents, with 9,171 of those claims meeting the study’s $1,000 minimum financial threshold for inclusion. Ransomware and business email compromise remain the top two named causes of loss in the study.

The clearest frequency-versus-severity finding in the study: large companies represented only 2% of the claims dataset by count, but accounted for over half of all incident costs, driven by scale and incident complexity rather than by how often a large company gets hit. That concentration sits alongside a softer pricing trend elsewhere in the line, with CIAB’s Q2 2025 survey reported to have put cyber liability’s rate change at a decline of 1.5% the same period.

Inside the Fifteenth Annual Cyber Claims Study

NetDiligence’s 15th annual 2025 Cyber Claims Study analyzed 10,402 total claims spanning incidents that occurred between 2020 and 2024, adding 4,108 new claims in 2025 alone, including 1,691 tied specifically to 2024 incidents. Of that total, 9,171 claims met the study’s own $1,000 minimum financial threshold for inclusion.

A study running fifteen consecutive annual editions, built on a dataset spanning multiple thousands of claims, is a meaningfully more established data source than a one-off vendor report, part of why its findings carry real weight in a line where reliable claims data is otherwise hard to come by.

Ransomware and Business Email Compromise Still Lead

The study names ransomware and business email compromise as the top two causes of loss in its dataset. Both are well-established attack patterns at this point, not emerging or unusual ones, which is itself informative: the cyber claims picture in 2025 was still dominated by known, well-documented threat types rather than a genuinely new category displacing them.

This page does not attach specific claim-count or dollar-average figures to either cause of loss individually. Several secondary aggregator pages circulating those exact splits could not be traced back to NetDiligence’s own primary report, so they are deliberately not repeated here.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

The 2% That Drives More Than Half the Cost

The study’s clearest frequency-versus-severity finding: large companies represented only 2% of the claims dataset by count, but accounted for over half of all incident costs, driven by scale and incident complexity rather than sheer frequency of attacks. Small and mid-size companies drive most of the study’s claim volume; large companies drive a disproportionate share of its total cost.

That is a direct, primary-sourced illustration of why claim frequency and claim severity are genuinely different questions in this line. A carrier or producer focused only on how often claims happen would badly underestimate where the real dollar exposure concentrates.

A Softening Rate Sitting on Top of This Claims Picture

CIAB’s Q2 2025 survey is reported to have put cyber liability’s rate change at a decline of 1.5% that quarter, one of five commercial lines to post an outright rate decrease. That specific magnitude reaches this page through secondary reporting on the survey rather than an independently confirmed direct read of it.

A softening headline rate sitting on top of a claims study showing large-loss severity concentrated in a small share of accounts is a combination worth naming directly to a client rather than leaving unspoken: a lower premium this year says nothing about whether the underlying severity risk in a large or complex account has actually gone down.

Why Frequency and Severity Are Different Underwriting Problems

This is reasoning, not a separately cited statistic: a claim type or account segment that is common but individually inexpensive is a different underwriting and pricing problem than one that is rare but catastrophic when it happens. The study’s large-company finding is exactly that second pattern, low frequency by count, outsized share of total cost.

A producer working larger, more complex commercial accounts in this line is underwriting into the segment the study’s own data says carries the heaviest severity concentration, not just a bigger version of the same small-business cyber risk.

Explaining the Gap, Not Just Quoting the Rate

A prospect focused only on this year’s premium number is missing the more complete picture this claims data actually tells. A producer who can explain why severity concentration matters, especially for a larger or more complex account, is offering something a rate quote alone does not.

Human + AI SDRs book qualified cyber liability meetings for commercial lines producers, so that fuller conversation happens with the prospects most likely to need it.

The Numbers

1

NetDiligence’s 15th annual 2025 Cyber Claims Study analyzed 10,402 total claims spanning incidents from 2020 to 2024, adding 4,108 new claims in 2025 (including 1,691 from 2024 incidents); 9,171 claims met the study’s $1,000 minimum financial threshold.

NetDiligence, NetDiligence Releases Fifteenth Annual 2025 Cyber Claims Study

2

Ransomware and business email compromise remain the top two named causes of loss in the study.

NetDiligence, NetDiligence Releases Fifteenth Annual 2025 Cyber Claims Study

3

Large companies represented only 2% of the claims dataset by count but accounted for over half of all incident costs, driven by scale and incident complexity.

NetDiligence, NetDiligence Releases Fifteenth Annual 2025 Cyber Claims Study

4

CIAB’s Q2 2025 survey is reported to have put cyber liability’s rate change at a decline of 1.5%, one of five commercial lines posting an outright decrease that quarter.

CIAB, Q2 2025 P&C Market Survey

Sources

The external data in this article draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

How many cyber insurance claims does NetDiligence’s 2025 study cover?
10,402 total claims spanning incidents from 2020 to 2024, with 4,108 new claims added in 2025, of which 9,171 met the study’s $1,000 minimum financial threshold for inclusion.
What are the most common causes of cyber insurance loss?
Ransomware and business email compromise remain the top two named causes of loss in NetDiligence’s 15th annual 2025 Cyber Claims Study.
Do large companies file more cyber claims than small businesses?
No. Large companies represented only 2% of the claims dataset by count, but accounted for over half of all incident costs, a severity, not frequency, pattern.
Are cyber insurance rates rising or falling in 2026?
Falling, per reporting on CIAB’s Q2 2025 survey, which put cyber’s rate change at a decline of 1.5%, one of five commercial lines to post an outright decrease that quarter.
Does a falling cyber rate mean severity risk has also gone down?
Not based on this data. NetDiligence’s claims study shows severity concentrated heavily in large, complex accounts, a pattern independent of whether the average premium is rising or falling.

Cyber submissions need a producer who can explain the severity gap.

Book a 15-minute call and see how Human + AI SDRs book qualified cyber liability meetings for commercial lines producers.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement

Recommended next steps