Average ransomware demand payments jumped 104% in a single quarter to $1.13 million even as incident volume fell 6% (Aon, Q2 2025), and Coalition's 2026 claims report puts the full-year increase at 47%, to just over $1 million on average. Filed cyber rates, meanwhile, just logged a twelfth straight quarterly decline, down 4% globally (Marsh, Q2 2026). That gap between what carriers charge and what ransomware now costs is the core problem in cyber ratemaking heading into 2027 renewals.

A Rate Cycle Still Falling, a Loss Cost Still Climbing

Marsh's Global Insurance Market Index for the second quarter of 2026 put cyber rates down 4% worldwide, the twelfth consecutive quarter of decline, following a 5% drop in the first quarter (Marsh, GIMI Q2 2026). The regional spread shows how uneven the softening has become: cyber fell 14% across India, the Middle East, and Africa, 10% in Latin America and the Caribbean, and just 2% in the United States, the market with by far the largest cyber book and the deepest claims history behind it (Reinsurance News, July 23, 2026). Overall commercial rates fell 6% globally in the same quarter, the eighth straight decline, driven by abundant capacity, strong insurer profitability, and a surplus of reinsurance capital. US casualty is the one line still hardening, up 7% in the second quarter after a 9% increase in the first (Insurance Journal, July 23, 2026). Cyber sits nowhere near that trajectory.

WTW's Insurance Marketplace Realities 2026 report frames the direction as decelerating rather than reversing: competitive conditions have held since 2022, cyber direct written premium fell 2.3% in 2024 on rate alone, and insurers are shifting focus toward book stability even as most accounts still see flat-to-single-digit rate movement in either direction (WTW, Insurance Marketplace Realities 2026, Cyber Risk). A pricing actuary reading only the headline rate print could reasonably conclude cyber pricing is approaching equilibrium. The claims data underneath the print says otherwise.

Frequency and Severity Move in Opposite Directions

Coalition's 2026 Cyber Claims Report, drawn from 2025 claims experience across its book, found initial ransom demands up 47% year over year to just over $1 million on average, with individual demands ranging from $9,000 to $16 million (Coalition, March 2026). Aon's data shows the same acceleration from a different angle: average ransomware demand payments rose 104% quarter over quarter to $1.13 million in the second quarter of 2025, even as the number of ransomware incidents Aon tracked fell 6% over the same period (Aon, 2025 Global Cyber Risk Report). Frequency and severity did not move together. That divergence is the actuarial problem in miniature, and it means a pricing actuary cannot default to a single blended cyber trend factor pulled from an aggregate industry benchmark without first separating the two components.

Severity itself is not uniform across the threat landscape. Coalition's claims data shows Akira, the most frequently observed ransomware variant on its book, demanding an average of $925,666, while RansomHub demanded more than $2.3 million on average, a spread of roughly two and a half times between the two most active operators (Coalition, March 2026). A book with concentrated exposure to double-extortion operators, who simultaneously encrypt systems and exfiltrate data and accounted for 70% of all ransomware claims in 2025, carries a materially different severity trend than a book weighted toward single-vector encryption events (Coalition, March 2026). A record 86% of Coalition's ransomware-affected policyholders refused to pay the demand in 2025, which caps realized loss cost below the headline demand figure for most claims, but the incidents that do settle are settling at a higher average than a year earlier, and the ones that do not pay still generate business-interruption and remediation costs that scale with the size of the demand. Selecting a single industrywide severity trend and applying it uniformly ignores that a carrier's own threat-actor mix, driven by its distribution of industry and company-size exposure, is itself a leading indicator of where its severity trend lands relative to the benchmark.

What Twelve Soft Quarters Do to the Premium Base

A cyber indication right now turns less on the trend selection than on what the premium in the denominator is worth. Twelve consecutive quarters of decreases mean every accident quarter in a standard three-year experience period earned premium at a rate level materially above today's, so an experience loss ratio computed on unadjusted premium flatters the current book: the denominator carries rate that no policy written this quarter will collect. On-leveled to the current rate level, the same loss experience produces a higher projected loss ratio and a higher indication, and the gap between the adjusted and unadjusted views widens with every additional soft quarter the experience period spans. Read against a permissible loss ratio in the typical cyber range, that adjustment is routinely the difference between an indication that clears and one that quietly breaches.

How deep the cumulative correction runs is not a published number. Marsh discloses the two most recent cyber prints, down 5% in the first quarter of 2026 and 4% in the second, but not the full quarterly series behind the twelve-quarter run, so the compounded market rate-level change from 2023 to today cannot be computed from the public record. It does not need to be: each carrier on-levels against its own filed rate history, and the index matters as evidence of how long and how uniformly the market has been sliding. The practical point is the cohort spread. A book with meaningful earned exposure from 2023 or 2024 needs a materially larger on-level adjustment than one renewing entirely inside the recent, flatter quarters, and treating the two books the same misstates both indications.

Credibility for a Book That Is Still Thin and Volatile

Cyber has none of the multi-decade loss history that anchors trend selection in auto liability or workers' compensation, and even a large carrier's ransomware claim count rarely supports a fully credible severity trend on its own; one hospital system or manufacturer with an eight-figure business-interruption claim can move a mid-size book's incurred ratio by several points in a single year. That pushes weight onto the benchmark complement, and the benchmark is aging fast. A severity assumption lifted from industry data assembled before the 2025 ransom-demand surge is already stale against Coalition's 47% and Aon's 104% prints, and the threat-actor mix underneath the aggregate moves faster than any annual study refresh. The uncomfortable position heading into 2027 pricing is a thin own-book trend blended against a benchmark that is both volatile and lagged, which argues for shorter trend periods, more frequent benchmark refreshes, and severity selections that lean on current threat intelligence rather than last cycle's claims study.

The Permissible Loss Ratio as a Renewal-Cohort Monitor

A single aggregate rate change number, the 4% cyber decline Marsh reports for the second quarter, obscures what is happening cohort by cohort. A more diagnostic view tracks the projected ultimate loss ratio for each renewal quarter's cohort of policies against the permissible loss ratio, holding the expense and profit provisions constant, and watches whether that gap is widening or narrowing over time. WTW's observation that the pace of cyber softening is decelerating, holding roughly flat to low single digits through 2026, could mean rate adequacy has stabilized. It could also mean filed rates have simply stopped falling fast enough to keep pace with a severity trend that Coalition and Aon both show accelerating, in which case each successive renewal cohort's projected loss ratio creeps closer to, or through, the permissible loss ratio even while the headline rate change looks stable. Tracking cohorts separately is the only way to distinguish the two scenarios, because a portfolio-level combined ratio computed across all cohorts blends vintages written at very different points in the rate cycle and can look adequate in aggregate while the most recent cohorts are already underpriced.

Limit and Retention Drift Beyond the Base Rate

A softening market rarely shows up only as a lower base rate. WTW notes increased interest in layered programs and alternative risk structures as carriers compete on terms rather than price alone, and market commentary across the cyber sector consistently describes competitive pressure translating into higher policy limits and lower self-insured retentions offered at flat or reduced premium. A higher limit at unchanged premium cuts the effective rate per dollar of coverage even when the filed base rate never moves, and a lowered retention hands the carrier more of the working layer at the same price. Because retention and limit terms are negotiated policy by policy rather than filed as a single rate level, this channel of erosion does not appear in any GIMI-style rate index at all. A pricing actuary relying solely on the filed rate movement to gauge adequacy is measuring only part of the erosion; the unfiled part, wider limits and thinner retentions granted at the same premium, can widen the true adequacy gap well beyond what a 4% quarterly rate decline suggests.

Desk Implications Before the 2027 Renewals

For the cyber pricing desk, the second-quarter print changes the work in specific ways. The severity trend needs selecting separately from frequency and stress-testing against the book's own threat-actor and industry mix rather than a blended market factor; a portfolio skewed toward the operators demanding seven figures is not trending at the market average. The premium base needs on-leveling against the carrier's own filed history across the full soft stretch, not just the recent quarters, before any experience ratio is read against the permissible loss ratio. And adequacy monitoring belongs at the renewal-cohort level, where a widening gap shows up quarters before the aggregate combined ratio concedes it.

Underwriting and reinsurance leadership carry their own version of the same question. Renewal packs deserve an explicit accounting of limit and retention drift, the erosion the rate index never sees, and January 1, 2027 treaty negotiations will price cyber quota shares and aggregate covers against exactly the severity data Coalition and Aon just published. The next checkpoints are dated: Marsh's third-quarter index lands in October, and third-quarter earnings will show whether US cyber loss ratios have started to absorb a $1 million average demand. A thirteenth consecutive rate decline printed against another severity increase moves this from a monitoring item to a 2027 plan assumption.

Further Reading on actuary.info