Average ransomware demand payments jumped 104% in a single quarter to $1.13 million even as incident volume fell 6% (Aon, Q2 2025), and Coalition's 2026 claims report puts the full-year increase at 47%, to just over $1 million on average. Filed cyber rates, meanwhile, just logged a twelfth straight quarterly decline, down 4% globally (Marsh, Q2 2026). That gap between what carriers charge and what ransomware now costs is the core problem in cyber ratemaking heading into 2027 renewals.
A Rate Cycle Still Falling, a Loss Cost Still Climbing
Marsh's Global Insurance Market Index for the second quarter of 2026 put cyber rates down 4% worldwide, the twelfth consecutive quarter of decline, following a 5% drop in the first quarter (Marsh, GIMI Q2 2026). The regional spread shows how uneven the softening has become: cyber fell 14% across India, the Middle East, and Africa, 10% in Latin America and the Caribbean, and just 2% in the United States, the market with by far the largest cyber book and the deepest claims history behind it (Reinsurance News, July 23, 2026). Overall commercial rates fell 6% globally in the same quarter, the eighth straight decline, driven by abundant capacity, strong insurer profitability, and a surplus of reinsurance capital. US casualty is the one line still hardening, up 7% in the second quarter after a 9% increase in the first (Insurance Journal, July 23, 2026). Cyber sits nowhere near that trajectory.
WTW's Insurance Marketplace Realities 2026 report frames the direction as decelerating rather than reversing: competitive conditions have held since 2022, cyber direct written premium fell 2.3% in 2024 on rate alone, and insurers are shifting focus toward book stability even as most accounts still see flat-to-single-digit rate movement in either direction (WTW, Insurance Marketplace Realities 2026, Cyber Risk). A pricing actuary reading only the headline rate print could reasonably conclude cyber pricing is approaching equilibrium. The claims data underneath the print says otherwise.
Frequency and Severity Move in Opposite Directions
Coalition's 2026 Cyber Claims Report, drawn from 2025 claims experience across its book, found initial ransom demands up 47% year over year to just over $1 million on average, with individual demands ranging from $9,000 to $16 million (Coalition, March 2026). Aon's data shows the same acceleration from a different angle: average ransomware demand payments rose 104% quarter over quarter to $1.13 million in the second quarter of 2025, even as the number of ransomware incidents Aon tracked fell 6% over the same period (Aon, 2025 Global Cyber Risk Report). Frequency and severity did not move together. That divergence is the actuarial problem in miniature, and it means a pricing actuary cannot default to a single blended cyber trend factor pulled from an aggregate industry benchmark without first separating the two components.
Severity itself is not uniform across the threat landscape. Coalition's claims data shows Akira, the most frequently observed ransomware variant on its book, demanding an average of $925,666, while RansomHub demanded more than $2.3 million on average, a spread of roughly two and a half times between the two most active operators (Coalition, March 2026). A book with concentrated exposure to double-extortion operators, who simultaneously encrypt systems and exfiltrate data and accounted for 70% of all ransomware claims in 2025, carries a materially different severity trend than a book weighted toward single-vector encryption events (Coalition, March 2026). A record 86% of Coalition's ransomware-affected policyholders refused to pay the demand in 2025, which caps realized loss cost below the headline demand figure for most claims, but the incidents that do settle are settling at a higher average than a year earlier, and the ones that do not pay still generate business-interruption and remediation costs that scale with the size of the demand. Selecting a single industrywide severity trend and applying it uniformly ignores that a carrier's own threat-actor mix, driven by its distribution of industry and company-size exposure, is itself a leading indicator of where its severity trend lands relative to the benchmark.
The Loss-Ratio Indication and the Permissible Loss Ratio
The standard actuarial mechanism for testing whether a rate is adequate is the loss-ratio, or loss-cost, indication method (Werner and Modlin, Basic Ratemaking, CAS). The indicated rate change equals the trended, developed loss and loss-adjustment-expense ratio divided by the permissible loss ratio, minus one. The permissible loss ratio is one minus the variable expense ratio and the target underwriting profit provision; it represents the share of premium available to pay losses once commissions, taxes, general expenses, and profit are funded (ASOP No. 53, Estimating Future Costs for Prospective Property/Casualty Ratemaking). A cyber program running a 30% combined variable expense and profit load has a permissible loss ratio of 70%. Anything the trended loss ratio produces above 70% signals an indicated rate increase; anything below it signals room to reduce rate, at least on paper.
The method only works if the premium in the denominator reflects current rate level, not the mix of rates actually charged across the historical experience period. Cyber's twelve consecutive quarters of rate decreases means every historical accident quarter used to build the experience loss ratio earned premium under a materially higher rate level than today's book carries. Skip the on-leveling step and the experience loss ratio ends up compared against a permissible loss ratio built for today's rates while its own premium denominator still reflects yesterday's, understating how much loss-ratio deterioration the current rate level has actually produced.
On-Leveling Twelve Quarters of Decline With the Parallelogram Method
The parallelogram method handles on-leveling when rate changes are frequent and exposures earn continuously through a policy period (Werner and Modlin, Basic Ratemaking, CAS). Plotted on a square representing a calendar or accident period against the range of possible policy effective dates, each rate change slices the square into regions, and the area of each region measures the proportion of premium earned at each historical rate level. Summing those areas and comparing them to today's cumulative rate level produces an on-level factor for every historical period feeding the experience base.
Applied to cyber, the arithmetic gets material fast. Using only the two most recently disclosed quarterly rate movements, a 5% decline in the first quarter of 2026 and a 4% decline in the second (Marsh, GIMI Q2 2026), and extending that roughly 4.5% average quarterly pace back across all twelve quarters of decline for illustration, since Marsh has not published every individual quarterly print in that run, the compounded on-level factor from twelve quarters ago to today works out to somewhere in the neighborhood of a 40% to 45% cumulative rate reduction. That figure is an approximation built from the two confirmed data points, not a precise reported number, but the order of magnitude is the point.
| Quarters Since Written | Approx. Cumulative Rate Decline | Illustrative On-Level Factor |
|---|---|---|
| 4 quarters ago | ~17% | ×0.83 |
| 8 quarters ago | ~31% | ×0.69 |
| 12 quarters ago | ~43% | ×0.58 |
Illustrative, built by averaging the two most recently disclosed Marsh GIMI cyber rate changes (Q1 2026: -5%, Q2 2026: -4%) across all twelve quarters of decline. Not a reported Marsh figure.
A book with meaningful earned exposure from three years ago is on-leveling against a rate level roughly 40 points lower than what was charged when that exposure was written. An experience period that spans even one of those early, higher-rated quarters needs a materially larger on-level adjustment than a book renewing entirely within the last few quarters, and getting that adjustment wrong in either direction moves the indicated rate change by a comparable amount.
Credibility for a Book That Is Still Thin and Volatile
Cyber has none of the multi-decade loss history that anchors trend selection in auto liability or workers' compensation. Even a large carrier's own ransomware claim count, concentrated in the tail of a young line, rarely approaches the volume needed for full credibility under a classical limited fluctuation standard, and a single large loss, a hospital system or a manufacturer with an eight-figure business-interruption claim, can swing a mid-size book's incurred loss ratio by several points in one year. A partial-credibility blend, weighting the carrier's own trended experience by a credibility factor and the complement by an industry benchmark such as Coalition's claims data or a comparable market aggregator, produces a more stable trend selection than relying on either source alone. The complement matters more for cyber than for a mature line precisely because the carrier's own experience is both smaller and more volatile than the industry aggregate, and the industry aggregate itself is evolving quickly enough that a benchmark trend selected two years ago, before the 2025 ransom-demand surge, would already be stale.
The Permissible Loss Ratio as a Renewal-Cohort Monitor
A single aggregate rate change number, the 4% cyber decline Marsh reports for the second quarter, obscures what is happening cohort by cohort. A more diagnostic view tracks the projected ultimate loss ratio for each renewal quarter's cohort of policies against the permissible loss ratio, holding the expense and profit provisions constant, and watches whether that gap is widening or narrowing over time. WTW's observation that the pace of cyber softening is decelerating, holding roughly flat to low single digits through 2026, could mean rate adequacy has stabilized. It could also mean filed rates have simply stopped falling fast enough to keep pace with a severity trend that Coalition and Aon both show accelerating, in which case each successive renewal cohort's projected loss ratio creeps closer to, or through, the permissible loss ratio even while the headline rate change looks stable. Tracking cohorts separately is the only way to distinguish the two scenarios, because a portfolio-level combined ratio computed across all cohorts blends vintages written at very different points in the rate cycle and can look adequate in aggregate while the most recent cohorts are already underpriced.
Limit and Retention Drift Beyond the Base Rate
A softening market rarely shows up only as a lower base rate. WTW notes increased interest in layered programs and alternative risk structures as carriers compete on terms rather than price alone, and market commentary across the cyber sector consistently describes competitive pressure translating into higher policy limits and lower self-insured retentions offered at flat or reduced premium. Increased-limits-factor mechanics apply here the same way they apply to any excess-of-loss pricing problem: raising a policy's limit without a proportional premium increase lowers the effective rate per dollar of coverage even when the filed base rate is unchanged, and lowering a retention shifts more of the loss distribution's lower layers onto the carrier without adjusting the premium to match. Because retention and limit terms are negotiated policy by policy rather than filed as a single rate level, this channel of erosion does not appear in any GIMI-style rate index at all. A pricing actuary relying solely on the filed rate movement to gauge adequacy is measuring only part of the erosion; the unfiled part, wider limits and thinner retentions granted at the same premium, can widen the true adequacy gap well beyond what a 4% quarterly rate decline suggests.
The twelfth consecutive quarter of cyber rate declines is not, on its own, evidence that cyber pricing has gone soft in the way a stagnant severity trend would make it soft. It is evidence that filed rate and loss cost have decoupled, and only a loss-ratio indication built on properly on-leveled premium, split frequency and severity trends, and credibility-weighted severity assumptions will show a pricing actuary which side of that gap their own book stands on before the 2027 renewal cycle locks in another year of terms priced against yesterday's ransom economics.
Further Reading on actuary.info
- Akira's Ransomware Concentration Is Reshaping the Cyber Rate Model -- a deeper look at how threat-actor concentration feeds directly into severity trend selection for cyber pricing.
- A Mixture Model for Ransom Refusal in Cyber Severity Pricing -- the actuarial mechanics behind separating paid and unpaid ransomware claims within a severity distribution.
- Cyber Reinsurance Rates Drop 32% as Capacity Floods the Market -- how the same softening cycle is playing out one layer up, in the reinsurance treaties that back primary cyber books.
- Cyber Insurance 2026: The Market Forces Reshaping Coverage -- broader market context on capacity, competition, and coverage terms driving the current cycle.
- Mythos and the Cyber Aggregation Risk Underwriters Cannot Ignore -- how systemic aggregation risk complicates the same rate-adequacy question from a capital perspective.
Sources
- Reinsurance News, "Abundant Capacity and Competition Drive 6% Global Commercial Insurance Rate Decline in Q2'26: Marsh" (July 23, 2026)
- Insurance Journal, "Q2 Global Commercial Insurance Rates Keep Dropping, Except for US Casualty" (July 23, 2026)
- Marsh, Global Insurance Market Index 2026
- Coalition, "5 Essential Insights From Our 2026 Cyber Claims Report" (March 2026)
- Aon, "Ransomware Payouts Decline Despite Growing Cyber Claims Frequency," 2025 Global Cyber Risk Report
- WTW, Insurance Marketplace Realities 2026, Cyber Risk
- Werner, G. and Modlin, C., "Basic Ratemaking," Casualty Actuarial Society, 5th Edition
- Actuarial Standards Board, ASOP No. 53, "Estimating Future Costs for Prospective Property/Casualty Risk Transfer and Risk Retention"