Munich Re agreed on August 19, 2026 to pay $575 million for At-Bay, the AI-native cyber insurtech, and board member Mike Kerner called the company's market position "a perfect addition" the day the deal was announced (Munich Re, August 19, 2026). The price is less than half the $1.35 billion valuation At-Bay carried after its 2021 Series D, and roughly 2.1x its $278 million of 2025 gross written premium (Insurance Journal, August 2026).

At-Bay will be folded into Hartford Steam Boiler, Munich Re's specialty insurance arm, rather than kept as an arm's-length capacity relationship. That makes the deal a clean build-versus-buy verdict: a top reinsurer decided owning an algorithmic cyber underwriting engine outright was worth more than reinsuring one.

$575M
Enterprise value Munich Re is paying for At-Bay, folded into Hartford Steam Boiler rather than run as a standalone unit
2.1x
Multiple on At-Bay's $278 million of 2025 gross written premium, down from a $1.35 billion valuation in 2021
$9.14B
Total US cyber insurance premium in 2024, the first-ever annual decline for the line (NAIC, 2025)

Key Takeaways

  • Munich Re is paying $575 million in enterprise value for At-Bay, with closing expected in the first quarter of 2027 and the company folded into Hartford Steam Boiler rather than run as an independent MGA.
  • The price is a repricing, not a growth story: roughly 2.1x At-Bay's $278 million of 2025 gross written premium, versus the $1.35 billion valuation from its 2021 Series D.
  • At-Bay credits its Active Risk Monitoring with ransomware frequency roughly seven times below the industry average, but part of that gap is risk selection at bind, not a treatment effect of the monitoring itself.
  • Active mitigation has no mechanism against the aggregation tail, the exposure the capacity market priced with $250 million of new non-proportional cyber reinsurance capacity in the first half of 2025.
  • The deal lands in a softening market: US cyber premium fell 7.11% to $9.14 billion in 2024, the first annual decline the NAIC has recorded for the line.

The Deal Terms

At-Bay's connection to Munich Re did not start with the August 19 announcement. Insurance Journal reported that Hartford Steam Boiler, Munich Re's specialty insurance arm, has been an At-Bay partner since the company's founding in 2017. Munich Re Ventures' HSB fund was also among the investors that backed At-Bay's 2021 Series D, alongside Icon Ventures, Lightspeed Venture Partners, and Khosla Ventures.

That history matters for how the deal should be read. This is not a reinsurer buying a stranger's book of business sight unseen. It is a reinsurer that has spent close to a decade underwriting behind At-Bay's own risk selection, converting a capacity-and-minority-stake relationship into full ownership of the underwriting engine, the claims history, and the security-scanning infrastructure that produces it.

The mechanics of the deal are straightforward (Munich Re, August 2026; Insurance Journal, August 2026):

  • Price: $575 million in enterprise value.
  • Timing: expected to close in the first quarter of 2027, pending regulatory approval.
  • Structure: At-Bay sits inside HSB rather than continuing as an independently branded MGA fronting for outside carriers.
  • Scale: $278 million in gross written premium and $23 million in cyber fee service revenue as of December 31, 2025, a top-10 position in the US cyber insurance market, and roughly 280 employees split between the US and Israel.

At-Bay chief executive Rotem Iram framed the deal in terms of scale rather than exit: "Joining Munich Re will accelerate At-Bay's mission to close the cybersecurity protection gap for the 90% of businesses being left behind" (Munich Re, August 19, 2026).

The Valuation Reset

Neither company's press materials dwell on what the $575 million price implies about At-Bay's trajectory since 2021. SecurityWeek reported that At-Bay closed a $185 million Series D in July 2021 at a $1.35 billion post-money valuation, co-led by Icon Ventures and Lightspeed. The round cited 800% year-over-year premium growth at the time.

At-Bay added a $20 million extension that October, bringing the round to $205 million and its cumulative funding to roughly $272 million. Against that backdrop, a $575 million sale price five years later is a repricing, not a growth story. The equity value implied by the acquisition sits well below the peak the venture market assigned At-Bay during the 2020-2021 cyber hard market, even as its premium base and market position both grew.

Date Event Disclosed Value
July 2021 Series D close, co-led by Icon Ventures and Lightspeed $185M raised, $1.35B post-money valuation
October 2021 Series D extension, adds ION Crossover Partners $20M added, $205M total round
December 2025 Reported year-end scale ahead of acquisition $278M gross written premium, $23M cyber fee revenue
August 19, 2026 Munich Re definitive acquisition agreement $575M enterprise value (2.1x GWP)

That compression is a data point for every venture-backed, AI-native cyber MGA still looking for an exit. A platform can grow its book, hold a top-10 market position, and still sell for less than 43% of the equity value it commanded when growth capital, not underwriting profit, was the metric investors priced against.

Munich Re did not buy At-Bay's growth story. It bought a book with $278 million of premium and a scanning and mitigation infrastructure it has watched perform from the reinsurance side for years, at a price built on realized economics rather than projected ones.

Pricing Implications: Selection vs. Treatment

What At-Bay's Data Claims

At-Bay's underwriting model, which it calls InsurSec, bundles cyber coverage with continuous external vulnerability scanning and pushed remediation guidance. Security posture is monitored throughout the policy term rather than treated as a one-time underwriting questionnaire. At-Bay's own published data makes three claims for the Active Risk Monitoring program (At-Bay, 2026):

  • Ransomware frequency in its book runs roughly seven times below the industry average.
  • A policyholder is 25% less likely to experience any type of cyber incident after resolving a flagged alert.
  • 80% of policyholders patch a flagged vulnerability within 2.5 months on average, twice as fast as the general population. That speed matters because claims cluster heavily in the first 30 days after a vulnerability is first observed.

The Selection Problem

Those figures are the entire commercial argument for a $575 million price tag. They are also where a pricing actuary evaluating the deal's economics has to slow down.

The "seven times below industry average" comparison is a portfolio-level statistic, measured against an outside population that never went through At-Bay's underwriting funnel in the first place. Businesses that buy a cyber policy bundled with continuous scanning, and actually engage with the resulting alerts, are plausibly more security-mature to begin with. Part of that sevenfold gap is therefore a selection effect baked in at the point of sale, not a treatment effect produced by the monitoring.

The 25%-less-likely figure is closer to a clean causal comparison. It holds the underlying population constant and compares insureds who resolved a given alert against those who did not act on the same alert.

Crediting the full portfolio-level gap to the mitigation product, rather than isolating what alert resolution itself buys once selection is held constant, is how a rating plan double-counts a benefit that underwriting selection at bind already captured. That is the actuarial question Munich Re is now buying the answer to. A competing cyber carrier evaluating a similar acquisition should insist on the same analysis before pricing an active-mitigation credit into its own book.

Reserving Implications

Cyber is conventionally reserved as a short-tail line relative to casualty business; most claims develop and close within a year or two of the triggering event. That headline characteristic coexists with a tail an individual policyholder's patching speed cannot touch: silent aggregation and systemic-event risk. A single compromised cloud provider, software vendor, or managed service platform can produce simultaneous claims across large numbers of otherwise well-secured insureds at once.

The IAIS's December 2025 Global Insurance Market Report found that the insurance sector's aggregate systemic risk profile declined slightly and remains well below the banking sector's. But supervisors continue to track affirmative and silent cyber coverage specifically because a major systemic event, not idiosyncratic ransomware, is the scenario that could reverse the sector's current pricing trend (IAIS, December 2025).

That distinction is the reserving-relevant point Munich Re's acquisition does not resolve. At-Bay's Active Risk Monitoring plausibly bends idiosyncratic frequency, the loss driver that shows up when one insured misconfigures a server or ignores a phishing warning. It has no mechanism, by design, against a correlated event that hits At-Bay's entire book simultaneously through a shared vendor dependency. Remediation speed at any single insured does nothing to stop a supply-chain compromise upstream of all of them.

The reinsurance capacity market is still pricing that gap separately from primary underwriting quality. Lockton Re tracked $250 million of new non-proportional cyber reinsurance capacity entering the market in the first half of 2025 alone. That capital was raised specifically to absorb the aggregation scenarios a bind-time active-risk score cannot underwrite away (Lockton Re, July 2025). Owning At-Bay does not retire that exposure for Munich Re; it moves the exposure onto Munich Re's own book instead of one it reinsures from the outside.

The Build-vs-Buy Verdict

Munich Re's decision sits at the far end of a spectrum other insurers and vendors have been testing throughout 2026, and it is the clearest data point yet for what that spectrum is actually worth:

Munich Re did none of those. It did not integrate At-Bay's scoring API, and it did not build a competing scanning-and-mitigation product inside HSB. It bought the entire underwriting company, its in-force book, its claims history, and its scanning infrastructure outright, at a price that values the whole operation at roughly 2.1 times one year of premium.

That is the actual verdict this deal delivers. In a line where loss history is short, non-stationary, and hard to model from public data alone, a top-five reinsurer concluded that six years of watching a proven risk-selection engine from the capacity side was not, by itself, enough to replicate its data advantage internally. Owning the underwriting and the mitigation infrastructure together was worth a premium over reinsuring them separately. The 2021-to-2026 price collapse suggests that premium was not unlimited; Munich Re bought ownership at a price the market itself had already brought down.

Capital Stack and Market Context

What Ownership Internalizes

Folding At-Bay into HSB rather than keeping it as an arm's-length MGA changes how its book gets capitalized. As an independent MGA, At-Bay placed capacity with multiple carriers, including HSB. Whatever margin sat above its own retention flowed in part to outside reinsurers standing behind those fronting arrangements, the same market that absorbed the $250 million of new non-proportional cyber capacity Lockton Re tracked in the first half of 2025.

Once At-Bay operates inside HSB, that premium and its associated retention can move through Munich Re's own group retrocession program instead of being placed externally. Munich Re retains more of the underwriting margin on a book it has spent years reinsuring from the outside. It also takes on the aggregation tail described above directly on its own balance sheet, rather than sharing it broadly across the open market.

A Softening Primary Market

That internalization compounds the softening the broader market is already navigating. US cyber direct written premium recorded its first annual decline in 2024, even as active policy counts held roughly flat at 4.37 million, evidence that the drop reflects falling rate rather than falling demand (NAIC, 2025).

Measure 2023 2024 Change
Total US cyber direct written premium (NAIC) $9.84B $9.14B -7.11%, first recorded annual decline
US-domiciled carrier premium (A.M. Best, cited in Lockton Re's mid-2025 capacity report) $7.2B $7.1B Same direction

A softening primary market is exactly the environment in which a proprietary risk-selection engine becomes more valuable to a reinsurer trying to hold underwriting margin. Owning one beats renting access through reinsurance treaties that get repriced every renewal.

Munich Re's own research has flagged the demand side of that equation too. Publicly reported ransomware attacks rose nearly 50% in 2025 and continued unabated into 2026. Agentic AI is expected to increase attack frequency more than severity in the near term, by allowing adversaries to plan and adapt multi-stage operations with minimal human input (Munich Re, March 2026). Rising attack frequency against falling premium is the pricing squeeze At-Bay's scanning infrastructure is meant to help Munich Re manage from the inside rather than the outside.

The Open Question

The open question the acquisition does not settle is whether Munich Re will publish the loss-ratio comparison that would resolve the selection-versus-treatment problem described above. That comparison would break out claims experience for insureds who engaged with At-Bay's Active Risk Monitoring alerts against those who did not, holding underwriting cohort constant.

Cyber actuaries at competing reinsurers and carriers evaluating whether to build, buy, or reinsure their way into an active-mitigation model now have a $575 million data point on what the market believes that capability is worth. Whether it is worth that much because it reduces genuine loss frequency, or because it selects better risks at the point of sale, is the analysis Munich Re just paid to have exclusive access to.

Further Reading