Fewer claims, bigger bills: what your insurer just learned
If your security insurance is up for renewal this year, expect a harder conversation than last time. Not because attacks are more common, they may well be less so for a business like yours, but because the ones that succeed now cost the insurer considerably more to settle. That shift is showing up in the claims data, and it changes what underwriters ask you before they quote.
What the numbers say
Chubb published its 2026 Cyber Claims Report on 25 August. Infosecurity Magazine's write-up sets out the pattern: across both the United States and Europe, the number of claims fell while the average cost of each one climbed.
In the UK and Europe, the average claim from a mid-market company rose 34% in 2025 compared with 2024. For large companies it rose 98%, close to double in a single year.
The figure that matters most to a smaller business is different, and less comfortable. For SMEs, claim frequency went up in both regions. So did the cost in the UK and Europe, where the average SME claim rose from about $51,000 to roughly $83,000. In the United States the equivalent figure fell. Whatever is driving the improvement for American small businesses is not reaching this side of the Atlantic.
Two caveats worth holding. Chubb is one insurer describing its own book, not the whole market, and the figures are in dollars because that is how the report presents them. The direction of travel is the useful part, not the decimal places.
Why the bills are growing
Chubb points at two things, and both are worth understanding because neither is really about hacking.
The first is litigation and regulatory cost. When personal data leaks, the expensive part is increasingly what happens afterwards: the legal claims, the regulatory engagement, the notification exercise. Chubb notes that the gap between American and European claim costs is largely explained by third-party litigation, which barely features here. That is a real advantage for UK businesses, and it is not guaranteed to last.
The second is a change in how attackers behave. Groups that once simply encrypted your systems and asked for payment now steal the data first and threaten to publish it. That converts what used to be an IT outage into a data protection incident, with everything that follows. You can restore from backups and still have the harder problem.
Put those together and you get the shape in the data: fewer incidents reaching the insurer, but the ones that do arrive carrying a longer tail of cost.
What this means at renewal
Insurers respond to rising severity in three ways, and you will meet all of them.
The questions get sharper. Proposal forms move from "do you have backups" to "are they tested, offline, and how quickly did the last restore actually take". Answer these carefully. An inaccurate answer on a proposal form is the most reliable way to have a claim reduced or refused, which we covered in your insurance questionnaire is the policy.
Controls become conditions. Increasingly, specific measures are not just questions but requirements written into the policy. Multi-factor authentication on remote access and email is the common one. If you agreed to it at renewal and it is not switched on everywhere, that is a gap between what you are insured for and what you have.
Price and excess move. Expect the excess to rise even where the premium holds steady, which quietly shifts more of a smaller incident onto you.
What to do before you renew
Three things, none of which needs a consultant.
Read last year's proposal form before you answer this year's. Check that every answer you gave is still true. Staff changed, a system was replaced, a supplier took over something: any of those can quietly turn a true answer false.
Test one restore, and write down how long it took. Not "do we have backups", but "we restored this system on this date and it took four hours". That sentence answers an underwriting question, and it tells you something you genuinely need to know.
Ask your insurer or broker what the policy expects of you. The conditions are often more specific than people realise, and they are much easier to meet before an incident than to explain afterwards.
The underlying message in the claims data is not that everything is getting worse. Fewer claims suggests the basics are working. It is that the cost of the incidents that do get through is rising faster than most small businesses have adjusted for, and insurers have noticed before their customers have.
How Steelwise can help
Working out whether the answers on your proposal form are still true, and whether the controls your policy assumes are actually in place, is a short piece of work that is far cheaper than a reduced claim. Get in touch.
Further reading
- NCSC: Cyber insurance guidance for organisations
- NCSC: Offline backups in an online world
- ICO: Personal data breaches