, APAC
180 views
/Pressmaster from Envato

Can cyber insurers stay profitable?

Rising cyber risks are testing the market's pricing strategy.

Cyber insurers are expected to remain profitable despite falling premiums and rising cyber threats, but analysts said the market's outlook depends on whether insurers resist further price cuts.

“Our stable outlook on the segment reflects solid demand for coverage, even as the market pricing softens, in addition to favorable profitability over the intermediate terms and the growing use of artificial intelligence (AI),” Cristian Sieira, a senior financial analyst at A.M. Best Company, Inc. said in a July report.

The credit rating company said demand continues to grow as businesses digitise operations, comply with stricter data protection rules, and become more aware of cyber risks.

It estimated global cyber insurance premiums exceeded $16b in 2025, although growth slowed as competition and ample underwriting capacity pushed prices lower.

S&P Global Ratings said the market is approaching an "inflection point," warning that continued rate declines could eventually erode underwriting profits if they fail to keep pace with rising claims.

“The decline in cyber insurance rates is beginning to slow, with early signs of improving pricing discipline that may help stabilise underwriting profitability and preserve the current reinsurance-led market structure,” Manuel Adam, an analyst at S&P Global Ratings, said in a July report.

“However, adverse cyber loss trends and persistent competitive pressure could challenge pricing adequacy and increase the risk of market underpricing,” he added.

Both reports identified stronger competition as the key reason premiums have declined.

AM Best said the market has favoured buyers since 2023 as insurers competed more aggressively, but underwriting remained profitable despite modestly higher claim costs.

S&P said insurers must raise premiums to keep pace with claims costs or risk underwriting losses.

AM Best said ransomware, business email compromise, and fund transfer fraud remain the main drivers of cyber insurance claims.

It added that AI is making cyberattacks more sophisticated and easier to scale. The debt watcher estimated ransomware attacks increased 30% in 2025 to 7,419 incidents worldwide.

Questions to ponder:

  • Can insurers maintain pricing discipline as competition for cyber insurance intensifies?
  • How should insurers price cyber risks as AI makes attacks more frequent and sophisticated?
     

Follow the link s for more news on

EXPERT OPINION

Cyber and Technology Risk Specialist, WTW

The market remains profitable for cyber carriers at present, so the key issue is whether emerging issues, such as changes to the cyber threat landscape or market dynamics, would create significant adverse conditions for insurers and accrued losses that would push some carriers, or cause wider corrections;

The points mentioned around the impacts of new AI systems is one of the most important issues, as it could significantly affect the cyber threat landscape (the threat landscape is all of the different ways that malicious threat actors could cause harm to organisations). Some important learnings can be drawn from recent AI incidents, and particularly the Hugging Face breach a few weeks ago, which shows:
 

  • Actions taken by agentic AI systems occur much faster when compared to traditional cyber attackers, who are typically limited to human inputs and human-in-the-loop processes. In the Hugging Face breach, the AI was able to execute tens of thousands of actions and brute-force itself across the network as speed. If you extrapolate this out, it means a threat actor could cause a catastrophic loss to a victim business in a much shorter period of time, and also that it will be more difficult for defenders to keep up with the speed of the threat actor. This would result in cyber events causing significantly greater losses when compared to historical trends and would put greater pressure on insurers;
     
  • There could be delay or asymmetry between the AI tools that cyber threat actors can use and the AI tools available to defenders. For example, following the Hugging Face incident, their security team were trying to analyse the attack and review logs to ensure they contained and removed the threat. They initially tried to use frontier models; however, they were locked out of these models due to those models ‘safety guardrails’. As a result, they sustained further delays in their investigations, and had to use a less powerful on-premises open-weight model (GLM 5.2). This again suggests that if AI driven cyber events happen more frequently or at scale, it will be difficult for companies to contain the incidents and limit the loss;
     
  • AI systems and AI platforms are going to create new attack surfaces, and likely lead to new types of cyber incidents that we haven’t previously seen. In the case of the Hugging Face incident, their AI platform’s data-processing pipeline was compromised. This is one of the areas where AI platforms are highly exposed because they can allow command execution and have to routinely accept user-supplied inputs, data, model files and configurations. Because these are new pathways for exposures, it’s likely they won’t be captured in traditional cyber incident loss data, and may instead reflect new loss types that insurers aren’t properly able to reserve for.
     

 
In terms of the other points mentioned:
 

  • Pricing – one of the issues being discussed across the industry is whether insurers are adequately reserving for the risk of future significant widespread events, particularly major outage events (think the 2024 Crowdstrike event). If we were to see a number of widespread loss events in the coming 12 months, it’s likely that current insurer pricing approaches wouldn’t be sustainable;
     
  • Competition – strong carrier competition is likely to stay for at least the next couple of years, given cyber remains one of the few specialty lines that is consistently showing growth and still has a relatively low purchase percentage when compared to the total potential population. This makes it very attractive as a line of business and a key growth strategy area for many carriers;
     
  • Discipline – because the market remains soft, many carriers are not applying the same degree of risk-underwriting rigour and control discipline that they would have applied in previous harder market conditions. This is another challenging area, as risk selection is difficult for carriers to justify in a soft market, so poorer risks that have high risk of attack are increasingly being covered. This also makes it harder for insurers to enforce controls and good cyber resilience across their portfolios.
10 days ago
Join Insurance Asia community
Since you're here...

...there are many ways you can work with us to advertise your company and connect to your customers. Our team can help you design and create an advertising campaign, in print and digital, on this website and in print magazine.

We can also organize a real life or digital event for you and find thought leader speakers as well as industry leaders, who could be your potential partners, to join the event. We also run some awards programmes which give you an opportunity to be recognized for your achievements during the year and you can join this as a participant or a sponsor.

Let us help you drive your business forward with a good partnership!