Global cyber insurance direct written premiums declined roughly 12% in 2023 and stabilized at lower levels through 2024 and early 2025, after peaking in 2022 Source. This is occurring during a period in which the number of reported data breaches in the United States continued to rise, with the Identity Theft Resource Center reporting a record number of data compromises in 2024 Source. The conventional narrative — more breaches equals more risk equals higher insurance prices — is false in the real market. Insurers are not stupid. They saw the breach data and they lowered the rates anyway.

The mechanics are straightforward if you ignore the security vendor marketing. Cyber insurance underwriting has matured dramatically since 2019. Early cyber policies were priced on guesswork — nobody had a long enough claims history to build actuarial models that distinguished between a well-managed enterprise environment and a catastrophe waiting to happen. Premiums spiked in 2020-2022 because the ransomware surge caught insurers flat-footed: claims frequency tripled, severity went up, and the entire sector realized it was underpricing a correlated risk. Premiums more than doubled between 2019 and 2022 Source.

The correction was swift and structural. Insurers tightened underwriting standards. They required multi-factor authentication, endpoint detection, and segregated backups as minimum conditions for coverage. They excluded acts of war and state-sponsored cyber operations from standard policies, following Lloyd's of London requirements that went into effect in early 2023 requiring all cyber insurance policies to include a clause excluding liability for losses arising from state-backed cyber attacks Source. They stopped writing policies with $10 million limits for enterprises that had not demonstrated basic cyber hygiene. The result: a loss ratio that improved from 72% in 2021 to roughly 44% in 2024 across the standalone cyber market Source. Premiums declined because the insured pool got better, and the pricing reflects the actual risk rather than a premium for uncertainty.

The implication for cybersecurity vendors is uncomfortable but real. The cyber insurance market is the only independent pricing mechanism for cyber risk in the economy. It aggregates claims data from thousands of organizations, across every industry, and prices the probability and severity of future claims. If that market is saying "the risk-adjusted cost of cyber incidents is declining," the security vendor narrative that every enterprise needs more products, more layers, and more spending to stay ahead of an ever-worsening threat environment is being contradicted by the only source that has its own money at stake.

This does not mean cybersecurity spending will decline in absolute terms. Compliance requirements — the SEC's cybersecurity disclosure rules, effective December 2023, require public companies to disclose material cybersecurity incidents within four business days Source — create a permanent demand floor that is independent of the insurance cycle. But it does mean that the urgency premium that drove budget growth in the 2019-2022 period is compressing. Security is becoming a utility, not a growth narrative. The vendors that win in that environment are the ones that can demonstrate measurable risk reduction — not the ones that tell the scariest story at the RSA Conference.

Ask a security vendor what's happening to cyber insurance premiums. Most of them won't know, because they don't track insurance markets — they track breach counts, which are going up, and they frame their marketing around them. Ask an insurer. They'll tell you the risk is getting more manageable, the underwriting is getting better, and the premiums are coming down because they're now pricing a known quantity rather than an unknown catastrophe.

The people with money on the line are usually right about the level of risk. The people selling you protection products rarely are.