Skip to main content

US Cyber Market Report 2025

Page 1

U.S. Cyber Market Report 2025


2025 White Paper

U.S. Cyber Market Report 2025 Following stagnating growth in 2023, the U.S. cyber insurance market continued to soften in 2024, resulting in a 7% decline in written premiums - the first drop on record. Ample capacity kept market conditions highly competitive despite a sharp rise in ransomware activity, including several incidents that affected thousands of customers at impacted organizations. As 2025 drew to a close, rates remain negative. At the same time, ransomware losses are on pace to set a new record high in 2025, and data breach and privacy class-action filings have surged dramatically. Early, necessary signs of stabilization are emerging, and as losses continue to develop, we need more corrective action in the market as respects rates, terms and conditions.


2025 White Paper

The U.S. Cyber Insurance Market Contracts for the First Time Softening conditions that began in 2023 deepened in 2024, leading to a 7% decline in direct written cyber premiums to $9.14 billion, according to NAIC-reported data. This marks the first contraction in the market since reporting began in 2015. Domestic insurers performed slightly better than alien surplus lines carriers, posting a modest -2% growth rate to $7.08 billion in premium, although this figure was somewhat inflated by previously unreported premium.

Figure 1: US Cyber Insurance Premium 2020-2024

$12,000

$9,686

$10,000

$9,843 $9,143

$2,421

$2,595

$7,265

$7,248

2022

2023

$2,061

$8,000

Millions

$6,543 $6,000

$1,716 $4,065

$4,000 $1,311

$7,083

$4,827

$2,000 $2,754 $0

2020

2021 Domestic Premium

2024

Alien Surplus Lines Premium

Source: NAIC Memorandum: Report on the Cybersecurity Insurance Market. National Association of Insurance Commissioners, October 15, 2025, https://content.naic.org/sites/default/files/cmte-h-cyber-wg-2024-cyber-ins-report.pdf. Accessed October 2025.


2025 White Paper The 2025 Fitch report1 on the U.S. cyber insurance market excludes approximately $280 million in premium from an entity that had previously operated as an MGA. Adjusted for this exclusion, the underlying results are weaker, reflecting -6% growth in domestic written premiums and -10% growth overall.

The NAIC updated its reporting structure for 2024, shifting from the previous stand-alone versus package classification to a new breakdown of primary, excess, and endorsement business. This change provides a clearer and more accurate picture of how cyber premiums are distributed. Primary cyber policies accounted for 65% of written premiums, with excess policies representing 31%, and endorsements making up the remaining 4%. However, the distribution looks very different when measured by policy count: endorsements comprised 55% of all policies, primary policies 42%, and excess policies only 3%, highlighting the large volume of lower-limit or add-on coverage relative to full standalone placements.

Figure 2: US Domestic Cyber Policy Count 2020-2024

5,000,000 4,5000,000

Number or Policies

4,000,000

Primary: 1.82M

3,500,000 3,000,000

Excess: 144K

2,500,000 2,000,000 1,500,000

Endorsement: 2.41M

1,000,000 5000,000 0

2020

2021

2022

2023

Reprinted: NAIC Memorandum: Report on the Cybersecurity Insurance Market. National Association of Insurance Commissioners, October 15, 2025, https://content.naic.org/sites/default/files/cmte-h-cyber-wg-2024-cyber-ins-report.pdf. Accessed November 30, 2025

¹ Source: Fitch Ratings. US Cyber Insurance Premium Shrinking to Continue. Fitch Ratings, Inc., April 15, 2025. https://www.fitchratings.com/research/insurance/us-cyber-insurance-premium-shrinking-to-continue-15-04-2025

2024


2025 White Paper

Despite cyber risk remaining a top concern for organizations, the number of customers purchasing coverage has not meaningfully changed in recent years, holding steady at 4.37 million in 2024. This stagnant buyer base means insurers are competing for the same pool of insureds fueling heightened competition and downward pressure on rates. With more than 200 insurers² now offering cyber products in the U.S., it is unsurprising that pricing continues to be under pressure. Although there are early indications that rates may be stabilizing, the direction is still uncertain. The Marsh reported rate has seen some improvement in 2025 after rates bottomed out at -6% in 2024, while CIAB data shows pricing continuing to edge slightly downward this year.

Figure 3: Cyber Market Rate Change 2020-2025 Q3

Marsh

CIAB

90%

79%

80%

66%

70% 60% 50% 40%

26%

30% 20%

18% 22%

10% 0%

4%

11%

-1%

-1%

-10%

-2% -3%

-6%

-20%

2020

2021

2022

2023

2024

2025 Q3

Figure 3: Marsh Global Insurance Market Index tracks price change in major P&C lines based on its own client portfolio while The Council of Insurance Agents & Brokers (CIAB) collects price information through a survey of its members. Source: Reprinted Marsh Global Insurance Market Index 2020 to 2025 Q3, Council of Insurance Agents and Brokers P/C Market Survey 2020 to 2025 Q3.

² Davis, Chris. 2025, November 25. US cyber market pricing pressure poses long-term risk. Insurance Business Magazine. https://www.insurancebusinessmag.com/us/news/cyber/us-cyber-market-pricing-pressure-poses-longterm-risk-556875.aspx#:~:text=There%20are%20now%20over%20200,competitors%20likel y%20show%20similar%20figures.


2025 White Paper

Shrinking Margins Given the updated NAIC reporting structure for the 2024-year it is harder to determine changes in profitability due to the difference in loss reporting requirements between stand-alone and package policies in previous years. Even so, the 2024 NAIC data points to a clear deterioration in market performance. The AM Best loss ratios are based on NAIC reported loss data which, in many cases, reflects paid loss and case reserves rather than ultimate loss estimates. Based on current market consensus, the combined ratio is trending toward 100% in 2024 and could move above that level in 2025. That is further supported by the 40% surge in reported cyber claims in 2024. While partly driven by several large-scale events affecting thousands of customers, the increase in claim volume far exceeds what those high-profile incidents alone would explain, especially considering that 2023 also saw multiple widespread events.

Figure 4: Domestic US Cyber Premium & Incurred Loss Ratio

8,000

$7,237 66.9

7,000

$7,244

65.5

80 $7,075 70 60

5,000 4,000

44.6

48.8 41.6

35.3

$2,011

50 40

$2,754

3,000 2,000

$4,829

44.6

30

$2,252

Loss & DCC Ratio

DPW ($ Millions)

6,000

20

1,000

10

0

0

2018

2019

2020

Total DPW

2021

2022

2023

2024

Cyber Insurance LR

Reprinted: Source: Graham, Christopher, et al. “US Cyber: Pricing Cuts Bring First Ever Reduction in Direct Premiums Written.” AM Best Market Segment Report, June 23, 2025, pp.2. Best Link


2025 White Paper With policy count remaining flat in 2024, the data points to a clear rise in claim frequency at a time when both rates and premiums have been declining. As outlined in our 2024 cyber report, the tail on cyber claims has grown longer due to a shift in costs from extortion payment to business income loss and a higher prevalence of litigation following cyber events. That’s further compounded by the wave of website tracking litigation and the rise in non-extortion data breach claims, adding additional pressure to loss performance. Claims involving litigation now exhibit a tail of roughly three to four years, with extreme cases extending to six to seven years, particularly for large excess portfolios. Beyond deteriorating loss ratios, market performance is also impacted by higher commission levels, escalating technology costs associated with the expansion of digital distribution, and necessary investment in cyber threat intelligence tools and resources. While aggregate loss ratios and claim volumes illustrate the growing pressure on the cyber insurance market, they do not fully explain what is driving today’s loss experience. Understanding these underlying loss drivers is essential to evaluating future risk trends and underwriting outcomes. The following section examines the primary mechanisms behind recent ransomware losses, beginning with the renewed role of SSL-VPN compromise.

Types of Cyber Losses SSL-VPN Compromise Leading to Fresh Ransomware Records Ransomware activity has risen steadily since 2022 based on data from leak sites. When annual leak-site volumes are combined with payment rates derived from our claim inventory and benchmarked against incident response firm data, the analysis points to a 60% increase in ransomware losses in 2023, followed by a more moderate 8% increase in 2024. Through the third quarter of 2025, the estimated volume of attacks was on pace for a 22% year-over-year increase, signaling another significant escalation in ransomware frequency. While leak-site data does not reflect every ransomware incident, it remains a reliable proxy for overall attack levels.

Figure 5: Estimated Global Ransomware Attacks 2021-2025 Q3 Attack Volume Based on Leak Site Victims & Payment Rate 5,976

4,450

7,136

49% 40%

Leak Site Victims Source: TOR site of ransomware group

$5,410

$5,322

37% 30%

$2,670

2022

7,096

$4,496

$3,048

2021

7,728

25%

2023

2024

Extortion Payment Rate

2025 Q3


2025 White Paper Figure 6: Global Distribution of Ransomware Attacks

Low (1-99) Medium (100-199) High (200+)

Source: https://www.ransomware.live/map

Part of the increase in ransomware activity is likely driven by the growing number of active ransomware groups. In the first half of 2025, 96 groups were operating, up from 68 active groups in the first half of 2024 - a substantial expansion in the threat landscape. Another contributing factor is the ease at which threat actors continue to gain or acquire access to victim networks. Weak credentials and lack of MFA (Multi Factor Authentication) on remote access continue to be the most prevalent ransomware initial access vector. Persistent SSLVPN Brute-Forcing and password spraying remains a leading initial access method of multiple access brokers, especially for the ones of lower sophistication. While trivial, the high likelihood that local and service accounts are not protected by MFA, increased sophistication of brute-forcing tools, and a general lack of password complexity and lockout policies, have resulted in perimeter security solutions meant to ward off unauthorized entry, becoming a convenient way into a victim network.


2025 White Paper A year-long campaign against SonicWall by Akira ransomware, is a good indication of this. Akira shifted focus from Cisco ASA to at-scale targeting of SonicWall devices starting in 2024. Released in August 2024, and addressed by SonicWall in SonicOS 7.3, CVE-2024-40766 is believed to be the root point of compromise. Despite SonicWall’s patches providing additional protections against brute-forcing, password spraying and “MFA attacks”, the campaign continues well into 2025, also affecting patched devices.

Lack of password reset for local accounts after patching, and possible

misconfigurations that expose non-VPN users to brute-forcing, continue to contribute to the success of Akira’s attacks against SonicWall users.

In Q1, 2025, the majority of overall initial access was due to valid accounts lacking MFA (Multi Factor Authentication)

56%

Valid Account/No MFA

Vulnerability Exploitation

13%

13%

6%

6%

6%

Exposed RDP Service

SEO Poisoning

Brute Force

Exposed RMM Tooling

Source: Boyd, Chris, "Rapid7 Q1 2025 Incident Response Findings", Rapid7, June 4 2025, www.rapid7.com/blog/post/2025/06/04/rapid7-q1-2025-incident-response-findings/


2025 White Paper

Software vulnerability exploitation also continues to be prevalent. For example, CVE-2024-57727, affecting SimpleHelp, a popular RMM (Remote Monitoring and Management) tool, was widely targeted in the first half of 2025, with groups like DragonForce, Play and Medusa benefiting from successful exploitation. This follows wide exploitation of another popular RMM tool in 2024, ConnectWise ScreenConnect, as multiple groups, including BlackBasta and LockBit successfully targeted ScreenConnect instances vulnerable to CVE-2024-1708 and CVE-2024-1709.

Fortinet’s

CVE-2024-55591, affecting FortiOS and FortiProxy, and CVE-2025-25257 affecting FortiWeb has also been widely exploited by multiple groups. In recent months, Cl0p has been identified as exploiting a 0day affecting Oracle E-Business Suite, CVE-2025-61882, which resulted in dozens of companies worldwide being extorted.

Besides software vulnerabilities, ransomware threat

While at-scale, non-targeted exploitation of vulnerable

actors including several nation-state sponsored APTs

devices and unprotected SSLVPN login panels was

from Russia, North Korea and Iran, have turned to

rampant in 2024 and 2025, news coverage does not

malware delivery via a novel method. Dubbed

often reflect this. Especially in a year where highly

“ClickFix” by researchers, the attacker tricks the user

targeted and costly ransomware attacks affected some

into solving a CAPTCHA that results in the user copying

of the most recognizable brands in the UK. These

and pasting commands into Windows PowerShell or

compromises are often characterized by a heavy social

terminal, effectively installing malware on their machine

engineering component. M&S (Marks & Spencer), the

by social engineering the victim. The technique was first

British

observed in 2024, with researchers seeing different

DragonForce ransomware as a result of the Scattered

malware being delivered via this method, including

Spider group successfully social engineering their 3rd

Lumma Stealer. InfoStealer malware continues to be a

party helpdesk. Given its primary members are

favored method to acquire critical credentials to

believed to be native English speakers, the group has

corporate resources. Often trojanized in freeware

been

downloads and facilitated by SEO (Search Engine

credentials via phishing and leveraging their native

Optimization) poisoning, millions of new machines

English-speaking skills to impersonate employees and

continue to be infected every year. The risk obviously

convince help desk to reset MFA.

extends to 3rd parties and outsourced partners that might be accessing corporate resources and application from non-managed machines infected with infostealer malware.

multinational,

successful

in

was

compromised

gathering

employee

by

valid


2025 White Paper They used similar TTPs (Tactics, Techniques and

Overall, specific security controls continue to be very

Procedures)

group

efficient against ransomware operations. For example,

successfully compromised two large casinos in the US.

while the frequency of ransomware attacks continues

In late August, JLR (Jaguar Land Rover), the UK’s

to increase, ransom payments are in decline, with only

largest car manufacturer, with an estimated annual

23% of victims paying ransom in Q3 2025, compared

revenue of $38B, was successfully targeted by

to 28% in Q1. This is largely due to continued increased

“Scattered Lapsus$ Hunters”, a group believed to be

adoption of cloud and offsite backups, lowering the

affiliated with Scattered Spider. The successful attack

effectiveness of data encryption. Basic security

resulted in weeks of interrupted operations, and it is

controls continue to be effective measures in

now estimated to be UK’s costliest cyberattack in

minimizing the risk of a successful ransomware attack

history, with a potential damage amounting to close to

and its overall severity, especially for SMBs (Small to

$2.4 billion. In 2025, we also witnessed criminals

Medium Businesses). Establishing a good patching

sending physical letters in the mail directly to

cadence for perimeter devices, restricting BYOD

executives’ residences, in an attempt to convince them

(Bring-Your-Own-Device) policies, enforcing MFA on all

to remit a payment without involving IT and security

account types, avoiding clientless SSLVPN, and having

departments. Although not a highly discussed, or

a clear incident response strategy remain vital.

in

2023,

when

the

same

successful approach, these events bring attention to the overall scope of extortion techniques.

Surge in Data Breach and Privacy Class Actions While ransomware remains the primary driver of cyber insurance losses, data breach and privacy class actions are increasingly contributing to higher claim severity - both in connection with ransomware events and in unrelated cyber incidents. Beyond the class actions that frequently follow ransomware attacks on consumer-facing organizations, there has been a major uptick in litigation stemming from data breaches and unauthorized data sharing with third parties. Part of the rise in data breach class actions stems from the continued growth in ransomware attacks involving data exfiltration. But several additional factors are also contributing to the surge. Expanding notification requirements including the SEC’s new disclosure rule - have increased legal exposure for organizations. Once an organization begins notifying individuals and regulators about a breach, class-action firms quickly evaluate the potential for litigation and settlement.


2025 White Paper

At the same time, more personal injury firms are moving into data breach litigation as a lucrative practice area, leading to heightened attention on smaller incidents. Whereas data breach class actions historically targeted large events affecting 100,000 or more individuals, today’s filings increasingly focus on breaches involving as few as 1,000 to 5,000 affected individuals. As a result, class-action activity has accelerated sharply: filings climbed from 300 in 2021 to 1,500 in 2024, and 2025 is on track to far surpass that total, with 1,700 filings in just the first six months of the year. Source: ThreatLocker. “Why Data Breach Class Actions Are Surging and How Cisos Can Respond.” LinkedIn, 9 Sept. 2025, www.linkedin.com/pulse/why-data-breach-class-actions-surging-how-cisos-can-respond-mwcee.

Outside of data breaches, the wave of website tracking litigation that began in 2022 has continued at a rapid pace. More than three years later, total filings now exceed 3,000, growing at a rate of roughly 100 lawsuits per month. California remains the dominant venue, accounting for 85% of all cases, with most of the remainder concentrated in a small group of other states. Approximately two-thirds of these lawsuits allege violations of state privacy laws, while the rest cite federal statutes such as the Video Privacy Protection Act and the Federal Wiretap Act.

Figure 7: Distribution of Website Tracking Lawsuits 2022-2025 Total Cases

3,153

*from 02/05/22 - 12/08/25

Most Cases California Illinois New York

More Cases

Cases by Court Type 872 2,281 State

Federal

Fewer Cases

Source: “Digital Wiretapping Litigation Map.” Fisher Phillips, www.fisherphillips.com/en/services/trending/us-privacy-hub/wiretapping-litigation-map.html. Accessed Nov. 2025


2025 White Paper Although publicly disclosed settlements have so far largely involved healthcare and media companies, the retail sector is the most affected, representing 36% of all filings. As expected, plaintiff firms initially targeted the largest organizations, many of which have since reached or are nearing settlement. A review of 50 publicly disclosed settlements shows an average payout of more than $6 million. While data breaches have occurred for decades and are difficult to prevent entirely, website tracking litigation presents a different kind of challenge. More than three years after the surge of lawsuits began in 2022, initially focused on healthcare providers, a large proportion of organizations still use technologies that track consumer activity on their websites. In many cases, organizations are simply unaware that these tools are embedded on their sites; in others, they lack a clear understanding of the compliance requirements that apply when such tracking technologies are used. As a result, there remains an abundant pool of potential defendants for plaintiff firms to target, even though this type of litigation is largely avoidable.

Spotlight on the Healthcare Sector Although the distribution of cyber losses has shifted across industries since the ransomware surge began in 2019, healthcare has remained one of the most consistently targeted sectors, by both threat actors and plaintiff law firms. Ransomware frequency in healthcare has jumped 90% in 2025, and claim severity nearly doubled between 2022 and 2024. Double extortion, where attackers not only encrypt systems but also steal and threaten to release patient data, has become the norm. These attacks trigger almost every major coverage component of a cyber policy, including breach response, liability, business interruption, data restoration, and extortion payments. As a result, ransomware events involving healthcare organizations now cost two to three times more than comparable attacks on non-healthcare entities. Healthcare networks are uniquely complex and deeply interconnected. Legacy systems, vendor-managed medical devices, and constrained cybersecurity resources dramatically expand the attack surface, making healthcare one of the most difficult sectors to secure. Moreover, when hospital systems go down, the impact extends far beyond operational disruption. Patient care is delayed, safety is jeopardized, and the financial and human consequences become inseparable.


2025 White Paper The healthcare sector has long been among the top industries targeted by ransomware groups, but the risks it faces extend well beyond direct attacks. The February 2024 Change Healthcare incident disrupted 94% of U.S. hospitals and affected nearly half of the U.S. population, demonstrating how a single point of failure can have nationwide impact. Change Healthcare is not the only vendor capable of creating such systemic disruption. Electronic Health Record (EHR) platforms represent another critical dependency among U.S. hospitals, and the market is dominated by two large providers making an attack on one of them potentially much more consequential than the Change Healthcare event. Even though healthcare is clearly a highly targeted sector, many still underestimate the complexity of its cyber and privacy exposure. Healthcare risks cannot be priced or managed in the same way as retail, manufacturing, or construction. The sector demands deep specialization, disciplined underwriting, and robust risk-management controls.

2026 Outlook: Rising Losses and the Path Toward Hardening The U.S. cyber insurance market is nearing a pivotal point. After the first recorded contraction in premium volume and continued rate softening through 2025, the pressures reshaping the market are accelerating. Competition remains intense, the buyer base stagnant, and losses are climbing sharply driven by record ransomware activity, a rapid escalation in class-action litigation, and increasingly complex, multi-layered claims. At the same time, threat actors are expanding their capabilities, exploiting both basic security gaps and critical software vulnerabilities at unprecedented scale. As we look back at the final weeks of 2025, one of the more striking developments has been the absence of any major widespread outage or systemic cyber event, despite two recent close calls tied to internet infrastructure failures. Yet much like this year’s anomalously quiet hurricane season, no one is confusing this lull with a new normal. The underlying systemic risks remain fully intact, and the conditions capable of driving large-scale disruption continue to loom in the background. Whether 2026 marks the beginning of a hardening cycle will hinge on how effectively insurers respond - tightening underwriting discipline, sharpening accumulation management, and investing in the specialized expertise needed to assess and price fast-evolving cyber exposures. What is clear, however, is that the US cyber insurance market has moved beyond its early phase of rapid expansion. It is entering a more mature and volatile stage - one that will demand greater agility, analytical rigor, and a deeper understanding of the systemic forces that will shape cyber risk in the years ahead.


tmhcc.com/cyber

Cyber... With Confidence. Tokio Marine HCC has been innovating in Cyber Liability Insurance worldwide, for over 20 years. Our dedicated global team is made up of cyber insurance and in-house claims experts with deep industry knowledge and a wealth of cyber security experience. We promote active knowledge exchange, making us a global leader when it comes to cyber risk, while keeping you at the forefront of emerging threats on the ever-evolving Cyber landscape. From offices in the U.S., our cyber team insures US-domiciled businesses, with a focus on the small- to mid-sized segment, as well as individuals concerned with protecting their family, home and privacy from cyber threats. From Europe and the U.K., our team concentrates on mid- to large-sized businesses domiciled anywhere outside of the U.S. In addition, we leverage our in-house Cyber expertise to enhance other Tokio Marine HCC insurance coverages, letting you take on risk with confidence. Follow us on LinkedIn: #TMHCC_Cyber Tokio Marine HCC is the marketing name used to describe the affiliated companies under the common ownership of HCC Insurance Holdings, Inc., a Delaware-incorporated insurance holding company. Headquartered in Houston, Texas, Tokio Marine HCC is a leading specialty insurance group with offices in the United States, the United Kingdom and Continental Europe. This is copyrighted material unless otherwise indicated in this Cyber U.S. Market Report 2025.

Tokio Marine HCC | NAS Insurance Services, LLC, CA License #0677191


Turn static files into dynamic content formats.

Create a flipbook
US Cyber Market Report 2025 by Tokio Marine HCC - Issuu