Cyber Insurance Claims Are Becoming More Expensive — Even as Attacks Become Less Frequent

Listen to this Post

Featured Image

Introduction: The Cybersecurity Equation Is Changing

Cybersecurity has entered a new and uncomfortable phase. For years, businesses were largely focused on one question: How often will we be attacked? Today, another question is becoming just as important: How expensive will the consequences be when an attack succeeds?

That distinction is at the heart of Chubb’s 2026 Cyber Claims Report, which analyzes cyber insurance claims through the end of 2025. The report reveals a striking contradiction: claim frequency declined for many middle-market and large organizations, yet the average financial impact of individual claims increased dramatically. In the United States, the severity of claims for large companies roughly doubled in 2025, while middle-market organizations also experienced a substantial increase. Europe and the UK followed a similar pattern, with fewer claims but significantly more expensive incidents.

The message is difficult to ignore. Cybersecurity defenses may be helping companies prevent or contain some attacks, but the incidents that get through can now create far more complicated financial, legal, regulatory, and operational consequences.

The Biggest Finding: Fewer Claims, Bigger Losses

Chubb’s report shows that cyber risk cannot be measured simply by counting incidents. Claim frequency and claim severity are moving in different directions, creating a risk environment that can look healthier on the surface while becoming more dangerous underneath.

In the United States, the average cost of cyber insurance claims increased by approximately 22% for middle-market businesses in 2025 compared with 2024. For large companies, the increase was dramatically larger, reaching roughly 100%. Chubb’s broader analysis puts average severity for large U.S. accounts at approximately $4.4 million in 2025, compared with around $2.2 million in 2024.

This is one of the most important cybersecurity trends for executives to understand. A declining number of incidents does not necessarily mean cyber risk is declining. If criminals are becoming more selective, more efficient, or more capable of maximizing damage, fewer successful attacks can still generate greater total losses.

The United Kingdom and Europe Are Seeing the Same Pattern

The same structural shift appeared across the UK and Europe, although the financial environment differs from that of the United States.

Chubb reported that cyber claim frequency among middle-market businesses in the region reached a five-year low in 2025, while the average cost of a claim increased substantially. The insurer says middle-market claim severity rose by about 210% over the five-year period from 2020 to 2025, reaching an average of $318,820 per claim.

Large European and UK businesses also experienced a dramatic increase in claim severity. Chubb reported that average claim costs for large companies rose by approximately 100% between 2024 and 2025, while claim frequency fell significantly.

The result is a cyber insurance market where frequency is no longer the only warning signal. Severity is becoming the story.

Why U.S. Claims Can Be So Much More Expensive

One major difference between the United States and Europe is litigation.

Chubb explains that U.S. cyber claims can generate significant third-party litigation expenses associated with data breaches and privacy-related claims. Those expenses can substantially increase the overall cost of an incident.

The situation is different in the UK and Europe, where Chubb noted that its claims data did not show material third-party litigation expenses from data breach or non-data-breach privacy claims comparable to those observed in the United States.

That does not mean European companies are protected from expensive cyber incidents. Instead, it demonstrates that the financial consequences of the same type of security failure can vary enormously depending on jurisdiction, regulatory obligations, litigation structures, and the number of affected individuals.

Privacy Regulation Is Becoming a Cybersecurity Cost Multiplier

The modern cyber incident rarely ends when the attacker leaves the network.

A stolen database can trigger regulatory investigations. It can lead to notifications, forensic analysis, legal reviews, customer communications, credit-monitoring expenses, business disruption, and potentially lawsuits.

Chubb highlights the growing complexity of privacy regulations in both the United States and Europe. Companies increasingly face layered obligations concerning how personal information is collected, stored, transferred, analyzed, and deleted. Regulations can also impose requirements concerning profiling, automated decision-making, and disclosures surrounding AI-driven processing.

This creates a new reality for security teams: protecting data is no longer purely an IT responsibility.

AI Is Adding Another Layer of Complexity

Artificial intelligence is becoming an important part of the cyber risk equation.

On one side, AI can help organizations identify vulnerabilities, detect suspicious activity, analyze enormous quantities of security data, and respond more rapidly to threats.

On the other side, attackers are using increasingly sophisticated technology to accelerate reconnaissance, automate parts of their operations, generate convincing social-engineering material, and scale attacks.

Chubb specifically identifies AI-driven threats as one of the forces reshaping the cyber claims landscape. The insurer describes AI as contributing to a risk environment where attacks can develop more quickly and potentially affect a broader range of systems and organizations.

The irony is striking: the same technology being deployed to improve defense is also helping attackers improve offense.

Ransomware Is No Longer Just About Encryption

Ransomware has also evolved beyond the traditional model of encrypting files and demanding payment for a decryption key.

Modern ransomware operations frequently involve data theft before encryption. Attackers can threaten to publish sensitive information, contact customers, expose confidential business documents, or use the stolen data as leverage.

Chubb warns that the intentional leakage of stolen information alongside encryption increases the potential for litigation and regulatory consequences under data protection laws.

This makes ransomware particularly dangerous because a single incident can simultaneously become an availability problem, a confidentiality problem, a privacy problem, a legal problem, and a business continuity problem.

The Hidden Cost of Business Interruption

Another major factor behind rising claim severity is business interruption.

When critical systems go offline, companies can lose revenue while continuing to pay employees, suppliers, infrastructure providers, and other operating expenses.

For large enterprises, even a relatively short outage can create enormous losses.

Chubb identifies increasing business interruption expenses as one of the key contributors to rising cyber claim severity in the United States.

The implication is straightforward: resilience is becoming as important as prevention.

A company that cannot prevent every attack can still reduce the financial consequences by maintaining tested backups, redundant systems, segmented networks, recovery procedures, and clear incident-response processes.

SMEs Face a Different Kind of Cyber Risk

Small and medium-sized businesses do not necessarily follow the same pattern as large enterprises.

In the United States, Chubb reported that the average claim cost for SMEs declined from approximately $215,297 in 2024 to $141,931 in 2025.

In the UK and Europe, however, SME claim severity moved in the opposite direction, increasing from approximately $51,095 to $82,621. Chubb also reported an 86% increase in SME claim frequency across the UK and Europe between 2024 and 2025.

That contrast demonstrates why organizations should avoid treating “cyber risk” as a single universal category.

A multinational corporation with thousands of employees, extensive legal exposure, and multiple business-critical platforms faces a very different financial threat from a 100-person company dependent on a handful of cloud services.

Supply Chains Are Becoming a Major Weakness

For smaller organizations in particular, third-party dependency can create significant exposure.

A business may have excellent endpoint protection and still be affected by a compromised software provider, managed service provider, cloud platform, payment processor, or other external partner.

Chubb specifically identifies supply-chain dependency as an important area of exposure for SMEs.

The lesson is uncomfortable but important: your

Cyber Insurance Is Becoming More Strategic

Cyber insurance was once sometimes treated as a financial safety net that would help a company recover after an incident.

That approach is becoming outdated.

Insurers now have strong incentives to understand how organizations manage vulnerabilities, identity, backups, endpoint security, incident response, supply-chain exposure, and employee awareness.

As claims become more expensive, underwriting becomes more sophisticated. Businesses may increasingly need to demonstrate that they have meaningful security controls rather than simply purchasing a policy and assuming the financial risk has been transferred.

Insurance can reduce financial exposure, but it cannot eliminate operational damage.

Privacy Litigation Could Become an Even Bigger Threat

The most striking part of the report may not actually be ransomware or AI.

It could be litigation.

Chubb points to the substantial administrative costs associated with certain U.S. privacy filings. In the example highlighted by the insurer, a case involving 10,000 claimants could generate more than $10 million in non-refundable filing fees before the underlying merits of the case are even considered.

That example illustrates why the economic consequences of a data breach can escalate so quickly.

A stolen database containing millions of records is not simply an information-security incident. It can become a legal and financial event affecting the company’s balance sheet for years.

The New Cybersecurity Metric: Cost Per Incident

For years, organizations frequently measured cybersecurity performance using metrics such as the number of detected attacks, malware infections, phishing attempts, or blocked intrusion attempts.

Those numbers remain useful, but they do not tell the whole story.

Companies should increasingly monitor the potential financial impact of a successful incident.

How quickly can critical services be restored?

How many systems can be isolated?

How much customer data could be exposed?

How quickly can the company determine what happened?

How much revenue could be lost during a prolonged outage?

How much would regulatory response cost?

How much could litigation cost?

These questions turn cybersecurity from a purely technical discipline into an enterprise-risk discipline.

Deep Analysis

Why Severity Can Rise While Frequency Falls

The Chubb data suggests that cybercriminal activity may be becoming more selective and economically optimized.

If attackers can identify high-value targets more accurately, they do not necessarily need to compromise as many organizations to generate the same financial return.

At the same time, defenders are improving detection and response capabilities, potentially preventing lower-level incidents from becoming insurance claims.

The remaining claims can therefore become disproportionately severe.

The Attack Chain Is Becoming More Automated

AI-assisted tooling could further accelerate the process.

An attacker may use automation to discover exposed services, identify vulnerable infrastructure, generate convincing phishing material, analyze stolen information, and prioritize valuable targets.

The defensive response therefore needs to be automated as well.

Security teams should consider using endpoint detection, centralized logging, identity monitoring, automated alerting, vulnerability management, and tested incident-response playbooks.

Basic Linux Investigation Commands

For Linux systems, administrators can quickly inspect suspicious processes, network connections, authentication activity, and recent system events with commands such as:

ps aux --sort=-%cpu | head -20

This can help identify processes consuming unusually high CPU resources.

ss -tulpn

This displays listening network services and can help administrators identify unexpected ports or processes.

last -a

This provides a historical view of successful login sessions.

sudo journalctl --since "24 hours ago"

This can be useful when reviewing recent system activity and security events.

sudo find /var/log -type f -mtime -1 -ls

This helps identify recently modified log files that may deserve investigation.

Windows Incident-Response Commands

Windows administrators can similarly begin investigations using built-in tools.

Get-Process | Sort-Object CPU -Descending | Select-Object -First 20

This can highlight processes consuming significant CPU resources.

Get-NetTCPConnection | Sort-Object State,RemoteAddress

This provides visibility into active TCP connections.

Get-WinEvent -LogName Security -MaxEvents 100

This retrieves recent Windows Security event records.

Get-LocalUser

This helps administrators review local accounts that may require investigation.

Get-ScheduledTask | Where-Object {$_.State -eq "Ready"}

This can help security teams review scheduled tasks for unexpected persistence mechanisms.

These commands are not a substitute for a full investigation, but they provide useful first-response visibility when suspicious activity is detected.

Logging Is Becoming an Insurance Asset

One of the most overlooked cybersecurity controls is comprehensive logging.

Without logs, organizations may struggle to determine when an attacker entered the environment, what systems were accessed, what information was stolen, and whether the threat has actually been removed.

That uncertainty can increase both recovery time and legal complexity.

Organizations should therefore treat logs as evidence, not merely operational telemetry.

Backups Must Be Tested, Not Merely Purchased

A backup that has never been restored is an assumption.

A tested backup is a recovery capability.

Organizations should maintain multiple backup copies, protect critical backups against unauthorized modification, separate backup infrastructure from production environments where practical, and regularly perform restoration exercises.

For ransomware scenarios, immutable or otherwise strongly protected backups can become one of the most valuable assets a company owns.

Identity Has Become a Primary Security Boundary

Attackers do not always need to exploit a sophisticated software vulnerability.

Sometimes they simply need a valid account.

Strong authentication, phishing-resistant MFA, privileged-access management, conditional access, least privilege, and continuous monitoring can significantly reduce the value of stolen credentials.

This is especially important as businesses increasingly connect cloud applications, AI services, SaaS platforms, APIs, and third-party systems.

Vulnerability Management Must Become Faster

A vulnerability is not automatically a breach.

But an exposed vulnerability combined with poor asset visibility, weak authentication, and delayed patching can create a dangerous chain.

Organizations should continuously identify internet-facing systems, prioritize vulnerabilities based on actual exposure and exploitability, and establish clear remediation deadlines for critical assets.

The goal should not be to patch everything at once.

The goal should be to make sure the vulnerabilities most likely to cause catastrophic damage are addressed first.

Incident Response Should Be Practiced Before the Crisis

When an attack happens, nobody should be deciding for the first time who is responsible for shutting down systems, contacting legal counsel, notifying executives, communicating with customers, preserving evidence, or coordinating with an insurer.

Those decisions should already exist in an incident-response plan.

Tabletop exercises can reveal weaknesses before criminals do.

A plan that looks excellent on paper can fail immediately if employees do not know how to execute it.

Cybersecurity and Legal Teams Need to Work Together

The Chubb findings reinforce the idea that cybersecurity cannot remain isolated inside the IT department.

Security teams understand systems.

Legal teams understand regulatory exposure.

Privacy teams understand data obligations.

Executives understand business priorities.

Insurance specialists understand financial risk.

The most resilient organizations connect these functions before an incident occurs.

The Data-Breach Cost Equation Is Getting More Complicated

A useful way to think about cyber losses is:

Total Cyber Loss =

Incident Response

+ Business Interruption

+ Recovery Costs

+ Legal Expenses

+ Regulatory Costs

+ Customer Notification

+ Litigation

+ Reputation Damage

+ Long-Term Remediation

The formula is not an insurance calculation, but it illustrates why the original intrusion is often only the beginning.

The attacker may spend relatively little money to compromise an organization.

The victim may spend millions recovering from the consequences.

Why Large Companies Are Especially Vulnerable

Large enterprises have enormous digital footprints.

They operate thousands of endpoints, numerous cloud environments, complex identity systems, legacy applications, external vendors, remote employees, APIs, databases, and interconnected subsidiaries.

Every additional connection can create another potential route into the organization.

Scale brings efficiency, but it also creates complexity.

That is one reason a successful incident at a large company can rapidly become a multimillion-dollar event.

Why Cyber Insurance Alone Is Not Enough

Cyber insurance can provide valuable financial protection, but it cannot restore customer trust overnight.

It cannot immediately rebuild damaged systems.

It cannot undo a public disclosure.

It cannot erase stolen information from the internet.

It cannot eliminate regulatory scrutiny.

Insurance should therefore be treated as one component of resilience rather than the foundation of resilience.

What Undercode Say:

  1. Cyber Risk Is Becoming More Expensive, Not Necessarily More Frequent

The most important lesson from

  1. Lower Claim Counts Can Create False Confidence

Organizations should not assume fewer claims automatically mean attackers are becoming less successful.

3. Attackers Are Becoming More Economically Efficient

Cybercriminals increasingly have tools that allow them to identify valuable targets and automate parts of the attack lifecycle.

4. Large Enterprises Carry Disproportionate Financial Exposure

A major company can lose millions from a single event because every minute of downtime can translate into substantial financial losses.

5. Privacy Has Become a Cybersecurity Issue

Data protection failures can create legal consequences long after technical remediation is complete.

  1. The United States Has a Particularly Complex Litigation Environment

The U.S. combination of state-level privacy requirements and litigation exposure can dramatically increase the financial impact of a breach.

  1. Europe Is Not Immune to Rising Costs

European and UK businesses are also experiencing increasing claim severity, even where litigation costs differ from the U.S. environment.

  1. SMEs Cannot Assume They Are Too Small to Matter

Cybercriminals increasingly target smaller organizations because they may have valuable data but fewer security resources.

  1. Supply Chains Are a Major Blind Spot

A company can maintain strong internal controls and still be compromised through a trusted external provider.

10. Ransomware Has Become a Privacy Crisis

When attackers steal information before encrypting systems, the victim faces both operational and data-protection consequences.

11. Business Interruption Deserves More Attention

Organizations frequently focus on stolen data while underestimating the cost of being unable to operate.

  1. AI Is Both a Shield and a Weapon

Defenders can use AI to identify threats faster, but attackers can use the same technology to increase speed and scale.

13. Human Response Still Matters

Automation can detect an intrusion, but organizations still need people capable of making high-impact decisions under pressure.

  1. Backups Should Be Considered Part of Cyber Defense

Recovery capability can determine whether ransomware becomes a short disruption or a catastrophic business event.

15. Identity Security Is Critical

Stolen credentials can allow attackers to bypass many traditional perimeter defenses.

  1. MFA Is No Longer Optional for Critical Systems

Strong authentication should protect administrative accounts, remote access, cloud platforms, and sensitive applications.

17. Logging Can Reduce Uncertainty

Good forensic visibility helps organizations understand the scope and timeline of an incident.

18. Uncertainty Can Be Expensive

The longer a company remains unsure about what an attacker accessed, the harder containment, notification, and legal assessment become.

19. Vulnerability Management Needs Business Context

Not every vulnerability represents the same level of danger.

20. Internet-Facing Assets Deserve Priority

Systems exposed directly to the internet should receive particularly aggressive monitoring and remediation.

21. Cybersecurity Budgets Should Reflect Potential Loss

A multimillion-dollar potential loss justifies a very different security investment from a minor operational inconvenience.

22. Insurance Data Is Valuable Threat Intelligence

Claims reveal what actually costs organizations money rather than merely what generates security headlines.

23. Executives Should Study Severity Trends

Boards and senior leaders should pay attention to average loss per incident, not just the number of attacks.

24. Cybersecurity Metrics Need to Change

Counting blocked attacks is useful, but measuring recovery time, business interruption, exposure, and financial impact is arguably more important.

25. Security and Insurance Should Work Together

Insurance requirements can encourage organizations to strengthen controls before an incident occurs.

26. Legal Teams Should Be Involved Early

Privacy and litigation considerations can influence technical decisions during an incident.

27. Data Minimization Can Reduce Exposure

The less unnecessary personal information a company stores, the less information attackers can potentially steal.

28. Retention Policies Matter

Keeping sensitive information indefinitely can increase the consequences of a future compromise.

29. AI Governance Is Becoming Cyber Governance

Organizations adopting AI need to understand what information AI systems can access and how that information is protected.

30. Third-Party AI Services Create New Dependencies

An organization may expose sensitive data through external AI platforms even when its own infrastructure is secure.

31. Security Architecture Must Assume Failure

The objective should not be to build an environment that can never be compromised.

32. The Objective Is Controlled Failure

Organizations should design systems so that one compromised account or application does not automatically expose everything.

33. Network Segmentation Matters

Segmentation can restrict lateral movement after an initial compromise.

34. Least Privilege Reduces Blast Radius

An account that can access only what it needs is less dangerous when compromised.

  1. Detection Speed Can Change the Financial Outcome

Finding an intrusion quickly can prevent a small incident from becoming a major breach.

36. Response Speed Matters Just as Much

Detection without effective containment provides limited protection.

  1. Cyber Resilience Is Becoming a Competitive Advantage

Customers and partners increasingly want to know whether businesses can continue operating after a cyberattack.

  1. Regulation Will Continue to Influence Security Budgets

As privacy obligations expand, companies will need stronger governance around personal information.

  1. The Cost Curve Should Concern Every Board

A world where attacks become less frequent but more expensive means one serious incident can have an outsized impact.

40. The Future Belongs to Resilient Organizations

The strongest companies will not simply try to prevent every attack. They will build systems capable of detecting, containing, recovering from, and financially surviving the attacks that inevitably get through.

✅ Chubb Report and 2025 Claim Trends

Verified: Chubb officially confirms that its 2026 Cyber Claims Report analyzes claims through the end of 2025 and identifies rising severity, privacy regulation, ransomware, supply-chain risk, and AI-driven threats as major themes.

Verified:

Verified: The U.S. large-company severity increase is supported by Chubb-related reporting, with average claim severity reaching roughly $4.4 million in 2025 compared with approximately $2.2 million in 2024.

✅ Privacy and Litigation Risks

Verified: Chubb identifies complex privacy requirements and litigation as important contributors to cyber claim severity, particularly in the United States.

Verified:

⚠️ Context: The exact financial outcome of a privacy lawsuit depends on jurisdiction, claim structure, policy terms, and the circumstances of the incident. The $10 million example involving 10,000 claimants is an illustration from Chubb rather than a universal cost applicable to every privacy case.

Prediction

(+1) Cyber Insurance Will Become More Closely Linked to Security Performance

Cyber insurance is likely to become increasingly integrated with practical cybersecurity controls rather than functioning purely as post-incident financial protection.

Insurers will have stronger incentives to examine identity security, MFA, vulnerability management, backup protection, incident response, logging, supply-chain exposure, and AI governance when assessing risk.

(+1) Incident Severity Will Become a Bigger Board-Level Metric

Companies will increasingly report not only how many cyber incidents occurred but also how quickly they were detected, how long operations were disrupted, how much data was exposed, and what the potential financial impact could be.

(+1) AI Will Increase Both Defensive Capability and Attack Complexity

AI-powered security systems will become increasingly important, but organizations will also face adversaries capable of automating reconnaissance, social engineering, vulnerability research, and other stages of an attack.

(+1) Privacy Litigation Will Remain a Major Cost Driver

As organizations collect more personal data and deploy more AI systems, the consequences of mishandling that information are likely to become more complicated.

(+1) Resilience Will Matter More Than Perfect Prevention

No organization can realistically guarantee that it will never be compromised. The companies best positioned to survive the next wave of attacks will be those capable of isolating threats quickly, restoring operations, protecting backups, and demonstrating exactly what happened.

The Bigger Picture
Cybersecurity Has Become an Economic Risk

The Chubb report ultimately tells a story that goes beyond insurance.

Cybersecurity is becoming an economic discipline.

An attack is no longer simply an IT problem that security teams resolve behind closed doors. It can become a business interruption event, a privacy incident, a regulatory investigation, a litigation crisis, a customer-trust problem, and a balance-sheet shock at the same time.

The most worrying signal is therefore not that cyberattacks are increasing.

It is that the attacks that successfully penetrate organizations are becoming increasingly expensive to survive.

For businesses, that changes the priority completely. The goal should no longer be measured only by how many attacks are blocked. The real question is whether the organization can withstand the attack that gets through.

And as AI, ransomware, privacy regulation, litigation, and supply-chain dependency continue to converge, that distinction may determine which companies merely suffer a cyber incident — and which companies survive one.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube