Cyber Insurance: The Impact of Evolving Threats From AI, Ransomware and Social Engineering

From 2024 to 2026, disruption risk, technology obsolescence and IP risk showed steady or declining levels of risk concern, according to Beazley’s “Spotlight on Cyber Threat and Tech Advances 2026.” Cyber risk did not decline. In fact, it is the threat executives are most worried about, the report said.

The increased concern is driven by a changing threat landscape, where artificial intelligence (AI), connected technology systems and supply-chain relationships make it easier for cyberattacks to spread quickly and cause wider disruption. These threats are affecting the cyber insurance market.

“In the past year, insurers faced two big challenges: First, they had to deal with widespread AI use that led to increased risk, including the rise of deepfakes and shrinking exploitation windows for attackers,” says Michael Phillips, global head of cyber portfolio underwriting at Coalition. “Second, they needed to decide whether their policies covered losses from AI as a tool, a threat vector or a core component of an organization’s processes.”

October is Cybersecurity Awareness Month, serving as a reminder that vigilance is more important than ever. Technological innovation and increasingly interconnected systems are transforming the cyber landscape and creating new challenges for businesses and insurers alike.

“AI is reshaping the threat landscape by enabling more sophisticated phishing, social engineering and ransomware attacks, while at the same time, organizations are leveraging AI-driven security tools to improve threat detection and response,” says Betty Shepherd, divisional president, cyber risk, Great American Insurance Group.

Notably, “ransomware remains a significant cyber threat and continues to evolve,” says Mike Maletsky, vice president, practice leader for technology and cyber, Hiscox. “Attackers have shifted their focus from simply encrypting systems to stealing data and threatening to release it.”

“Those incidents tend to be more complex, take longer to resolve and often create additional legal, regulatory and reputational consequences that insurers must consider,” Maletsky adds.

The average U.S. business experienced at least one ransomware attack in the past 12 months, with organizations paying an average ransom equal to 2.24 times the cost of recovery, according to the Hiscox Cyber Readiness Report. Additionally, 88% had to rebuild their data.

Further, after paying the ransom, 50% did not recover all their data, and 27% suffered another attack, the report said.

These changes continue to influence the industry, affecting claim frequency and severity, as well as pricing and underwriting decisions.

“Losses are shifting rather than disappearing,” Phillips says. “Ransomware remains a significant threat, but social engineering, funds transfer fraud, privacy-related claims and vendor-driven incidents are playing a bigger role in the claims mix.”

“Ransomware continues to drive claim severity but social engineering accounts for increasing claims frequency trends,” says Anthony Dolce, head of professional liability, cyber and tech errors & omissions at The Hartford. “Stronger risks will continue to see attractive options while organizations with weaker controls or more complex exposures may see more underwriting questions, restrictions on terms or different pricing.”

While agents can expect to find competitive pricing “particularly for clean accounts with strong controls, we do not view the current pricing environment as a signal that risk has decreased,” Shepherd says. “Rather, it reflects abundant market capacity and competition.”

Echoing that perspective, Phillips also cautions that softer pricing trends should not be mistaken for a permanently easing market.

“Broad market softness does not necessarily mean pricing will continue to decline indefinitely,” Phillips says. “Premiums have been flat to modestly down in many segments, but rising paid losses, more complex AI and privacy exposures and continued concern around systemic risk all point toward a market that may stabilize or become more differentiated, rather than continue uniformly softening.”

Carriers are “looking beyond specific threats, leading insurers to shift away from the old model of annual questionnaire-based underwriting toward a more active model that includes continuous scanning, threat intelligence, proactive alerts and pre-claims support,” Phillips continues. “That helps carriers and policyholders respond faster as threats evolve instead of waiting until renewal or until after a loss.”

As trusted advisors, agents can also ensure clients are making use of carrier training “to avoid certain scams as well as establishing certain protocols to avoid claims involving invoice manipulation and fraudulent wire transfers,” Dolce adds. “This is why cyber resilience and employee awareness are so critical.”

Olivia Overman is IA content editor.