Cyber: A soft market with a hard truth
Our H1 2026 regional cyber report
Summary
Cyber insurance has rarely been more affordable. Cyber risk has rarely been more consequential. Both are true at the same time, and reconciling them is the central challenge this report sets out to address. In the first half of 2026, recorded ransomware activity hit a fresh half-year record, data theft became a routine feature of almost every serious attack, and regulators sharpened their focus from whether an organisation was breached to what the breach revealed about its governance. And yet cyber insurance pricing fell for a fourth consecutive year, with capacity abundant and carriers competing hard on both price and breadth of cover.
Those trends appear contradictory, but they are not. Attacks are becoming more frequent and their consequences more severe, while the insurance market is being held soft by a structural oversupply of capacity rather than any easing of the underlying threat. The cost of transferring cyber risk has fallen, even as the cost of retaining it keeps rising. The report also makes an important point about the numbers themselves: figures such as the 4,295 recorded ransomware events are recorded and reported incidents, not the true total. They exclude organisations that paid quietly, incidents settled before disclosure, and events in sectors with no mandatory reporting. The real exposure is materially larger than any published number suggests.
Bringing together three perspectives on the same problem, the report draws on threat intelligence from NSB Cyber, legal and regulatory analysis from Wotton Kearney, and market and boardroom insight from Howden. It examines who is attacking, who they target, and how; what a breach actually triggers once systems are back up; and what all of this means for how organisations finance, govern and transfer the risk. A recurring theme is the shift from encryption to data theft, and why data-driven losses behave very differently: they surface months or even years later through regulatory investigations, litigation and contractual disputes, long after an incident is considered "over."
Above all, the report frames today's conditions as a window rather than a destination. The organisations that gain the greatest advantage will not be those that simply buy the cheapest policy, but those that use favourable conditions to strengthen resilience, secure appropriate limits, align their cyber, crime and management liability programmes, and build the governance that regulators, insurers and stakeholders now expect. The market remains soft. The threat environment is not.

State of Cyber: H1 2026
Download the full report to see what the half looked like in the data, what it means for your organisation, and what to do while the window is open.
