Cyber: A soft market with a hard truth

Our H1 2026 regional cyber report

Summary

Cyber risk continues to escalate despite a fourth consecutive year of declining cyber insurance premiums. The report highlights record ransomware activity, the growing shift from encryption to data theft, increased regulatory scrutiny following breaches, and the widening gap between rising cyber exposure and falling insurance costs. It also explores how organisations can strengthen resilience, governance and risk transfer strategies while market conditions remain favourable.

Cyber insurance has rarely been more affordable. Cyber risk has rarely been more consequential. Both are true at the same time, and reconciling them is the central challenge this report sets out to address. In the first half of 2026, recorded ransomware activity hit a fresh half-year record, data theft became a routine feature of almost every serious attack, and regulators sharpened their focus from whether an organisation was breached to what the breach revealed about its governance. And yet cyber insurance pricing fell for a fourth consecutive year, with capacity abundant and carriers competing hard on both price and breadth of cover.

Those trends appear contradictory, but they are not. Attacks are becoming more frequent and their consequences more severe, while the insurance market is being held soft by a structural oversupply of capacity rather than any easing of the underlying threat. The cost of transferring cyber risk has fallen, even as the cost of retaining it keeps rising. The report also makes an important point about the numbers themselves: figures such as the 4,295 recorded ransomware events are recorded and reported incidents, not the true total. They exclude organisations that paid quietly, incidents settled before disclosure, and events in sectors with no mandatory reporting. The real exposure is materially larger than any published number suggests.

Bringing together three perspectives on the same problem, the report draws on threat intelligence from NSB Cyber, legal and regulatory analysis from Wotton Kearney, and market and boardroom insight from Howden. It examines who is attacking, who they target, and how; what a breach actually triggers once systems are back up; and what all of this means for how organisations finance, govern and transfer the risk. A recurring theme is the shift from encryption to data theft, and why data-driven losses behave very differently: they surface months or even years later through regulatory investigations, litigation and contractual disputes, long after an incident is considered "over."

Above all, the report frames today's conditions as a window rather than a destination. The organisations that gain the greatest advantage will not be those that simply buy the cheapest policy, but those that use favourable conditions to strengthen resilience, secure appropriate limits, align their cyber, crime and management liability programmes, and build the governance that regulators, insurers and stakeholders now expect. The market remains soft. The threat environment is not.

Cyber report H1 2026

State of Cyber: H1 2026

Download the full report to see what the half looked like in the data, what it means for your organisation, and what to do while the window is open.

Get in touch today