23 Eye-Opening Cybersecurity Insurance Statistics (2023) (2024)

How common is cybersecurity insurance in the US compared to globally? How much does it cost? How much does it actually help companies in the event of a breach?

These are some of the questions we set out to answer when we took a deep dive into the state of the cybersecurity insurance market in 2022.

In this article, we’ve compiled more than 23 cybersecurity insurance statistics from multiple data sources, to provide answers to these questions, to help companies make better insurance and security decisions.

Cybersecurity Insurance Statistics (Editor’s Picks)

  • The global market for cybersecurity insurance was USD $7.60 billion in 2021 and is expected to grow to USD 20.43 billion by 2027.
  • The US market for cybersecurity insurance was worth $2.38 billion in 2020.
  • How often did cyber insurance pay out? 27% of data breach claims and 24% of first-party claims had some exclusion written into the policy that prevented part-payout or full-payout.
  • How many companies have cyber insurance? In a 2022 survey, only 19% of organizations claimed to have coverage for cyber events beyond $600,000.
  • Only 55% of organizations claimed to have any cybersecurity insurance at all.
  • How common are cybersecurity insurance claims? In the past 3 years, cyber insurance claims have increased by an order of 100% and payouts a total of 200%, with the peak claims being 8,100 in 2021.
  • What size companies made the most cybersecurity insurance claims? 99% of all cybersecurity insurance claims came from SME companies (annual revenue under $2 billion).
  • The average cybersecurity insurance claim cost for a small to medium enterprise is $345,000.
  • The average cybersecurity insurance claim cost for an SME for a ransomware event is $485,000. The average claim for all organizations is $812,360.

How Big is the Cybersecurity Insurance Market Globally?

The global market size for cyber insurance was USD 7.06 billion in 2020 and is expected to grow to USD 20.43 billion by 2027. In 2021 (Fortune Business Insights), the cyber insurance market was USD 7.49 billion globally. Both studies predict that the market will grow at a CAGR of 24% over that same time.

Source: Research and Markets report. Fortune Business Insights.

How Big is the Cybersecurity Insurance Market in the US?

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (1)

The US market continues to be the largest contributor to the cyber insurance market, with a total market cap in 2020 of USD 2.38 billion. Further, it is predicted that the US will continue to be the largest driver in the growth and adoption of cyber insurance over the next 6 years.

Source: Fortune Business Insights

Is the Cyber Insurance Market Growing?

The short answer is yes, the market is growing, but like many markets over the last few years, COVID-19 has introduced unforeseen factors that have altered the growth pattern and adoption. Analysis shows that cybercrime and claims are increasing across the globe, which further drives the adoption and desire to have coverage for cyber-related incidents.

The main factor contributing to the adoption and growth of the cybersecurity insurance market is that the overall cost of claims is going up.

Sources: IBM reference in the Research and Markets report. Fortune Business Insights.

CISOs Comment on the State of Cyber Insurance

While these numbers seem to be supported across multiple studies, there is room to theorize that the overall growth in the industry may be stronger in that period. From personal experience and from conversations with peer CISOs across industries, overall rates and ability to gain cyber insurance are becoming more difficult. To me, this indicates a demand that is stronger than the risk appetite of the insurers and shows that organizations are utilizing cyber insurance as a mechanism to help make the organization whole, in the event of a breach.

I have heard from several CISOs and executives that have claimed to be turned away by cyber insurance carriers. In some cases, this may be due to the type of business or vertical the organization operates within. This is very similar to trying to get homeowners’ insurance in a hurricane-susceptible region or a low natural disaster region with a fire station close by. The risk of loss to the insurer is lower. This further indicates to me that the market is extremely strong and has high demand, as it was not that long ago that almost any organization could get coverage if they chose; no matter how good their security program was.

How Common is Cyber Insurance?

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (2)

It can be difficult to know just how many organizations have coverage and what level of coverage they have, as this data is self-reported. In a 2022 survey of 450 organizations, only 19% claimed to have coverage for cyber events beyond $600,000 with a total of 55% having some cyber insurance coverage.

Another way to look at total adoption is based on the total written coverages. The total number of written premiums in 2020 was USD 2.7 billion with a total of 4 million policies in force. Additionally, we see continued adoption of cybersecurity insurance year after year from 2016 (doubling in that time), with the largest increase being from 2019 to 2020.

Sources: The Register, NAIC, Sophos.

How Common Are Cyber Insurance Claims?

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (3)

A good way to review the total number of claims is to review the loss ratios. Insurers expect to have to pay out a certain number of the full claims each year, and they attempt to spread that cost across the premiums, in hopes of not having to pay out all of the premiums.

In 2020, the top 20 cybersecurity insurers’ loss ratio ranged from 24.6% up to 114%.

In the past 3 years, cyber insurance claims have increased by an order of 100% and payouts a total of 200%, with the claim payouts peaking at 8,100 in 2021.

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (4)

Further, a detailed 2021 report analyzing 5,797 claims from 2016-2020 found that 99% of all claims came from SME companies (annual revenue under $2 billion).

Sources: NAIC, FitchRatings, NetDiligent

What is The Average Cyber Insurance Claim? ($)

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (5)

Breaking down the insurance claims, the average claim cost for a small to medium enterprise is:

  • $111,000 for crisis services
  • $98,000 for legal
  • $145,000 for the incident itself
  • $345k average total claim

However, when it comes to ransomware, the total average claim cost rise to $485k.

Source: NetDiligent

What is the Most Common Reason for a Cyber Insurance Claim?

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (6)

Ransomware continues to be the most common cyber insurance claim followed by phishing attempts.

However, it can be argued that phishing is the primary culprit of compromise, as this is how most ransomware is entering the business.

According to a 2022 report, one in six cybersecurity insurance claims were related to ransomware, with the FBI seeing an increase of 69% of reported complaints or crimes in 2020.

Also, a total of 37 billion personal records were compromised in 2020, which shows that the impact and the total number of breaches are not slowing down.

All of this can be evidenced by additional legislation and regulatory requirements that are being passed and required for organizations.

Sources: NetDiligent, Security.org.

What Percentage of Security Breaches Are Covered by Cyber Insurance?

According to one report that analyzed more than 1,150 claims, 36% of the cost of the incident cybersecurity events the insurer paid under the policy limit, and in 2% the insured limit was under the total amount required for the incident, resulting in an underpayment by the broker.

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (7)

In all, 27% of data breach claims and 24% of first-party claims had some exclusion written into the policy that prevented payout or full payout.

Source: Willis Towers Watson.

Who Are The Largest Cybersecurity Insurers?

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (8)

The top 8 cybersecurity insurers are Chubb, AXA XL, AIG, Travelers, AXIS, Beazley, CAN, and BCS. What is more astounding is that AXA XL, Chubb, AIG, and Travelers make up 40% of the market for policies across all industries.

With so few having such a large percentage of the market, they really can dictate the rates and increase, along with requirements for insurance. However, they are also taking on a larger percentage of risk and loss at the same time.

Source: eSecurity Planet, NAIC

What’s The Most Popular Type of Cyber Insurance?

There are multiple types of cyber security insurance an organization can have. Beazley lays out the most common types of policies that are available. Ranging in coverage and use cases, you have policies for breaches that cover response, investigations, and monitoring services.

There is the first party, which includes business interruption, extortion, and recovery costs. Also, there is third-party coverage that helps with regulatory fines, privacy, and media. An additional policy can be added to the writer that covers fraud, which could be an accident transfer of funds or other fraudulent activities.

While it would be great to have hard numbers on which policies are most popular, this data is difficult to obtain. In the absence of this data, we are left to infer based on other cyber insurance data what the most common cyber insurance policies might be.

Based on the report by NetDiligent and according to the cost of the breaches, it would appear the two most common policies carried out are breach response and first-party insurance.

Speaking from experience and from what I hear from peer CISOs, fraud insurance can be hard for any business that deals with payments (either business or consumer) regularly, so this policy tends to be utilized less.

Further, it is common for cyber insurance policies to be written with a primary and secondary provider, usually split evenly to help offset the risk exposure.

Source: Beazley, NetDiligent.

Most Common Reason Companies Invest in Cyber Insurance?

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (9)

The two most common reasons for a company to invest in cyber insurance are:

  1. A cyberattack occurred against another company in the same industry.
  2. It was recommended after an independent cybersecurity risk assessment.

Other reasons a company will have cyber insurance are for the recovery of lost data or lost devices, to meet notification requirements, and for forensics after an incident.

Recovering from an incident can be costly, especially when systems need to be restored or rebuilt because they have been compromised and are not able to operate safely.

Additional notification requirements and fines have increased the cost of a breach, including the fines that can be levied against an organization. Often, each compromised or deleted record is charged several hundred dollars.

For an organization to be able to withstand the financial hit, the organization will need insurance to assist with the costs of dealing with a breach and the fines that will result from it.

Source: Travelers, Statista.

23 Eye-Opening Cybersecurity Insurance Statistics (2023) (2024)

FAQs

What are the statistics for cyber security in 2023? ›

Cybersecurity Fast Facts

The year 2023 saw a notable increase in cyberattacks, resulting in more than 343 million victims. Between 2021 and 2023, data breaches rose by 72%, surpassing the previous record.

What is the loss ratio for cyber insurance in 2023? ›

A first look at data compiled from cyber insurance supplemental filings in statutory financial statements indicates that for standalone cyber coverage the direct incurred loss and defense and cost containment (DCC) expenses ratio held relatively steady at 44% in 2023 versus 43% in 2022.

What is the cyber insurance market trend in 2023? ›

Buyer-Friendly Cyber Market Conditions Prevail

Throughout 2023, cyber insurance premium rates decreased by an average of 17 percent, challenging expectations of a modest deceleration in rate reductions by Q4. In the second half of 2023, there was a notable surge in cyber and privacy incidents.

How many cybersecurity breaches in 2023? ›

There were 3,205 data compromises in 2023, impacting 353 million total victims, a figure that includes people who appear in more than one publicly-reported data breach notice, according to the resource center, a non-profit that tracks publicly reported incidents of compromised personal information and consumer data in ...

What are the statistics for cybersecurity in 2024? ›

130+ Cybersecurity Statistics to Inspire Action This Year [2024 Update] Global cyber attacks continue to rise in 2024, with the average number of cyber attacks per organization per week reaching 1,308 in the first quarter of 2024. This is a 28% increase from the last quarter of 2023 and a 5% increase year-over-year.

What are the latest statistics for cyber crime? ›

How often does cyber crime occur? With an average of 97 cyber crime victims per hour, this means there is a victim of cyber crime every 37 seconds. In addition, 2 internet users have had their data leaked every second in 2022. This is an improvement over 2021, where 6 users had their data leaked every second.

Is the demand for cyber insurance increasing? ›

Cyber insurance remains one of the fastest-growing areas within the global insurance industry, with premiums anticipated to exceed $20 billion by 2025, up from an estimated $15 billion in 2023.

What percent of companies have cyber insurance? ›

Data breaches in the U.S. cost up to 9.44 USD on average. 34% of organizations in the U.S. have a standalone cybersecurity insurance policy. 43% of SMEs in the U.S. bought cyber insurance for the transfer of risks.

Why is it difficult to get cyber insurance? ›

Demand, losses, and premiums are all on the rise

The demand for cyber insurance coverage is skyrocketing. At the same time, insurance providers' losses are growing. High demand in combination with high payouts lead to increased premiums. Businesses report premium hikes of 50% and even 100% year over year.

What is the growth rate of cyber insurance? ›

The global cyber insurance market is projected to be worth $90.6bn by 2033, at a growth rate of 22.3% CAGR from 2023, according to an analysis by Market.Us. The industry is expected to reach $14.8bn by the end of 2024, a significant rise from a projected valuation of $12.1bn in 2023.

What is the US cyber insurance market outlook? ›

Cyber is a market with strong growth potential as demand for coverage remains strong amid an evolving risk environment. However, weaker pricing led to a 1% decline in U.S. direct cyber written premiums in 2023 following a 160% increase in volume from 2020-2022.

What is the future of cyber insurance? ›

Despite challenges such as pricing volatility and threat uncertainties, the cyber insurance market is growing rapidly and is expected to amount to USD 480 billion of commercial premiums by 2040; this growth is largely driven by rising innovation and sophistication in risk assessment, policy coverage, and risk ...

What is the cybersecurity market growth for 2023? ›

The global cyber security market size was valued at USD 172.32 billion in 2023 and is projected to reach USD 424.97 billion in 2030, exhibiting a 13.8% CAGR during the forecast 2023-2030. North America accounted for a market value of USD 67.77 billion in 2022.

How much has cyber crime increased in 2023? ›

The cost of reported cybercrime in the U.S. jumped 22% last year to more than $12.5 billion, according to the FBI's Internet Crime Complaint Center (IC3) 2023 annual report (PDF).

What company was the largest data breach in 2023? ›

See the full list of data breaches for September 2023. September saw the biggest data breach of the year by far, when the digital risk protection company DarkBeam exposed an astounding 3.8 billion records thanks to a misconfigured Elasticsearch and Kibana interface.

Will cybersecurity be in demand in 2023? ›

Cyber security is an ever-growing industry. It is projected to grow by 11% in 2023 and by 20% in 2025. This is a fast-paced career with a median salary of $81,000.

What is the cyber risk outlook for 2023? ›

In terms of threats for businesses and individuals, ransomware will remain the primary loss driver in 2023, and very likely also beyond. The numbers are significant. According to Cybersecurity Ventures, ransomware will cost its victims approximately US$ 265 billion annually by 2031.

References

Top Articles
Latest Posts
Article information

Author: Greg Kuvalis

Last Updated:

Views: 6755

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Greg Kuvalis

Birthday: 1996-12-20

Address: 53157 Trantow Inlet, Townemouth, FL 92564-0267

Phone: +68218650356656

Job: IT Representative

Hobby: Knitting, Amateur radio, Skiing, Running, Mountain biking, Slacklining, Electronics

Introduction: My name is Greg Kuvalis, I am a witty, spotless, beautiful, charming, delightful, thankful, beautiful person who loves writing and wants to share my knowledge and understanding with you.