CYBER & TECHNOLOGY

Buyer-friendly conditions persist, but watch for loss drivers

KEY TAKEAWAYS


Cyber insurance buyers still enjoy a favorable market but should expect more underwriting scrutiny.


AI continues to reshape the cybersecurity landscape as threat actors deploy the technology and models themselves have infiltrated other systems.


Regulators continue to take aggressive action as it relates to privacy, particularly children’s privacy.

Expected rate changes next quarter*

Flat to 5% increase


Cyber

The cyber insurance market remains soft, continuing a trend that is approaching four years in duration. In the second quarter of 2026, median cyber insurance rates fell 0.1%, according to Lockton data.

Buyers continue to secure favorable rates and improved terms and conditions as insurers compete for business in most sectors, with healthcare and legal being the exceptions. New market entrants, along with aggressive growth targets, have only intensified the competition.

At the same time, underwriters are becoming more selective about the risks they write, given potentially mounting loss costs. Several losses are out in the market in the current claims environment, many of which are being litigated and will take years to play out.

Carrier risk management services continue to play an increasingly important role in cyber insurance purchasing decisions. As premium reductions have moderated and insurers focus more closely on cybersecurity controls, many carriers are differentiating themselves through value-added services. Those include:

Vulnerability assessments

External attack-surface monitoring

Employee awareness training

Incident response planning

Tabletop exercises

Access to preferred cybersecurity vendors

Organizations should evaluate these capabilities alongside premium, retention, and policy terms, as proactive risk management resources can help reduce both the frequency and severity of cyber events.

Carriers continue to focus on whether, and to what extent, buyers have adopted meaningful cyber controls, given the persistent and fast-growing threat that AI-enabled hacks and intrusions pose to companies.

Threat actors have established the use of AI as a force multiplier in their operations, leveraging it to increase the speed, scale, and sophistication of attacks. AI can enhance phishing campaigns, social engineering fraud, impersonation, reconnaissance, and other techniques designed to deceive employees and gain access to targeted organizations.

Cyberattackers can use AI to accelerate their breakout times — the time it takes to move from an attack’s entry point to other areas within the network — making it more difficult for companies to contain an intrusion. CrowdStrike research shows that the average breakout time in 2025 fell below 30 minutes for the first time, marking a 70% reduction from 2021.

AI-enabled attacks pose a particular risk to small and medium-sized companies. Their relative lack of resources and staffing puts them on an uneven playing field against nimble attackers.

AI itself is a network security risk that companies are struggling to keep up with, given its rapid advancement. An incident in July crystallized these worries.

Hugging Face, a machine learning company, detected a bizarre and unique network breach. Soon after, frontier AI firm OpenAI disclosed that one of its advanced and unreleased models had escaped a sandbox testing environment and infiltrated Hugging Face’s systems.

The incident highlights how AI models themselves, when undergoing testing in insufficiently contained environments, can pose cybersecurity threats.

Cyber insurers have started developing AI-specific products, endorsements, and underwriting approaches. That said, the market remains fragmented, and no standardized or universally adopted strategy for addressing AI-related risks has yet emerged.

Non-data breach privacy claims represent another core risk to which insureds are increasingly exposed. These claims often allege that companies mishandle or misuse consumer data collected without permission through advertising pixels and other tracking technologies.

The California Invasion of Privacy Act (CIPA) and other statutes originally designed to address wiretapping claims have been used by plaintiffs in class actions to recover damages for unauthorized data collection.

In July, for example, a federal judge approved a $3.85 million settlement in a class action alleging that the Los Angeles Times used unauthorized data trackers to collect internet protocol addresses from website visitors.

In 2024, plaintiffs filed 2,529 data privacy lawsuits, a 77% increase from 2020, according to data from Thomson Reuters/Westlaw Edge.

Third-party privacy violations, along with AI-related threats, are among the risks that the cyber reinsurance market is closely watching. There is considerable capacity in the cyber reinsurance market for global programs with favorable loss experience, even though the pace of new entrants has slowed.

Cyber reinsurance buyers

have benefitted from risk-adjusted rate improvements on quota share and excess-of-loss programs thanks to robust capacity and a lack of large loss events so far this year. Still, reinsurers are looking to diversify their exposure away from the large-risk segment into the middle-market business and unique portfolios going into 2027.

Margin pressure is increasing for reinsurers, leading some in the market to manage allocations for catastrophic exposure to maintain positions on cyber quota share programs.

Cyber reinsurance programs

may see price decreases in the 5% to 10% range for Jan. 1 renewals, creating a favorable buying environment. That being the case, reinsurers are keeping an eye on losses from the 2023 and 2024 underwriting years and how that may impact their portfolios.

Some jurisdictions are taking a tougher posture on data privacy.

california

California regulates how businesses can use data from automatic license plate readers. Companies that use data collected from license plate readers — parking garages, security services, retailers — face class action exposure if they fail to comply with California’s privacy law. A recent California appellate court decision held that private companies can be held liable if they fail to publicly disclose that they use automatic license plate readers, even if a plaintiff doesn’t prove a direct economic harm from the collection of license plate data.

new jersey

In August, New Jersey joined a growing number of states that have set tighter regulations around child privacy. New Jersey enacted new legislation that limits what data companies can collect from children. It also requires online platforms, such as social media sites, to set their default privacy settings to the highest level when children gain access.

Europe & Australia

In Europe and Australia, enforcement of statutes such as the General Data Protection Regulation, the AI Act, and the Cyber Resilience Act imposes various requirements on AI governance and on reporting cyber breaches.

Essentially, insureds should expect that cyber and privacy events will increasingly become regulatory events, especially where they involve critical infrastructure, AI, children’s privacy, and third-party vendors.

*Note: Rate ranges presented here reflect expected renewal outcomes — as of the Lockton Market Update publication date — over the next quarter for most insurance buyers. These should not be taken as a guarantee of any specific results during renewal negotiations. Depending on risk profiles, loss histories, account specifics, and other factors, individual buyers may renew their programs outside these ranges.


© 2026 Lockton Companies. All rights reserved.