The renewal packet arrived with a lower price and a longer application. That combination is the trap. Cyber insurance premiums have fallen for twelve straight quarters, yet the underwriting behind that number has gotten stricter, not looser, and treating this renewal like last year's is going to cost someone real money.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

The Price Went Down. The Bar Went Up.

Global cyber insurance rates fell 4% in the second quarter of 2026, the twelfth consecutive quarterly decline, according to Marsh's Global Insurance Market Index. The United States posted the smallest drop of any region tracked, just 2%, while India, the Middle East and Africa fell 14% and Latin America fell 10%. Marsh attributes the broader trend to abundant capacity and intense competition among carriers across every product line, not just cyber.

Read that as one number and you would assume renewals are getting easier across the board. They are not. Twenty percent of Marsh's clients raised their coverage limits this cycle, and eighteen percent cut their retentions. Both moves only make sense if carriers are competing hardest for accounts they already trust. The softness in headline pricing is concentrated on organizations that can already prove strong controls. Everyone else is negotiating from a weaker position than the average rate figure suggests, and the average rate figure is what most finance teams see first.

The Claims Data Explains Why

Carriers are not cutting prices because risk went down. At-Bay's 2026 InsurSec report, built from more than 100,000 policy years of claims, found claim frequency rose 7% year over year in 2025, the highest rate since 2021, while average claim severity hit an all-time high of $221,000. Companies under $25 million in revenue took the worst of it, with severity up 26%, the steepest jump of any segment for the third year running.

One ransomware operator drove an outsized share of that damage. Akira caused a 53% jump in ransomware frequency in the second half of 2025 and accounted for more than 40% of all ransomware claims for the full year, the highest concentration At-Bay has recorded from a single group. Eighty-six percent of Akira intrusions hit environments running SonicWall devices, and two-thirds of the attacks landed at night or on weekends, when detection is slowest and staffing is thinnest. Coalition's 2026 claims report separately found initial ransom demands surged 47% year over year even as 86% of businesses refused to pay them.

Put those two Coalition numbers together and you get the real story of this renewal cycle. Demands are getting more aggressive while refusal rates climb, which means carriers are absorbing more incident response and business interruption cost per claim even when no ransom changes hands. At-Bay found claims involving business interruption averaged $510,000 versus $168,000 for claims without it, a threefold gap. Underwriters price for that gap by asking harder questions about backup architecture and failover time, not by raising the sticker price across the board where competition is fiercest.

Detection Speed Became a Pricing Variable

The clearest evidence that controls now drive pricing more than history does is At-Bay's finding that not one of its managed detection and response customers filed an Akira claim in 2025. Zero, against a threat actor responsible for more than 40% of all ransomware claims industry-wide that year. Underwriters see results like that and build them directly into applications. Marsh identifies a set of roughly twelve cyber hygiene controls that carriers now treat as close to mandatory. Multi-factor authentication everywhere, endpoint detection and response, and tested backup recovery do most of the work separating the accounts that got a rate cut from the accounts that got declined outright or pushed onto restrictive terms.

AI Exposure Is the New Wildcard

The other pressure showing up at renewal has nothing to do with ransomware. Insurers are quietly rewriting how AI-related losses get treated. The Insurance Services Office introduced a generative AI exclusion into commercial general liability forms in January 2026, and cyber and management liability carriers are following with their own endorsements, application questions, and narrower base forms, according to legal analysis published by law firm Fenwick. None of this shows up as one headline clause most executives would notice on the first read. It shows up as a new application question about which AI tools touch customer data, and as coverage that quietly moves out of the base cyber form into a separate, more restrictive endorsement nobody negotiated for.

A Worked Example

A 400-employee manufacturing company renewed in 2024 at $180,000 for $5 million in cyber coverage. MFA covered email only, there was no dedicated detection tooling, and backups were tested once a year. At its 2026 renewal, the underwriting application ran four pages longer, added a section asking which departments used generative AI tools against customer data, and required MFA on all remote access plus evidence of quarterly backup restoration tests. The company had no ready answers on the AI questions and had not tested backups since the prior renewal.

The quote came back flat year over year on premium, which the CFO initially read as good news. The retention had doubled, though, and business interruption coverage dropped to a sublimit worth two-thirds of what the policy carried the year before. The invoice looked unchanged. The risk the company actually retained had grown substantially, and nobody caught it until the broker walked the CFO through the sublimit language line by line, three weeks after the policy had already bound.

The Counterargument Worth Taking Seriously

Some brokers will argue this framing overstates the shift, that soft markets have always meant carriers compete on non-price terms once price bottoms out, and that a 2% national rate decline paired with expanding limits is, on balance, good news for buyers who already invest in security. That argument has real merit. A buyer with strong MFA coverage, tested backups, and a documented incident response process is genuinely getting a better deal in 2026 than in any of the past four renewal cycles, and pretending otherwise would be dishonest.

The problem is that this favorable market gets sold to every renewing account as the same story, when the claims data shows it applies to a shrinking, better-controlled subset of buyers, while everyone else absorbs the difference through higher retentions, narrower sublimits, and AI carve-outs that never make it into the top-line premium conversation the board actually sees.

The practical fix is not to distrust every broker's pitch. It is to ask the broker to separate the two arguments explicitly, what the market-wide price trend is doing, and what this specific account's control posture earned it this cycle, rather than letting a favorable headline number stand in for both. Those two figures move independently now in a way they did not five renewal cycles ago, and conflating them is how a flat premium ends up masking a meaningfully worse contract.

Questions for Monday

Ask the broker for the actual retention and sublimit changes year over year, not just the headline premium number. Ask whether this year's renewal application added new AI-related questions, and confirm who in the company is actually qualified to answer them accurately. Ask when backups were last tested to a full restoration, not just backed up. Ask what share of remote access still relies on single-factor authentication. These are exactly the kinds of questions leadership and the board should be walking through with the broker before the renewal call, not discovering after the policy has already bound.

The renewal that looks the same as last year's is the one that should worry you most.