Mid-market cyber severity has tripled even as claims fall - Chubb survey

A single supplier's ransomware incident halted manufacturing across five weeks and affected more than 5,000 UK organisations that were never directly attacked. That is now the primary cyber risk for mid-market clients

Mid-market cyber severity has tripled even as claims fall - Chubb survey

Cyber

By Josh Recamara

Chubb's latest cyber claims analysis shows that while cyber incident frequency among mid-sized UK and European businesses has stabilised, the financial cost of those incidents that do occur continues to climb sharply.

The insurer's 2026 Cyber Claims Report found that middle market claims frequency fell to a five-year low in 2025, even as the average claim value tripled between 2020 and 2025.

According to Chubb's own published findings, middle market claim severity across the UK and Europe rose 210% over five years to an average claim cost of $318,820 in 2025, while claims frequency fell to 1.51 claims per 100 policies, the lowest level the report has recorded. Severity alone rose by around 100% between 2024 and 2025.

AI cuts both ways

Chubb said artificial intelligence is helping businesses better identify and detect cyber vulnerabilities, but is simultaneously enabling more sophisticated adversarial use of technology that can accelerate both the speed and scope of an attack once it begins.

That dual effect, better detection tools reducing how often attacks succeed, but successful attacks becoming more damaging when they do, is one plausible explanation for the pattern of falling frequency alongside rising severity that the report describes.

Supply chain exposure is now central to the risk

Jimaan Sané, Chubb's head of growth for global cyber, said one of the key areas of increased exposure for small and medium-sized businesses is their own supply chain, given greater dependency on third-party suppliers. He said mid-sized businesses increasingly face the same level of cyber disruption as large corporates, but often without the same operational resilience, and that beyond preventing their own cyber failures, businesses now face the challenge of financial and operational fallout when interconnected systems, suppliers and partners are compromised.

Sané said that when a technology provider is struck by ransomware, the consequences rarely stay contained: for retailers, manufacturers and service businesses that depend on that provider's systems, sales transactions can halt, inventory visibility can be lost and operations can be suspended, even though the attack originated outside their own walls. He said this growing exposure underscores the importance of contingent business interruption coverage within any comprehensive cyber risk strategy.

That dynamic has already played out publicly in the UK market. The 2025 cyberattack on Jaguar Land Rover disrupted operations across the company's supply chain, illustrating exactly the dependency risk Sané describes, where a single major customer's cyber incident can effectively halt operations for businesses that had no direct role in the attack.

Separately, Chubb's own claims data has recorded a UK ransomware incident that caused around $568 million in losses for the targeted company but $1.4 billion in losses across its entire supply chain, halting manufacturing for five weeks across sites in the UK, Slovakia, Brazil and China and affecting more than 5,000 UK organisations in total.

Ransomware and social engineering remain persistent risks

Chris Collier, Chubb's vice president of claims, said social engineering fraud, privacy incidents and ransomware attacks continue to present significant risk alongside AI-driven threats and growing supply chain dependencies. He said these incidents can be crippling, particularly for small and mid-sized businesses that lack appropriate cyber coverage and have no way to recover from or pay for losses that turn out to be unrecoverable.

Collier added that even when initial ransomware encryption attempts are thwarted, the exfiltration of sensitive data can still trigger extensive notification requirements and remediation costs.

A persistent coverage gap

The severity trend Chubb describes is landing on a market where standalone cyber coverage remains far from universal.

The UK's most recent Cyber Security Breaches Survey found that around 61% of medium-sized businesses hold some form of cyber insurance, though separate industry research has put specific standalone cyber policy uptake among medium-sized firms in a narrower range, generally below two-thirds even among better-insured mid-market segments, with take-up considerably lower among smaller businesses.

UK cyber insurance claims payouts recorded by the Association of British Insurers rose from £59 million in 2023 to £197 million in 2024, a 234% increase in a single year, underscoring how quickly claims costs have grown even as coverage gaps persist.

The wider read

Chubb's data points to a market where the risk calculus for mid-sized businesses has genuinely shifted: fewer incidents, but each one now carries meaningfully higher financial consequences, often stemming from a supplier's failure rather than a company's own security lapse.

For brokers advising mid-market clients, that reframes the coverage conversation away from "how likely is an attack" and toward "how exposed is this client through relationships they don't fully control," making contingent business interruption cover and supply chain-aware policy wording a much harder sell to skip than it might have been when frequency, not severity, was the dominant concern.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!