US cyber insurance rates are still falling, but the market is showing signs that the long run of reductions may be approaching its limit.
According to Marsh, US cyber rates declined another 2% in the second quarter of 2026, matching the decrease seen in Q1. Rates have now been falling since the second quarter of 2023, while capacity remained stable despite consolidation among cyber insurers. Marsh said obtaining further reductions increasingly required brokers to approach a broader range of markets.
Michael Spinks, head of SME cyber, USA at CFC, believes the market is now closer to the bottom of the cycle than the top.
“The cyber market has been softening for the past few years following the significant rate increases of the ransomware-driven hard market in 2020 to 2022,” Spinks said. “While ransomware remains a major threat, increased capacity and competition have pushed pricing down, with rates in some areas approaching 2019 pre-hard market levels.”
Rather than expecting another round of widespread reductions, Spinks said the pace of softening is likely to slow.
He also cautioned that improvements in insureds’ cybersecurity alone do not explain how far pricing has moved; additional carrier capacity, abundant capital and competition have all played significant roles.
Competition is still substantial. Aon reported that more than 90 insurers participated in its cyber placements during 2025, while North American clients generally achieved average reductions of between 4% and 7%.
Around 19% of its US cyber liability buyers also purchased additional limits during the year, suggesting clients have been using softer conditions to strengthen programs rather than simply pocket premium savings.
But underwriting results are beginning to give carriers more reason to watch pricing.
AM Best reported the US cyber insurance loss ratio increased 4.3 percentage points to 53% in 2025, the second consecutive annual increase and the first time it had exceeded 50% since the ransomware surge during the pandemic. Surplus lines insurers now account for almost two-thirds of cyber premium, with an incurred loss ratio of 55.9%, compared with 50.2% for admitted carriers.
Spinks said rate adequacy already varies considerably between industries. “In some US industry segments, for example, additional rate may be needed to accurately reflect the level of exposure, while in others that may not be necessary,” he said.
Keith Savino, CEO of Emergence US, said cyber, at roughly 25 to 30 years old, remains a relatively young insurance class and should be expected to go through the same market swings seen in property and casualty. One factor differentiating cyber from more mature commercial lines is the amount of business still outside the insurance market.
A Morning Consult survey of 506 US small-business owners, conducted for the Public Private Strategies Institute, found just 24% carried cyber insurance. This leaves significant room for insurers to grow without relying solely on taking existing accounts from competitors.
Savino’s view is that lowered pricing are enabling smaller businesses to access coverage. “Premiums right now are very attainable by the insured,” he told Insurance Business. “Because there’s a tremendous amount of new business opportunity, I think you’ll continue to see a lot of competition in this space.”
With pricing already relatively inexpensive, brokers have more room to scrutinize what clients are receiving rather than treating another rate reduction as the primary renewal objective.
AI is becoming one of those areas. Insurers are increasingly asking about clients’ AI use, exposures and controls, while third-party software and vendor dependency remain among underwriters’ leading concerns.
Spinks said brokers should establish how clients are deploying AI, what governance surrounds its use and whether policies respond affirmatively to related losses.
“Proactive capabilities should also be a key consideration at renewal,” he said. “Effective cyber insurance today is not just about paying claims after an incident. Prevention, threat monitoring and proactive risk management are equally important.”