Human error drives most cyber breaches, yet many organizations still treat cyber risk as an IT problem. Cowbell's Cyber Roundup 2026 Claims Report argues that cyber resilience requires prevention, preparedness, response, and recovery built into overall organizational strategy. An AM Best report found premiums fell to $9.14 billion while claims rose 40 percent. Nurishah Knushaj, director of claims at Cowbell, explains what that gap means for organizations, brokers, and the future of cyber insurance.
Cyber resilience means building protection and recovery into the entire organization, not just the IT department. Cowbell's Cyber Roundup 2026 Claims Report frames resilience as going beyond what any single insurance policy can provide. Nurishah Knushaj, director of claims at Cowbell, put it directly: "While insurance remains an important financial safeguard, resilience today requires a combination of prevention, preparedness, response, and recovery." Organizations that treat cyber risk as a business concern, rather than a technical one, consistently outperform those that don't. Awareness training matters, but without prevention, preparedness, and response plans, it leaves organizations exposed when an attack occurs. Insurance, in Knushaj's view, should be one component of a broader strategy, not the whole plan.
The market is sending conflicting signals. An AM Best report found cyber insurance premiums declined for the first time to $9.14 billion, while claims rose 40 percent in the same period. Knushaj called the gap meaningful: "That divergence suggests that cyber risk is intensifying, even as market pricing remains highly competitive for the industry." She added that disciplined underwriting, proactive risk management, and claims expertise will determine which insurers remain viable long-term. The trend matters for every organization buying coverage: lower premiums may seem attractive, but a less disciplined market can produce worse outcomes when claims occur. In Knushaj's assessment, the health of the market depends on helping policyholders reduce losses, not simply transferring risk after an incident.
Human error contributes to most breaches, according to Cowbell's 2026 report. AI is making the problem worse by enabling more convincing phishing campaigns, business email compromise, and social engineering attacks at scale. Knushaj was clear on what organizations should do: "Technology and people must be viewed as complementary, not competing, investments. The Cowbell report found that human error remains a contributing factor in most breaches – underscoring that technology alone cannot solve cyber risk." She recommended building a culture of security awareness alongside foundational technical controls. Those controls include multi-factor authentication, endpoint protection, secure email technologies, and continuous monitoring. Organizations that invest in both people and technology are better positioned to stop attacks before they become full-scale incidents.
Experienced claims teams make a measurable financial difference when ransomware strikes. Cowbell's 2026 report found that effective claims handling can reduce average ransomware payments by approximately 44 percent. Proactive negotiations cut average ransom demands by as much as 65 percent. Knushaj described what organizations should expect from a best-in-class insurer: "I would say that the best-in-class cyber claims experience should provide immediate access to breach counsel, forensic investigation, ransomware negotiations, recovery specialists, and communications experts." Rapid engagement and coordinated decision-making across the entire incident life cycle, she added, are the standard to measure against. The objective is not simply paying a claim. It is helping organizations recover as quickly and effectively as possible, minimizing both financial and operational disruption.
Ransomware attackers have moved well beyond simple file encryption. Knushaj described the shift: "With encryption-optional attacks, many modern groups now completely skip the time-consuming and noisy encryption phase, meaning they rely purely on data exfiltration – stealing sensitive files and threatening to leak them on dedicated public shaming sites. We've seen multi-extortion frameworks recently – attackers maximizing leverage by applying layers of pressure." These frameworks range from single extortion, involving encryption only, to quadruple extortion, where attackers contact a victim's suppliers, clients, and partners directly. Akira is the most active group in Cowbell's 2026 data, responsible for 38.8 percent of incidents. Akira typically targets small and mid-sized enterprises through VPN exploitation, making unpatched remote access infrastructure a high-priority exposure.
Supply chain vulnerabilities, credential theft, and attacks targeting remote access technologies are among the highest-priority risks heading into the second half of 2026. AI-enhanced social engineering is making business email compromise harder to detect and significantly easier for attackers to scale. Knushaj identified the combination driving the most claims activity: "Supply chain vulnerabilities, credential theft, and attacks targeting remote access technologies will continue to present significant risks. Business leaders, I would say, should pay close attention to threats that combine technical compromise with human manipulation, because those attacks increasingly drive both frequency and severity of claims." Incident response planning, tested backup strategies, and third-party risk management are among the most effective controls organizations can implement against this threat combination.
Brokers need to move beyond placing policies and become educators on the full value a cyber insurer provides before, during, and after an incident. Knushaj was direct about the direction Cowbell is taking: "The most successful insurers will not simply indemnify losses after an incident; they will help organizations reduce the likelihood and impact of those incidents in the first place." Claims data gives insurers unique insight into what actually drives losses, allowing them to offer practical guidance on controls, training, risk monitoring, and preparedness planning. Organizations that invest in resilience, employee training, and strong security hygiene are likely to earn better coverage options and more favorable pricing over time. That outcome-focused message, Knushaj noted, is where brokers can add real value.
Nurishah Knushaj: director of claims, Cowbell; subject matter expert in ransomware negotiations, incident response coordination, and cyber underwriting trends; noted that claims have evolved significantly over the last several years to require simultaneous management of legal, forensic, regulatory, operational, and reputational challenges.