Cyber Insurance
Cyber insurance is adjacent to cybersecurity but shapes it directly: it is a third involuntary demand engine alongside threats and regulation, a consolidating industry in its own right, and increasingly an arena where insurers and security vendors converge, generating deal-adjacent M&A.
The chapter has several drill-downs: Market Structure, Carriers & MGAs covers the value chain (insured→broker→MGA→carrier→reinsurer), where the margin sits, ~$16B gross written premium (GWP) with the US at ~70%, the named carriers/MGAs/reinsurers/brokers, and the consolidation of the MGA layer; Active Insurance & the Insurer↔Vendor Convergence covers the active-insurance model, the Allianz–Coalition transition (May 6 2026), and the deal patterns where insurers and security vendors converge; Brokers & Distribution covers cyber brokers, the distribution tiers, broker economics, and distribution as a consolidation engine (Aon–NFP, Marsh–McGriff, Gallagher–AssuredPartners); Reinsurance, ILS & Capacity covers the capacity stack behind the carriers, cyber cat bonds (Beazley PoleStar Re ~$300M), and the capacity cycle; Systemic & Aggregation Risk covers correlated loss, the CrowdStrike accumulation event, war exclusions (Merck/Lloyd's), and the federal-backstop question; and Insurance as the Third Demand Engine covers how underwriting requirements (MFA-as-gate) convert loss experience into a controls mandate and a vendor demand pull, alongside threat and regulation.
Relevance to the business of cybersecurity
- It manufactures demand. Insurers, burned by the 2020–2022 ransomware loss spike, now require specific controls — MFA, EDR, tested backups, incident-response plans — as a condition of coverage or favorable pricing. The insurer is, in effect, a buyer behind the buyer, steering security purchases toward particular categories and even vendors (see How Buyers Buy / Demand, and the buyer chapter in the book). From the CISO's seat this makes the underwriter's control checklist a de-facto minimum baseline — the controls that must be in place to transfer any residual risk at all, and whose absence at claim time can jeopardize the payout.
- It is consolidating. Carriers, MGAs/insurtechs, brokers, and security vendors are circling one another; the boundary between insuring risk and reducing it is blurring ("active insurance").
- It re-prices the whole risk. Premiums, sub-limits, and exclusions transmit the threat economy's economics into corporate budgets — a real-time signal of how bad ransomware/BEC losses are.
Recent settlements illustrate the loss costs that feed this repricing. Per Wall Street research, in 1H 2026 Comcast established a $117.5M settlement fund over a 2023 breach affecting roughly 31.6M customers, and Flagstar Bank received preliminary approval for a $31.5M settlement over 2021 breaches — the kind of tail liabilities that underwriters translate into premiums, sub-limits, and controls requirements.
Market shape
- Size: GWP ~$15–16B and growing double digits, still a small fraction of the protection gap (most cyber risk remains uninsured).
- Loss experience: improved after the 2021 ransomware shock as insurers tightened underwriting and mandated controls; periodically pressured by large systemic events (e.g., widespread software-supply-chain or single-vendor outages — "aggregation risk" in insurance terms).
- Systemic-risk worry: a single widely used vendor failing (the insurance version of platform concentration) could trigger correlated claims — a live concern for carriers and reinsurers.
Key players
| Layer | Players |
|---|---|
| Cyber-native carriers / MGAs ("active insurance") | Coalition, At-Bay, Corvus (Travelers), Resilience, Cowbell, Measured |
| Traditional carriers w/ large cyber books | Beazley, AIG, Chubb, AXA XL, Zurich, Tokio Marine, CNA |
| Reinsurers | Munich Re, Swiss Re, Hannover Re (cyber is a growing/contested reinsurance line) |
| Brokers | Marsh, Aon, Gallagher, WTW, Woodruff Sawyer (cyber specialty practices) |
| Security vendors at the boundary | MDR/IR firms partnering with carriers; vendors offering warranties; carriers acquiring/partnering with security capability |
The convergence trend ("active insurance")
The defining dynamic: insurers no longer just pay claims — they actively reduce losses by bundling security monitoring, scanning, and incident response with the policy. Coalition and At-Bay built this model natively. The logic is identical to the cyber roll-up arbitrage: lower the losses you have to pay, and the economics improve. This pulls insurers toward owning or partnering with security capability — and pulls security vendors toward distribution through insurance.
→ Cross-references: demand engines (Threat Economy, Regulation); the buyer (03); systemic/aggregation risk mirrors platform concentration (01).
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.