CYBER CLAIMS STUDY

2026 REPORT

Quotes From Our Sponsors

Once again, the NetDiligence Cyber Claims Study found enormous variations in the magnitude of loss data. The dramatic differences between losses for SMEs as compared with losses for large companies reflect the vast risk in the online criminal ecosystem. Many losses likely resulted from opportunistic criminal activity while some massive losses resulted from targeted sophisticated criminal activity. As AI becomes an equalizer between unsophisticated criminals and sophisticated criminal organizations, the number of claims and relative losses for SMEs will likely increase substantially, while large companies will continue to be targeted—but will likely experience significant increases in both the magnitude of losses and sophistication of attacks. The cyber insurance landscape will continue to provide a unique lens into the management of this unprecedented risk.

Sean B. Hoar

Constangy Cyber

Cyber incidents can quickly become enterprise-wide crises impacting an organization’s reputation and revenue. The organizations that respond most effectively are those that have already established a response team, practiced their response plan, and know how they will communicate with employees, customers, and other stakeholders when an incident occurs.

Michael Bruemmer

Experian

We’ve started seeing more employees trying on their developer hat and testing AI tools that plug straight into corporate data infrastructure. Data governance usually isn’t keeping up with that. In conversations across the cyber insurance ecosystem and with clients, the same theme keeps coming up: AI governance is becoming a bigger part of how risk gets assessed, and from what we’re hearing, it’s likely to influence how coverage gets written and how policies match up to actual exposure. Companies that don’t put real governance and controls around AI now are setting themselves up for bigger failures down the road.

Rich Servilas

RSM US, LLP

For an SME, the cost of a cyber incident depends not just on whether an attack succeeds, but on how much of the environment requires rebuilding and how long the business stays disrupted. Backups can dramatically reduce recovery time and data-reconstruction costs, provided they are isolated, current, and tested. Multi-factor authentication reduces the likelihood that stolen credentials escalate into a broader compromise, limiting an incident’s potential scale. Separating Active Directory and critical environments can further contain an attacker’s movement and reduce the number of systems requiring investigation or rebuilding. Together, these controls reduce not only cyber risk but also the severity, duration, and cost of recovery when an incident occurs.

Karla Reffold

Surefire Cyber

© 2026 NetDiligence All Rights Reserved.