The soft market in cyber insurance has created a convenient myth: that falling rates reflect a maturing market rewarding better controls. Underwriters and actuaries know better. The 2% quarterly rate decline in Q2 2026 wasn't driven by a sudden outbreak of cybersecurity excellence. It was driven by capacity, capital, and competition. With the US cyber insurance loss ratio climbing to 53% in 2025, the gap between pricing and risk is becoming clear.
These myths persist because they're convenient. Carriers want to believe their underwriting discipline is holding. Brokers want to tell clients their security investments are paying off in premium savings. But the data tells a different story. Understanding that story is how you avoid pricing yourself into a corner.
Myth 1: Rate reductions reflect improved cybersecurity posture across the insured base
Reality: Additional carrier capacity and abundant capital explain most of the price movement. Michael Spinks, head of SME cyber at CFC, stated that improvements in insureds' cybersecurity alone do not explain how far pricing has moved. When more than 90 insurers participated in Aon's cyber placements during 2025, it was a capacity game, not a risk-quality game.
If you're underwriting as though every 5% rate decrease corresponds to a 5% improvement in controls, you're mispricing. The actual control improvements are incremental. The pricing pressure is structural. You need independent validation of security maturity, not assumptions that price reflects quality.
Myth 2: The soft market will continue indefinitely because cyber is "different"
Reality: Cyber insurance is roughly 25 to 30 years old, according to Keith Savino, CEO of Emergence US. That makes it young, not exempt from insurance cycles. Property and casualty lines went through the same swings. The difference is that cyber still has a massive uninsured market. A Morning Consult survey found just 24% of US small-business owners carried cyber insurance.
That untapped market is keeping competition alive, but it doesn't suspend gravity. Loss ratios are already moving the wrong direction. The 4.3 percentage point increase to 53% in 2025 was the second consecutive annual rise and the first time the ratio exceeded 50% since the pandemic ransomware surge. Surplus lines carriers, which now account for almost two-thirds of cyber premium, are running a 55.9% incurred loss ratio.
You can grow into new accounts without taking share from competitors, but you can't ignore frequency-severity trends while doing it. The floor exists. You're just pricing closer to it than you think.
Myth 3: All industry segments are equally well-priced at current rate levels
Reality: Rate adequacy varies considerably between industries. Spinks noted that in some US industry segments, additional rate may be needed to accurately reflect exposure levels, while in others that may not be necessary. This isn't a blanket market. It's a segmented one where healthcare, manufacturing, and financial services face different threat profiles and different control baselines.
If you're applying uniform rate adjustments across your book, you're subsidizing high-risk segments with low-risk ones. The actuarial work needs to happen at the segment level. Aggregation Exposure Analysis should account for industry-specific attack patterns, not just limit concentrations. A municipal government and a software-as-a-service provider both buy $5 million limits, but their loss potentials are not equivalent.
Myth 4: Pricing is the primary value conversation at renewal
Reality: Marsh reported that obtaining further reductions increasingly required brokers to approach a broader range of markets. That's a signal. When rate movement requires more effort for smaller gains, the conversation shifts. Around 19% of Aon's US cyber liability buyers purchased additional limits during 2025. They used soft conditions to strengthen programs, not just reduce spend.
For underwriters, this creates an opening. If you're competing solely on price, you're in a race to the bottom with 90+ other carriers. If you're differentiating on coverage breadth, incident response quality, or proactive monitoring, you have a defensible position. Spinks emphasized that effective cyber insurance today is not just about paying claims after an incident. Prevention, threat monitoring, and proactive risk management are equally important.
Build that into your offering. Pre-breach services, threat intelligence feeds, and access to vetted breach coaches aren't add-ons. They're underwriting controls that reduce your loss exposure while creating policyholder value that price-focused competitors can't match.
Myth 5: AI is a distant concern that can be addressed in future underwriting cycles
Reality: Insurers are already asking about clients' AI use, exposures, and controls. This isn't speculative. It's happening in Underwriting Questionnaires now. Third-party software and vendor dependency remain among underwriters' leading concerns, and AI sits at the intersection of both.
You need to establish how clients are deploying AI, what governance surrounds its use, and whether your policy language responds affirmatively to related losses. If your forms are silent on AI-related incidents, you have an ambiguity problem. If you're not collecting data on AI adoption during underwriting, you can't model the exposure.
The gap between AI deployment and AI-specific underwriting guidance is where your next adverse development will come from. Close it before the claims arrive.
What to Do Instead
Stop treating rate as the only lever. You're underwriting a risk class where 76% of the small-business market remains uninsured, loss ratios are climbing, and capacity is abundant but not infinite. That combination creates opportunity, but only if you differentiate on something other than price.
Focus your underwriting on segment-specific risk factors. A 2% rate reduction across your entire book ignores the reality that some industries need rate increases. Use your claims data to identify which segments are driving losses, then price accordingly.
Integrate proactive services into your value proposition. Incident prevention capabilities reduce your loss costs while creating policyholder stickiness. When renewal conversations move beyond rate, you want something substantive to discuss.
And collect better data on emerging exposures. AI, vendor dependencies, and third-party software risks are already influencing claims. If you're not capturing that information during underwriting, you're flying blind. The soft market won't last forever, but the exposures you're writing today will.





