// Cyber

Frequency up, severity up, loss ratio up. Price down.

Everyone in this line is already living that contradiction. Underneath it sits a question that is not a question: do you have MFA? A firm with MFA on webmail only, and nothing on VPN, RDP, cloud admin consoles, service accounts or privileged access, answers yes. That is also exactly where ransomware enters.

The market has moved from attestation to evidence. Most underwriting workflows have not.

// The situation

Eight quarters of rate reductions into a rising loss ratio.

Cyber rates fell for an eighth consecutive quarter through Q1 2026, a fourth consecutive year of declines, while the loss ratio reached 53 in 2025 — the first reading above 50 since the ransomware spike of the COVID era.

Rate: CIAB Commercial P/C Market Index, Q1 2026. Loss ratio: 2025 statutory results, reported 2026.

A softening market does not reduce the verification burden. It moves it: the same self-attested application, fewer hours per submission to check it. So the first build reconciles what the applicant answered against what their own systems export, before the quote rather than after the claim.

// The stack you actually run

No ACORD form, and no shared definition of a control.

The 2026 standard, stated in the terms an underwriter can verify.

MFA on email, on remote access including VPN and RDP, on cloud administrative consoles and on all privileged accounts, with SMS codes increasingly rejected in favor of phishing-resistant methods. EDR on servers and workstations rather than a subset, with a preference for managed detection and response, because an agent nobody is watching at 2am on a Saturday is decorative. The claims data is why: 70% of ransomware claims involved both exfiltration and encryption, at roughly twice the cost of encryption alone, and ransom demands rose 47% year over year to exceed $1M while 86% of businesses refused to pay.

Coalition 2026 Cyber Claims Report — vendor research.

// The build

Four builds, and what each one is measured on.

01

Application-to-evidence reconciliation

Read the questionnaire answer, then read the identity-provider enrollment export, the EDR coverage report and the restore-test record, and reconcile them. Does the MFA exemption list contain a domain admin? Does EDR coverage match the asset count? Was the restore test run against a current snapshot? Underwriting inputs here are self-attested and the verification burden falls on a human who usually does not have the hours.

Surface: the submission document store plus IdP, EDR and backup exports, into the underwriting file as a reconciled control record.

02

Portfolio dependency mapping

Extract vendor and dependent-business-interruption schedules across the book and surface shared exposure to a cloud region, an EDR vendor, a managed service provider or a managed file-transfer product. An inventory rather than a model, and the thing nobody actually has: you cannot model a correlation you cannot enumerate.

Surface: bound-policy documents into a portfolio dependency register, refreshed at renewal.

03

Outside-in scan integration, framed correctly

Ingest BitSight, SecurityScorecard or similar findings as a negative signal in triage, with the interpretation built into the interface rather than left to the underwriter to remember. A bad score reliably predicts bad hygiene. A good score tells you very little, and the interface says so on the tin.

Surface: scan vendor API into the triage queue, stored as a signal with its polarity recorded.

04

War exclusion clause identification at bind

War exclusion wordings are not interchangeable. LMA5567A carries attribution mechanics requiring objectively reasonable evidence including formal government attribution; 5567B omits attribution guidance entirely, which leaves the burden on the insurer. Chubb, Beazley and Marsh have adopted compliant variants with subtle definitional differences. A clause-identification check at bind reads which wording is attached and records it. Small build, large downside avoided.

Surface: the bound policy document set, out to a clause register on the policy record.

What we measure

Share of application answers reconciled against an evidence artifact rather than accepted as attested. MFA coverage expressed as enrolled privileged accounts over total privileged accounts, broken out by access path rather than as a single yes. EDR coverage as agents reporting over assets in inventory. Count of distinct single points of failure enumerable across the book, and the share of the book exposed to the largest one. Share of bound policies whose war exclusion wording is identified by clause number in the policy record. Definitions and baselines, set in the first week.

// We ran one of these

We ran the security and vendor-dependency side of a regulated carrier as an operating obligation with an examiner attached, which is the same evidence problem a cyber submission poses from the other side of the desk — the difference between an attestation and a record.

The operating record →

// What's hard about this

Two limits, and what we do about each.

Outside-in scanning measures the wrong surface.

Security ratings observe the internet-facing perimeter: open ports, TLS configuration, patch cadence on public assets, leaked credentials. Ransomware overwhelmingly enters through phishing, stolen credentials and remote access, which are largely invisible from outside. A bad score reliably predicts bad hygiene; a good score tells you very little. So the scan gets integrated and labeled as what it is — a negative signal, its polarity recorded in the data model and stated in the interface — and the positive case is carried by the evidence artifacts described above, because presenting a good score as a positive signal is how a portfolio gets mispriced with high confidence.

Severity and aggregation prediction do not work here.

The loss distribution is dominated by rare correlated events with no historical analog. You cannot train on eight CrowdStrikes when there has been one. The industry could not agree within a factor of three on what that one cost: CyberCube estimated up to $1.5B of insured loss, while Parametrix put it at $540M to $1.08B.

CyberCube and Parametrix estimates, 2024 — both vendor research, and the spread is the point.

That was a single-vendor, non-malicious event with a known cause and a fast fix. Ransom payments show the same distributional problem from the claims side: in Q2 2026 the average payment was $1,880,612, up 176% from Q1, against a median of $150,000, down 50%.

Coveware, Q2 2026 — vendor research; use both numbers or neither.

A few enormous payments against a collapsing payment rate is not a distribution a model fits. What replaces the severity model is enumeration: the dependency register above makes correlated exposure countable, which is a lower claim than a prediction and a defensible one.

// What ships with it

The governance file, with privilege left intact.

Model inventory entry, data lineage from control evidence to underwriting decision, pre-deployment testing results, drift thresholds with remediation triggers, and a named human decision-maker specification — because regulatory responsibility does not transfer to a vendor, and Iowa’s bulletin formally defines the bias and outcomes testing that has to sit behind it. Two additions here: the clause register, recording the war exclusion wording attached to each bound policy, and a claims design constraint — nothing we build changes who holds the privileged document, because the forensic report is retained through breach counsel for a reason.

NAIC and state bulletins · current at September 2026.

Cyber is fundamentally a surplus lines business, with non-admitted markets writing close to two-thirds of premium, so the compliance machinery on the excess and surplus page applies to most of what you bind here.

Bring us one submission and its evidence.

We will tell you which controls your submissions can actually evidence, and which are attestations.