Boldly Reimagined
From the firm

Your renewal packet is about ransomware. Your claim probably will not be.

Cyber insurance · August 1, 2026

Business email compromise and funds transfer fraud made up 58% of cyber insurance claims last year. Ransomware took the headlines and most of the renewal questionnaire. The controls that satisfy an underwriter and the controls that prevent your most likely claim overlap less than almost anyone assumes.

Coalition insures small and mid-size companies and settles their claims, which makes its annual claims report one of the few places where a business this size can see what actually happens rather than what a vendor says will happen. The 2026 edition, covering all of 2025, is worth reading against your own renewal packet.

Business email compromise and funds transfer fraud together accounted for 58% of cyber incidents. Funds transfer fraud alone was the second most common event at 27% of claims, with an average loss of $141,000, and 52% of those cases started with a compromised email account. Ransomware demands did rise sharply, up 47% year over year, but 86% of businesses refused to pay and the average ransomware loss came in at $269,000 (Coalition 2026 Cyber Claims Report).

Read that again with a renewal questionnaire in front of you. Most of the questions are about endpoint protection, backups, segmentation and privileged access. Almost none are about whether your controller can wire $400,000 on the strength of an email.

Why the questionnaire looks the way it does

This is not carrier incompetence. An underwriter is pricing the worst plausible loss, not the most likely one. Catastrophic ransomware is what threatens their capital, so that is what the packet interrogates. Frequency of moderate losses is priced into the premium and largely accepted.

Your position is the opposite. You do not care much what threatens the carrier's capital. You care about the event that is most likely to hit your quarter. The renewal packet is a reasonable proxy for the first question and a poor one for the second, and companies that treat passing it as the whole security program have answered a question nobody asked them.

Both jobs, done separately

Job one is passing the renewal, and it now runs on evidence. Attestation is no longer the currency. Marsh reports that carriers now treat a defined set of twelve cyber hygiene controls as essential, and underwriters increasingly want to see the artifact rather than the checkbox (Marsh US cyber insurance market update). A sign-in log export, a screenshot of the enforced policy, a dated restoration test result, an offboarding record. The work is assembly, not transformation, and the companies that struggle at renewal are usually the ones assembling it in the last two weeks.

Job two is preventing the claim you are actually likely to file, and almost none of it is technology spend:

The line at $100 million

One finding in the report deserves its own paragraph. Companies above $100 million in revenue experienced claims frequency five times higher than smaller organizations. Growth changes the exposure profile, and it does so faster than most companies update their controls, because the controls were designed for the company they were three years ago. If revenue has grown substantially since the last real review, the renewal packet is not the only thing that is out of date.

The part that should be reassuring

64% of Coalition's closed claims resolved with no out-of-pocket loss to the policyholder, and overall claim severity fell 19% year over year to an average of $116,000. Cyber insurance, bought properly and backed by controls that are real rather than attested, works. The failure mode is not the policy. It is discovering at claim time that an answer on the application was aspirational.

Which is the honest reason to take the renewal seriously. Not because the questionnaire is a good security program, but because an overclaimed answer becomes a coverage argument on the worst day of the year.

Two weeks of assembly ahead of renewal is what Insurance Renewal Readiness exists for, and what carriers now ask for covers the requirements themselves question by question.