Cyber

What Insurance Buyers Need to Know about the Cyber Liability Outlook

Here is the current picture for a Michigan business shopping for cyber coverage. After two years of falling prices, the cyber insurance market is firming again. Underwriters still expect to see basic security controls before they will offer terms, and the cost of an actual breach keeps climbing. Planning ahead and talking with a local agent early is how you keep renewal from becoming a surprise.

The last time we wrote a full outlook on this coverage, the market was in the middle of a hard stretch and rates were climbing fast. A great deal has changed since. Below is where things actually stand now, what carriers are looking at, and the handful of steps that make the biggest difference when your policy comes up for renewal.

Where does the cyber insurance market stand right now?

Softer than it was, but starting to turn. After the sharp increases of 2021 and 2022, competition returned and prices came down. Marsh reported that US cyber insurance rates fell about 5% on average in the fourth quarter of 2024 (Marsh US Cyber Insurance Market Update), and reinsurance pricing dropped even further heading into 2026.

That softening may not last. S&P Global Ratings has projected cyber premium increases in the range of 15% to 20% for 2026, pointing to rising claim severity and the growing role of AI in attacks (reported cyber market analysis). For a business owner, the practical takeaway is simple: if you locked in a favorable rate during the soft market, expect underwriters to look harder at renewal, and do not assume last year's price carries forward.

Why does a breach cost so much, even for a smaller business?

Because the expensive part is rarely the ransom itself. It is the forensics, the legal and notification work, the downtime, and the days or weeks a business spends putting itself back together. IBM's 2025 Cost of a Data Breach Report put the global average cost of a breach at $4.44 million and the US average at an all-time high of $10.22 million, with organizations taking an average of 241 days to identify and contain an incident (IBM Cost of a Data Breach Report 2025).

Those are large-organization averages, and no small business in Alpena or Gaylord is going to see a ten-million-dollar bill. They matter because of the shape of the loss, not its size. Even a modest incident brings the same categories of cost. The FBI's Internet Crime Complaint Center logged more than $16 billion in reported cybercrime losses in 2024, up 33% from the year before, with business email compromise alone accounting for $2.77 billion across roughly 21,000 complaints (FBI 2024 Internet Crime Report). Business email compromise, where someone impersonates a vendor or an owner to redirect a payment, is the exposure that hits small Michigan businesses most often, and it usually starts with a single convincing email.

What do underwriters want to see before they will quote you?

Basic security controls have become the price of admission. A carrier that would have quoted almost any applicant a few years ago now asks a detailed set of questions first, and weak answers can mean higher pricing, lower limits, or no offer at all. Coverage is always subject to underwriting, but having these controls in place puts you in a much stronger position:

  • Multifactor authentication (MFA) on email, remote access, and administrator accounts. This is the single control carriers ask about most.
  • Endpoint detection and response (EDR) or comparable security software on company devices.
  • Tested, offline backups of critical data, so a ransomware attack does not leave you with no way back.
  • Employee training on phishing and wire-transfer fraud, documented and repeated rather than a one-time slideshow.
  • A written incident response plan that names who to call and what to do in the first hours.
  • Prompt patching of software and a process for retiring outdated systems.
  • Payment verification procedures, such as a call-back rule before changing any vendor's bank details, which stops most business email compromise losses cold.

What actually drives your cyber premium?

Several factors, most of them specific to your business:

  • Your industry. A medical practice or a firm that stores customer payment data carries different exposure than a landscaping company.
  • Your size. More revenue, more customer records, and more transactions generally mean more exposure and a higher premium.
  • The coverage you choose. Limits, sublimits, and whether items like business interruption and social engineering sit inside or outside your main limit all move the number.
  • Your claims history. Prior incidents make underwriters look more closely.
  • Your controls. The security measures above are not just underwriting hurdles; they can genuinely affect what you pay and how much risk you keep yourself through a deductible.

What can you do before your renewal?

Start early and come prepared. The businesses that get the best outcomes treat the renewal as a project rather than a form to sign at the last minute. Here is what to have ready before you call an agent:

  • Your current cyber policy, including limits, sublimits, and deductible.
  • A short description of the data you hold, such as customer records, payment information, or health information, and roughly how much.
  • Your honest answers to the controls list above, including anything you know is missing.
  • Any changes in the business since last year: new locations, new systems, remote staff, or a big jump in revenue.
  • Any past incident, even a near miss, and what you changed afterward.

Give yourself 60 to 90 days before the policy expires. That leaves time for an independent agent to take your information to more than one carrier, which is where otherwise similar businesses can end up with meaningfully different terms. As an independent agency, Top O' Michigan works with several cyber markets rather than a single company, so when one carrier's number comes back high, there is somewhere else to look.

Cyber coverage also does not stand alone. It usually sits alongside a business owners policy and the rest of your commercial program, and it is worth reviewing the whole picture together. If you are still sorting out what this coverage even does, our plain-language explainer on what cyber liability is is a good starting point, and our small-business cybersecurity guide for Michigan walks through the controls in more detail. For a real example, see how cyber insurance responded for a Michigan business facing a $27,000 loss.

Where to start

Cyber risk feels abstract until the morning it isn't. If you want someone to walk through your current coverage, tell you plainly where the gaps are, and shop it across our markets, that is exactly the kind of conversation our agents have every week. Coverage is not bound or changed until confirmed by an authorized representative, so the sooner you start, the more room there is to get it right.

Call Top O' Michigan at 800-686-8664, stop by an office such as our Gaylord location, or learn more about cyber liability coverage and reach out for a quote. Real people, right here in northern Michigan, who work with these policies every day.

Back to Insurance 101

Questions about your coverage?

Talk to a local Top O Michigan agent well help you make sense of it.