A more competitive cyber insurance market does not mean cyber risk has disappeared.

October is Cybersecurity Awareness Month, making this a timely opportunity for businesses to review both their cybersecurity practices and the insurance coverage that may respond when a cyber incident occurs.

The 2026 theme for Cybersecurity Awareness Month is “Don’t Make It Easy for Them,” with an emphasis on practical habits such as using strong passwords, enabling multifactor authentication, recognizing and reporting scams, and keeping software updated. National Cybersecurity Alliance

At the same time, cyber insurance market conditions have become more competitive. The Council of Insurance Agents & Brokers reported an average 3.2% decrease in cyber premiums in Q2 2026, marking the ninth consecutive quarter of average decreases for the line. The Council of Insurance Agents & Brokers

That does not mean the underlying exposure has gone away.

The FBI’s 2025 Internet Crime Report included more than one million complaints of suspected internet crime and reported losses exceeding $20 billion. Ransomware, business email compromise, phishing, data breaches, and other forms of cybercrime continue to create financial and operational risk for businesses. FBI 2025 Internet Crime Report

For businesses reviewing cyber insurance in 2026, the question should not simply be whether premiums have gone down.

The more important question is whether the coverage reflects how the business operates today and how a cyber incident could affect it.

Cyber Insurance Is Not One Standard Policy

Cyber coverage can vary significantly from one insurer and policy form to another.

The National Association of Insurance Commissioners notes that cyber policies are highly customized, while most commercial property and general liability policies do not cover cyber risks. National Association of Insurance Commissioners

That makes it important to review the actual policy rather than assume the phrase “cyber insurance” means every cyber-related loss will be covered.

A business may face costs involving system restoration, forensic investigation, legal counsel, customer notification, business interruption, cyber extortion, fraud, regulatory response, or claims made by customers and other third parties.

Whether and how those costs are covered depends on the specific policy.

Review First-Party Cyber Coverage

One of the first areas to review is what happens to the business itself after an incident.

The Federal Trade Commission explains that first-party cyber coverage may address expenses such as forensic investigation, restoration of lost or compromised data, customer notification, legal assistance, crisis management, business interruption, cyber extortion, and certain fraud-related losses. Federal Trade Commission

For a business, several of those expenses can develop at the same time.

A cyber incident may shut down systems while outside specialists investigate the cause, data is restored, customers are notified, and the business works to resume normal operations.

The policy should be reviewed to understand which expenses are covered, what limits apply, and whether particular categories are subject to separate sublimits or conditions.

Business Interruption Can Be a Major Exposure

A cyberattack does not have to damage physical property to disrupt a business.

A ransomware incident, system compromise, or network outage can prevent employees from accessing files, processing transactions, communicating with customers, scheduling work, or using systems necessary to operate.

Businesses should understand how their cyber policy addresses business interruption, including the event that must trigger coverage, any applicable waiting period, the method used to calculate covered income loss, and how long coverage may continue.

Third-party technology should also be considered.

Many businesses rely on cloud providers, software platforms, payment processors, outsourced IT providers, and other vendors. An incident involving one of those providers can create operational problems even when the business’s own network was not the original target.

The FTC recommends checking whether a cyber policy addresses cyberattacks involving data held by vendors and other third parties. Federal Trade Commission

Businesses that rely heavily on outside technology providers should review how their specific policy treats those dependencies and whether separate terms, conditions, or sublimits apply.

Ransomware Coverage Should Be Understood Before an Attack

Ransomware continues to be a significant cyber threat.

The FBI received more than 3,600 ransomware complaints in 2025, with reported losses exceeding $32 million. The FBI also cautions that those reported loss figures generally do not include many additional costs such as lost business, lost time, wages, files, equipment, or third-party remediation services. FBI Internet Crime Complaint Center

Businesses should understand their policy’s treatment of cyber extortion before an incident occurs.

That includes reviewing applicable limits or sublimits, insurer notification requirements, consent requirements, incident-response vendors, and the procedures the business is expected to follow after discovering an attack.

Because policies may include notice, consent, and incident-response requirements, businesses should understand those provisions before an incident occurs and follow the applicable reporting procedures after a loss.

Social Engineering and Funds Transfer Fraud Deserve Separate Attention

Not every cyber loss begins with someone hacking into a server.

An employee may receive what appears to be a legitimate email from an executive, vendor, customer, or financial institution. The message may request a change in banking information, an urgent wire transfer, or access to sensitive information.

That can result in a substantial financial loss without the type of network intrusion businesses traditionally associate with a cyberattack.

Businesses should review whether social engineering, fraudulent instruction, business email compromise, and funds transfer fraud are addressed by their insurance program and whether separate limits, conditions, or coverage forms may apply.

Cyber and crime coverage can respond differently depending on the policy and circumstances, so the existence of one policy should not be treated as confirmation that every form of electronic fraud is covered.

Third-Party Liability Also Matters

A cyber incident can create expenses beyond restoring the company’s own systems.

Customers, employees, vendors, regulators, or other parties may allege that the business failed to properly protect information or otherwise caused them harm.

Third-party cyber coverage is generally intended to address certain liabilities and associated defense costs arising from these types of claims, subject to the policy’s terms and conditions. The FTC identifies potential third-party expenses such as litigation, regulatory inquiries, settlements, and claims brought by people affected by a breach. Federal Trade Commission

Businesses that maintain customer information, employee information, payment data, confidential business records, or other sensitive information should understand both the first-party and third-party sides of their cyber program.

Security Controls Still Matter

More favorable insurance pricing should not reduce the attention businesses give to cybersecurity.

Security controls can reduce the likelihood or impact of an incident, and insurers may also consider a business’s controls when evaluating a cyber risk. Specific underwriting questions and requirements vary by insurer.

For Cybersecurity Awareness Month, businesses can start with several practical measures:

These measures are consistent with guidance from the National Cybersecurity Alliance, CISA, and the Federal Trade Commission.

Know Who to Call Before You Need Them

A cyber incident is not the ideal time to determine who should be contacted first.

Businesses should know where the policy is located, how to report an incident, whether the carrier maintains a 24-hour breach hotline, and whether specific forensic, legal, or incident-response providers are required or available through the policy.

The FTC specifically recommends considering whether a cyber insurer provides a breach hotline that is available around the clock. Federal Trade Commission

The incident-response plan should also identify internal decision-makers and outside resources so the business is not trying to build a response team while its systems are unavailable.

Review Limits, Sublimits, and Retentions

The policy’s overall limit is only part of the coverage discussion.

Certain exposures may have separate limits or sublimits. Depending on the policy, these could include cyber extortion, social engineering, fraudulent transfers, business interruption, dependent business interruption, data restoration, regulatory costs, or other expenses.

Businesses should also understand applicable deductibles or retentions and whether different parts of the policy use different amounts.

A $1 million cyber policy, for example, should not automatically be interpreted as providing $1 million for every type of cyber loss.

The actual policy language determines how coverage applies.

A Softer Cyber Market Can Be an Opportunity to Review Coverage

Cyber premiums averaged lower in Q2 2026, but businesses should not treat a lower renewal premium as evidence that cyber exposure has become less important.

Instead, more competitive conditions may create an opportunity to evaluate the insurance program more closely.

That means comparing not only premium, but also limits, sublimits, retentions, exclusions, incident-response resources, business interruption provisions, third-party coverage, and security requirements associated with the policy.

RAM Risk Group previously noted the broader shift in its 2026 commercial insurance market review, where cyber was among the coverage lines reporting average premium decreases even as commercial auto and umbrella remained under greater pricing pressure.

The objective should be to understand what protection the business actually has before a cyber event tests the policy.

Reviewing Your Cyber Risk or Commercial Insurance Program?

Cyber insurance should be considered as part of a broader risk-management strategy, not as a replacement for cybersecurity controls.

Businesses should periodically review how their technology, employees, vendors, operations, and data have changed and whether their insurance program continues to reflect those exposures.

RAM Risk Group works with businesses to evaluate commercial insurance programs and identify coverage options based on their operations and risk profile.

Call (561) 206-4733, email service@ramriskgroup.com, or use the RAM Risk Group contact form to discuss your commercial insurance needs.

This article is provided for general informational purposes only and is not legal, cybersecurity, financial, or individualized insurance advice. Insurance availability, pricing, terms, conditions, exclusions, limits, sublimits, and coverage vary by insurer and risk. Businesses should review their specific cybersecurity practices with appropriate technology professionals and their insurance coverage with a licensed insurance professional.