Reinsurance

Ransomware Severity After Security Control Decay in Cyber Treaties

On this page

How Decaying Security Controls Quietly Raise Ransomware Severity

A cedant that passed its security questionnaire eighteen months ago is not the same risk today, even if nothing on paper has formally changed. Controls that were fully deployed at binding tend to lose coverage quietly over time, and that decay is now showing up directly in ransomware severity data, not just in theory.

What Does Security Control Decay Actually Mean in a Cyber Treaty Context?

Security control decay means a control that was genuinely effective at the time of underwriting loses coverage or effectiveness as the environment around it changes. New systems get added, legacy applications persist longer than planned, and VPN or firewall configurations drift from their original secure state, all without any formal record of the control having failed.

This is fundamentally different from a control never being deployed at all, since decay implies the organization believed, correctly at one point, that the control was working. That belief becomes outdated as the environment evolves, and nothing in a standard annual attestation process necessarily catches the gap before an attacker does.

Why Does Decayed Control Effectiveness Raise Severity Rather Than Just Frequency?

Decayed controls raise severity because they let an attacker who gains initial access move further through an environment before being detected or stopped. A control gap on a secondary system, rather than blocking the attack outright, simply becomes the path an attacker uses to escalate a small foothold into a much larger incident.

This is why control decay shows up in severity data rather than frequency data specifically, the number of attempted attacks may stay roughly constant while the cost and impact of the attacks that succeed climbs. Underwriting models that only track frequency, without a corresponding severity-side view of control effectiveness, will miss exactly this shift until claims experience reveals it after the fact.

How Does 2026 Data Show This Pattern in Practice?

Sophos' 2026 State of Ransomware report, based on 2,158 organizations that experienced a ransomware attack in the prior year, found encryption succeeded in 56 percent of attacks, up from 50 percent the year before, even as exploited-vulnerability-based attacks fell 14 percentage points to 18 percent. That combination is the pattern in a single dataset, attackers succeeding at the technical encryption stage more often overall, while the traditional route into the network, unpatched vulnerabilities, actually declined in share.

The gap is being filled by identity-based approaches, which the same report found behind 79 percent of ransomware attacks, a category of attack vector that depends directly on whether authentication controls are consistently and currently enforced across every system, not just the primary ones.

What Does the MFA Coverage Gap Reveal About Control Decay Specifically?

It reveals a genuinely nuanced picture, since 97 percent of victims whose attack originated from compromised credentials actually had MFA enabled in some form at the time of the attack. The failure was not an absence of MFA as a control category, it was a coverage gap, with protection missing specifically on VPNs, firewalls, and legacy applications that had not been brought into the same MFA enforcement as the organization's primary systems.

That distinction matters enormously for underwriting, since "does the organization have MFA" is a fundamentally different, and much weaker, question than "does MFA cover every system that could provide an attacker a path inward."

Why Did Encryption Rates Rise Even as Overall Ransom Payments Fell?

Encryption rates and payment rates are measuring two different, independently moving parts of the same problem. Attackers are succeeding at the technical stage, encrypting data, more often than the year before, which is the control-decay story this diagnosis is built around.

Separately, victim organizations are becoming more willing to resist paying even after encryption succeeds, a distinct trend in organizational response rather than technical defense. A Ransomware Cost Trending analysis from Coveware found the average ransom payment jumped 176 percent to 1.88 million dollars in a single quarter even as the median payment fell and the overall payment rate hit a record low, showing severity concentrating in a smaller number of high-value cases rather than spreading evenly.

How Does This Differ From the Traditional View of Ransomware Risk?

The traditional underwriting view treats security controls as binary, present or absent at the point of application, verified once a year through a questionnaire or scan. This diagnosis treats control effectiveness as something that degrades continuously between those verification points, meaning the risk profile at claim time can differ meaningfully from the risk profile recorded at binding.

ViewTraditional modelControl-decay model
Control statusBinary, present or absentContinuous, degrades over time
Verification cadenceAnnual attestationRequires ongoing monitoring
Risk signal trackedFrequency of attacksSeverity given successful attack
Underwriting questionDoes the control exist?When was the control last verified everywhere?

Which Controls Decay Fastest, and Why Does That Matter for Underwriting?

Identity and access controls decay fastest, specifically MFA and access management coverage on secondary systems like VPNs, firewalls, and legacy applications that get added to an environment faster than security coverage is extended to include them. Endpoint protection and backup systems also decay, but typically more slowly, since they tend to be centrally managed rather than added piecemeal the way VPN endpoints and legacy application access often are.

A Security Posture Assessment AI Agent applied at renewal can specifically test coverage consistency across an environment rather than simply confirming a control category exists somewhere within it.

What Data Actually Helps a Reinsurer See Control Decay Before a Loss?

Continuous external attack-surface monitoring data, rather than point-in-time self-attestation, is the most practical way to see decay before it turns into a claim. This kind of monitoring can flag when a new system appears without the expected authentication controls, or when a previously covered system falls out of coverage as configurations change.

A Ransomware Exposure AI Agent built around this kind of continuous signal gives underwriting a materially more current view than an annual questionnaire ever could. The margin cost this severity increase creates is what ultimately justifies the investment in this kind of ongoing monitoring capability.

How Should This Diagnosis Change Renewal Underwriting Questions?

Renewal questions should shift from asking whether a control exists to asking when it was last verified across the full environment, including secondary and legacy systems, not just primary infrastructure. A cedant that can answer this specifically, with a recent verification date and defined scope, is a meaningfully different risk than one that can only confirm the control exists somewhere without specifying where coverage stops.

Does Organization Size Change How Much Control Decay Matters?

Yes, and the 2026 data shows a clear split by size, with only 34 percent of small organizations between 100 and 250 employees managing to stop an attack before encryption or extortion occurred, compared to 46 percent at larger firms. Smaller organizations typically have leaner security teams, which means a control gap that opens on a secondary system is less likely to be caught quickly before an attacker exploits it.

This size effect matters directly for underwriting a book with a meaningful share of smaller insureds, since the same control-decay diagnosis applies more severely to organizations least equipped to detect and close the gap quickly. A book weighted toward smaller cedants may need a more conservative severity assumption built into pricing than the same diagnosis would suggest for a book of larger, better-resourced organizations.

How Does Sector Matter for This Kind of Risk?

Sectors with a high proportion of legacy systems and slower technology refresh cycles, such as manufacturing, healthcare, and parts of financial services, tend to show the most pronounced control decay over time. These sectors often retain older applications for operational or regulatory reasons well beyond the point where modern authentication controls were designed to cover them.

A reinsurer with meaningful exposure concentrated in these sectors should weight control-recency questions even more heavily during underwriting, since the base rate of decay is structurally higher than in sectors with faster technology turnover. This is not a reason to avoid these sectors, but it is a reason to underwrite them with a more specific, current view of control coverage rather than relying on the same generic questionnaire used across the whole book.

What Early Warning Signals Suggest a Cedant's Controls Are Decaying?

A growing gap between an organization's total system count and its documented MFA or endpoint coverage count is the clearest early signal, even when the organization has not had an incident yet. Rapid infrastructure growth, mergers, or legacy system retention without a corresponding security coverage review are the operational conditions most likely to produce this kind of gap.

Reinsurers who wait for a severe claim to reveal control decay are pricing the risk after the fact. Building visibility into coverage consistency now, rather than assuming a binary control status holds steady between renewals, is what turns this into a known, manageable exposure rather than an unpriced surprise.

Sources

Frequently Asked Questions

What does security control decay actually mean in a cyber treaty context?

It refers to previously effective controls, such as MFA or endpoint protection, losing coverage or effectiveness over time as gaps open in legacy systems, VPNs, or unmonitored assets.

Why does decayed control effectiveness raise severity rather than just frequency?

Weakened controls let attackers move further before detection, so the same initial access produces a bigger, costlier incident rather than simply more frequent attempts.

How does 2026 data show this pattern in practice?

Encryption success rates rose to 56% even as exploited-vulnerability-based attacks declined, showing attackers are succeeding through gaps in identity and access controls instead.

What does the MFA coverage gap reveal about control decay specifically?

97% of credential-based attack victims had MFA enabled somewhere, but gaps remained on VPNs, firewalls, and legacy applications, showing partial control coverage rather than full decay.

Why did encryption rates rise even as overall ransom payments fell?

Attackers are succeeding at the technical encryption stage more often, while victim organizations are separately becoming more willing to resist paying, two independent trends moving in different directions.

How does this differ from the traditional view of ransomware risk?

Traditional underwriting treats security controls as binary, present or absent, while this diagnosis treats control effectiveness as something that degrades continuously after initial certification.

Which controls decay fastest, and why does that matter for underwriting?

Identity and access controls, especially MFA coverage on secondary systems like VPNs and legacy applications, decay fastest because new systems get added faster than coverage is extended to them.

What is the first practical step to diagnose this risk in an existing book?

Adding control-recency questions to renewal underwriting, asking not just whether a control exists but when it was last verified across the full environment.

Hitul Mistry

Hitul Mistry

CEO, Insurnest

An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.

View LinkedIn profile →
ShareLinkedInX

Read our latest blogs and research

Featured Resources

Reinsurance

Cloud Concentration Beyond Named Providers in Cyber Reinsurance

Cloud concentration beyond named providers hides aggregation risk inside shared backend services that policy schedules never list, leaving cyber and technology reinsurers exposed to losses they never priced.

Read more
Reinsurance

Emerging Risks Watchlist: The Perils Reinsurers Underwrite Next

A reinsurance watchlist of emerging perils — from AI and cyber to PFAS, climate, and biorisk — and how to underwrite risks without a loss history.

Read more
Reinsurance

The Return-on-Capital Erosion From Ransomware Severity Decay

Ransomware severity after security control decay is eroding return on capital by bunching losses at the high end of the severity distribution, even as overall attack frequency and payment rates decline.

Read more

Meet Our Innovators:

We aim to revolutionize how businesses operate through digital technology driving industry growth and positioning ourselves as global leaders.

circle basecircle base
Pioneering Digital Solutions in Insurance

Insurnest

Empowering insurers, re-insurers, and brokers to excel with innovative technology.

Insurnest specializes in digital solutions for the insurance sector, helping insurers, re-insurers, and brokers enhance operations and customer experiences with cutting-edge technology. Our deep industry expertise enables us to address unique challenges and drive competitiveness in a dynamic market.

Get in Touch with us

Ready to transform your business? Contact us now!