Reinsurance

The Return-on-Capital Erosion From Ransomware Severity Decay

On this page

How Rising Ransomware Severity Erodes Cyber Reinsurance Return on Capital

A book can show a stable or even declining ransomware attack frequency and still deliver a much worse capital outcome than expected, simply because the attacks that do succeed are becoming more severe. That is the specific mechanism behind the return-on-capital erosion tied to security control decay, and it is a distinct problem from the frequency-side story most cyber pricing models were originally built around. Understanding this mechanism precisely is what separates a reinsurer that can explain a bad year to its board with data from one left guessing at causes after the capital hit has already landed.

Why Does Rising Severity Hit Return on Capital Harder Than Rising Frequency?

Capital models are generally far more sensitive to the tail of the severity distribution than to a moderate increase in the total number of claims. A modest rise in frequency spreads additional cost relatively evenly across the book, while a rise concentrated in severity produces a small number of much larger losses that disproportionately consume capital held against the tail.

This distinction matters because a reinsurer watching only frequency trends can reasonably believe the book is performing as expected, right up until a handful of severe claims land and reveal that the real driver of loss cost had shifted to severity all along.

How Much Has Average Ransomware Severity Actually Increased?

Average ransom payments jumped 176 percent in a single quarter, reaching 1.88 million dollars according to Coveware's Q2 2026 data, even as the median payment fell 50 percent to 150,000 dollars. That divergence between average and median is itself the signal, a small number of very large payments are pulling the average sharply upward while most incidents actually settle for less than before.

Recovery costs tell a related story from a different angle, with Sophos finding the average recovery bill reached 1.7 million dollars per incident in 2026, up 11 percent year over year, even as the median ransom demand itself fell 65 percent over two years. Severity, in other words, is increasingly a story about the cost of the incident overall, not simply the size of the ransom demand attackers are asking for.

What Does the Rising Encryption Rate Mean for Loss Ratio?

A higher encryption success rate, which Sophos found reached 56 percent of attacks in 2026, up from 50 percent the year before, means a larger share of incidents reach the most expensive stage of a ransomware event rather than being stopped at an earlier, cheaper stage. Every incident that reaches encryption carries recovery, downtime, and potential ransom costs that an incident stopped earlier simply does not incur.

Metric20252026Direction
Encryption success rate50%56%Up
Average recovery costLower baseline$1.7 million (+11% YoY)Up
Median ransom demandHigher baseline$698,000 (-65% over 2 years)Down
Average ransom payment (quarterly)Lower baseline$1.88 million (+176% QoQ)Up

How Does This Distort Capital Held Against the Book?

Capital calibrated against historical average severity understates what is actually needed once losses bunch more heavily at the high end of the distribution, since average-based capital models assume a smoother, more evenly spread distribution than the current data shows. A book holding capital based on last year's average severity figure is effectively under-capitalized against this year's more concentrated tail risk.

This distortion compounds for reinsurers who have not updated their severity assumptions to reflect the specific divergence between rising encryption success and falling median payments, since a naive read of "median payments are falling" alone would suggest improving, not worsening, capital adequacy.

What Happens to Reinstatement Economics When Severity Bunches at the High End?

Reinstatement provisions get triggered by a smaller number of larger losses rather than a steadier stream of moderate ones, which changes the underlying economics of how those layers were originally priced. A layer designed around an assumption of moderate, frequent losses can find itself exhausted faster than expected when the same aggregate loss cost arrives concentrated in fewer, larger events instead.

Does This Affect Excess-of-Loss Layers Differently Than Quota Share?

Yes, excess-of-loss layers sit directly exposed to severity concentration at the top of the distribution, since that is precisely the layer designed to absorb the largest individual losses. Quota share arrangements share the impact proportionally across the whole book instead, meaning the practical consequence of rising severity differs meaningfully depending on which structure a specific treaty uses.

How Should Pricing Respond to a Bifurcated Severity Distribution?

Pricing should explicitly model the distribution as bifurcated, reflecting a growing gap between typical and extreme outcomes, rather than relying on a single average severity assumption that understates the true tail. A Cyber Maturity Assessment AI Agent applied at the individual insured level can help identify which cedants are more likely to fall into the high-severity tail based on their actual control coverage, rather than treating the whole book as equally exposed to this shift.

Diagnosing where control decay is actually occurring in the book gives pricing teams a concrete basis for this bifurcation, rather than applying a blanket severity adjustment uniformly across insureds with very different underlying control postures.

What Is the Cost of Discovering This After a Bad Renewal Year?

Discovering this shift only after a renewal year with several severe claims means absorbing the capital hit before any pricing or wording adjustment has had a chance to respond to it. That is the most expensive possible sequence, an unpriced severity shift followed by a capital surprise, followed only afterward by the corrective pricing action that should have happened before the losses occurred.

Discovering the shift through current claims data and industry reporting, ahead of the next renewal, allows pricing, capital allocation, and reinstatement structuring to all adjust in advance of the loss experience actually landing.

How Does Recovery Cost Inflation Compound the Problem?

Recovery cost inflation, the 11 percent year-over-year rise in average recovery bills, compounds the ransom-payment side of severity rather than simply repeating the same cost in a different form. A claim now carries a higher forensic, remediation, and business-interruption cost even independent of whatever ransom amount is ultimately paid or refused.

This means total claim severity is rising from two separate directions at once, technical recovery cost and, in a smaller number of extreme cases, ransom payment size, both of which need to be captured in an updated severity model rather than tracked as a single blended figure.

What Tools Help Quantify the Capital Impact Before Renewal?

Scenario-based stress testing against current severity data, rather than reliance on multi-year historical averages that predate this shift, is the most practical near-term tool available. A Security Posture Assessment AI Agent run across the book can flag which insureds carry the control gaps most associated with high-severity outcomes, giving capital modeling a more granular input than a single blended book-wide severity assumption.

How Should Margin Targets Change to Reflect This Shift?

Margin targets should build in an explicit buffer for tail-severity events, reflecting the bifurcated distribution rather than the smoother historical pattern margin targets were originally set against. A target based purely on recent average experience will look comfortably achievable in most years and materially wrong in the specific year a handful of severe, control-decay-driven claims land.

That buffer does not need to be large to matter, since even a modest, deliberately reserved cushion changes the capital outcome significantly in the year severity concentration actually shows up in claims experience.

How Should Rate Adequacy Reviews Change Given This Shift?

Rate adequacy reviews should specifically test whether current rates were calibrated against pre-shift severity data, since a rate that looked adequate against last year's severity distribution may already be inadequate against this year's more concentrated tail. A standard annual rate review that only compares loss ratio to plan, without decomposing whether the underlying severity distribution has shifted, can miss this specific driver entirely, attributing any deterioration to generic "market conditions" rather than an identifiable, data-supported cause.

Building a specific severity-distribution check into the rate adequacy process, comparing the current bifurcation pattern against what current rates assume, gives actuarial and pricing teams a much sharper diagnostic than a generic loss ratio trend line alone.

What Does This Mean for Multi-Year Deals Priced Before This Shift?

Multi-year treaties priced before this severity shift became visible in the data carry a specific, quantifiable risk, since the rate was set against an assumption that no longer matches current claims experience. Reinsurers holding these positions should proactively model the gap between original pricing assumptions and current severity data, rather than waiting for the multi-year term to run its course before finding out how large the miss actually was.

Where contract terms allow a mid-term review or reset, this is exactly the kind of data that justifies invoking it, since the case for adjustment rests on concrete, verifiable severity data rather than a subjective reassessment of appetite.

Sources

Frequently Asked Questions

Why does rising ransomware severity hit return on capital harder than rising frequency?

Because capital models are generally more sensitive to the tail of the severity distribution than to a moderate increase in the number of claims, so severity growth flows through disproportionately.

How much has average ransomware severity actually increased?

Average ransom payments jumped 176% in a single quarter to 1.88 million dollars, while average recovery costs reached 1.7 million dollars, up 11% year over year.

What does the rising encryption rate mean for loss ratio?

A higher encryption success rate, up to 56% of attacks, means a larger share of incidents reach the costliest stage of a ransomware event rather than being stopped earlier.

How does this distort capital held against the book?

Capital calibrated against historical average severity understates what is needed once losses bunch more heavily at the high end of the distribution.

What happens to reinstatement economics when severity bunches at the high end?

Reinstatement layers get triggered by fewer, larger losses rather than a steady stream of moderate ones, changing the economics of how those layers were originally priced.

Does this affect excess-of-loss layers differently than quota share?

Yes, excess-of-loss layers are directly exposed to severity concentration at the top of the distribution, while quota share shares the impact proportionally across the whole book.

How should pricing respond to a bifurcated severity distribution?

By modeling the distribution explicitly as bifurcated, rather than using a single average severity assumption that understates the true tail risk.

What is the fastest way to quantify the capital impact before the next renewal?

Stress-testing the book against the current bifurcated severity data, rather than relying on prior years' average-severity assumptions.

Hitul Mistry

Hitul Mistry

CEO, Insurnest

An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.

View LinkedIn profile →
ShareLinkedInX

Read our latest blogs and research

Featured Resources

Reinsurance

Ransomware Severity After Security Control Decay in Cyber Treaties

Ransomware severity after security control decay is emerging as a distinct executive risk, since decaying controls raise the cost and impact of each attack even when overall attack frequency stays flat.

Read more
Reinsurance

The CUO's Decision Framework for Ransomware Severity Risk

Ransomware severity after security control decay forces CUOs to decide how quickly to invest in control-recency verification, before the next renewal cycle prices another year of decayed controls blind.

Read more
Reinsurance

The Margin Cost of Cloud Concentration Beyond Named Providers

Cloud concentration beyond named providers turns one shared outage into many simultaneous claims, quietly eroding margin and distorting capital allocation across cyber and technology reinsurance books.

Read more

Meet Our Innovators:

We aim to revolutionize how businesses operate through digital technology driving industry growth and positioning ourselves as global leaders.

circle basecircle base
Pioneering Digital Solutions in Insurance

Insurnest

Empowering insurers, re-insurers, and brokers to excel with innovative technology.

Insurnest specializes in digital solutions for the insurance sector, helping insurers, re-insurers, and brokers enhance operations and customer experiences with cutting-edge technology. Our deep industry expertise enables us to address unique challenges and drive competitiveness in a dynamic market.

Get in Touch with us

Ready to transform your business? Contact us now!