Cybersecurity

Cyber Insurance Claims Are Getting More Expensive: What Financial Institutions Should Do Now

Cyber insurance claims are getting more expensive. Learn what banks and credit unions should do now to strengthen controls, resilience, and readiness.

Cyber insurance can no longer be treated as a backstop that activates only after controls fail. New claims and breach cost data show that incident severity, litigation expense, business interruption, ransomware extortion, and AI-enabled attacks are reshaping the risk picture for banks, credit unions, and financial service providers.

If your institution has questions about cyber insurance readiness, GLBA controls, ransomware resilience, or IT audit priorities, contact NETBankAudit to discuss practical next steps.

Cyber Claims Severity Is Now a Board-Level Risk Signal

The Chubb 2026 Cyber Claims Report is an annual cyber insurance study published by Chubb, one of the world's largest commercial insurance companies. The report analyzes Chubb's actual cyber insurance claims data through the end of 2025 and discusses emerging cyber risk trends affecting businesses. 

Recent claims analysis highlighted a difficult trend: average cyber insurance losses rose in 2025 even though some claim counts declined. In the U.S., average claim cost increased 22% for middle-market firms and 100% for large companies compared with 2024.

For financial institutions, that trend should be viewed as a governance issue, not only an insurance issue. A lower claim count does not automatically mean a lower control burden, lower examination concern, or lower operational risk.

Fewer claims do not mean lower exposure

Claim frequency and claim severity tell different stories. Frequency measures how often losses occur. Severity measures the average cost when they do occur. When severity rises, a single event can consume management attention, affect customer confidence, trigger regulatory notifications, and test the institution’s ability to maintain operations.

Litigation and business interruption drive the cost curve

Chubb’s report tied higher severity to rising data breach litigation, privacy-related litigation, and business interruption expenses. That matters to banks and credit unions because cyber events rarely remain technical. They quickly become customer service, legal, compliance, vendor management, board reporting, and reputation events.

The litigation-first dynamic is especially important. Privacy claims, mass arbitration tactics, and disputes over tracking technologies can create significant legal pressure before the underlying merits are resolved. Cybersecurity evidence must be ready before the event, not assembled under stress.

Data Breach Costs Are Moving Into Financial-Sector Territory

A recent breach cost analysis placed the global average cost of a data breach at $4.99 million, a 12% increase. The same coverage identified the financial sector among the five costliest sectors, with average breach costs of $6.3 million.

Those numbers should get the attention of community bank and credit union leadership. Even when an institution is smaller than the organizations used in global studies, the loss drivers are familiar: customer trust, business interruption, investigative costs, notification work, remediation, and vendor coordination.

Ransomware now targets trust, not just uptime

Attackers still encrypt systems, but many also threaten data exposure and brand damage. The IBM-related article noted that 41% of organizations hit by ransomware said attackers used reputation damage or customer data exposure as pressure to pay.

That tactic has special force in financial services. Customers expect their bank or credit union to protect personal and financial information. A ransomware event that exposes data can become a customer confidence problem even if systems are restored quickly.

AI adds speed, scale, and cost

The IBM study connected AI-driven attacks with higher breach costs, including an average added cost of $1 million per breach. It also noted that over one in four organizations experiencing a malicious attack said it was AI-driven.

For institutions, AI risk is not abstract. It can appear through deepfake impersonation, AI-enabled malware, faster phishing development, automated reconnaissance, and improper employee use of public AI tools with sensitive information.

What Banks and Credit Unions Should Take From the Reports

The strongest lesson is that loss severity grows when controls cannot prove what happened, what data was exposed, and what management did next. Insurance may help with financial recovery, but it cannot replace control evidence. The following areas deserve immediate review.

  • Information security governance: Confirm that risk assessments, board reporting, GLBA 501(b) documentation, and information security program updates reflect ransomware, AI, privacy, and third-party risk.
  • Identity controls: Review privileged access, remote access, service accounts, password practices, and multi-factor authentication coverage. Identity-based attacks remain a common path into financial systems.
  • Vulnerability and patch management: Validate that scanning, prioritization, remediation, and exception tracking are documented. A patch process is only useful if it is repeatable and supported by evidence.
  • Social engineering controls: Test whether employees can detect phishing, vendor payment redirection, pretext calling, and deepfake-style impersonation. Training should be measured, not assumed.
  • Data exposure analysis: Know where sensitive customer information resides, how it moves, who can access it, and which third parties process it.
  • Incident response readiness: Test notification workflows, legal escalation, communications, forensic coordination, insurance contacts, and board reporting expectations before an incident occurs.

AI Governance Belongs in the Information Security Program

AI can improve detection and analysis, but it also changes the threat model. Chubb’s report described agentic and autonomous AI as a factor that can compress attack timelines from days to minutes. Manual response alone may not be fast enough.

Public AI tools create a new leakage path

One practical risk is simple: employees may paste sensitive information into publicly accessible AI tools. For a financial institution, that could include customer information, loan details, suspicious activity narratives, wire documentation, vendor contracts, or internal audit materials.

Policies should define approved AI use, prohibited data inputs, review responsibilities, retention expectations, and third-party data handling. AI governance should also connect to vendor management because many service providers are embedding AI into existing products.

Deepfakes change social engineering testing

Traditional phishing tests are still valuable, but attackers now have more tools to imitate executives, vendors, borrowers, and internal staff. A deepfake voice request tied to a wire transfer, vendor payment change, or credential reset may feel more convincing than a suspicious email.

Security awareness should therefore include verification discipline. Staff should be trained to slow down, use approved call-back procedures, validate account changes, and escalate unusual pressure tactics.

Cyber Insurance Renewal Should Start With Control Validation

Cyber insurance questionnaires are becoming more detailed because losses are becoming more expensive. Underwriters want evidence that controls exist and operate effectively. Institutions should prepare for renewal by validating controls before the questionnaire is due.

  1. Reconcile key controls: Confirm that responses about backups, endpoint detection, MFA, privileged access, patching, and incident response match current practice.
  2. Document exceptions: If a control is not fully implemented, record compensating controls, ownership, target dates, and management acceptance.
  3. Test restoration: Backups should be recoverable, segmented, and aligned with business impact expectations. A written plan is not enough.
  4. Review incident roles: Identify who contacts counsel, the carrier, forensic providers, regulators, customers, law enforcement, and the board.
  5. Assess AI language: Review whether policy language, endorsements, exclusions, or sublimits address AI-related events. Involve qualified insurance and legal advisors when needed.

The goal is not to make the renewal process easier on paper. The goal is to reduce uncertainty when a real event occurs. Better evidence can also help management answer examiner, board, and insurer questions with more confidence.

Third-Party Dependencies Can Turn Vendor Incidents Into Institution Losses

No financial institution operates alone. Core processors, digital banking platforms, payment providers, cloud services, managed service providers, fintech partners, and data processors all influence operational resilience. Chubb’s report emphasized systemic interdependency as a major feature of modern cyber risk.

A vendor outage can affect account access, loan processing, ACH, wire transfers, card operations, call center activity, reporting, and branch workflows. The institution may not control the vendor’s network, but it is still responsible for vendor oversight, customer communication, contingency planning, and board reporting.

Vendor management should include incident practicality

Contract due diligence is important, but incident practicality is equally important. Institutions should know how quickly critical vendors provide breach notices, status updates, forensic information, service restoration estimates, and customer impact data.

Vendor testing should also connect to business continuity planning. If a platform is unavailable, staff need clear alternate procedures. Those procedures should be realistic enough to support customers and documented enough to satisfy oversight expectations.

Build Resilience With NETBankAudit

NETBankAudit was formed in 2000 by IT banking executives and regulatory specialists to help institutions manage technology risk, audit expectations, and regulatory complexity. The firm works as an extension of the internal audit function or management self-assessment efforts. That combination is valuable when cyber risk, insurance, and regulatory oversight intersect.

NETBankAudit supports financial institutions with independent audits, risk assessments, and technical testing designed around real banking environments. The following services directly support the issues raised by rising cyber claim severity. Each can help management strengthen controls before an incident, renewal, or examination.

  • IT General Controls audits: Risk-based reviews of governance, management, operations, security, support, and delivery controls.
  • GLBA 501(b) and cybersecurity assessments: Evaluation of information security programs, cybersecurity preparedness, and regulatory alignment.
  • Vulnerability and penetration testing: Internal and external testing, VPN testing, cloud reviews, Active Directory assessments, and configuration reviews.
  • Social engineering testing: Phishing, pretext calling, onsite awareness reviews, and practical feedback to strengthen employee response.
  • Ransomware, incident response, and business continuity reviews: Assessment of response plans, BIA assumptions, recovery expectations, and operational readiness.
  • Vendor management and regulatory consulting: Review of due diligence, monitoring, third-party risk practices, and examination preparation. These reviews help connect cyber controls to board and examiner expectations.

Rising cyber insurance losses make one point clear: financial institutions need tested controls, usable evidence, and practical response planning before a disruptive event occurs. To discuss how NETBankAudit can help your bank or credit union prepare, contact NETBankAudit.

THE GOLD STANDARD IN
Cybersecurity and Regulatory Compliance

 
class SampleComponent extends React.Component { 
  // using the experimental public class field syntax below. We can also attach  
  // the contextType to the current class 
  static contextType = ColorContext; 
  render() { 
    return <Button color={this.color} /> 
  } 
} 

Mitigate Risks with Comprehensive Audits & Assessments

Request For Proposal
NEWS & ARTICLES

Explore Our Learning Center

Ask a Question
Thank you! We will email you the answer to your question shortly!
Oops! Something went wrong while submitting the form.