What we have seen in June renewals
June renewals remained highly competitive for organisations with MFA, EDR, tested backups, incident response plans and strong governance. Weak control risks are still quickly identified. The cyber risk environment is entering a new phase defined by AI-driven threat acceleration, heightened regulatory scrutiny and persistent systemic vulnerabilities. While traditional attack vectors remain dominant, the emergence of autonomous offensive capabilities and escalating geopolitical tensions are likely to significantly reshape both risk exposure and mitigation strategies over the coming twelve to twenty-four months.
Policy innovation is accelerating, with insurers expanding cyber add-ons and endorsements particularly in response to emerging AI-related risks. There is growing focus on coverage clarity, particularly around how policies respond to AI-driven attacks and systemic events. While pricing pressures are easing, risk selection remains disciplined as insurers respond to a more complex and interconnected threat landscape.
Premium pricing trends
Pricing is -5% to -15% for strong risks and flat to +10% for poor controls, data-heavy operations or prior incidents. Underwriting scrutiny remains high, particularly in relation to identity and access management, endpoint detection and response, backup resilience and incident response maturity.
Insurer behaviour
Cyber insurers continue to demonstrate strong appetite for well-managed risks, driven by improved cyber hygiene across insureds, favourable loss ratios, and increased market competition. As a result, organisations are benefiting from broader coverage options and more competitive pricing across many sectors.
Claims trends
Claims trends include ransomware, BEC, social engineering, vendor outages, privacy breach, AI-enabled fraud and supply-chain technology failure. Consistent with our January 2026 market update, the underlying drivers of cyber incidents remain largely unchanged: business email compromise, ransomware, and third-party and supply chain breaches. The human element remains a key vulnerability, contributing to approximately 60% of breaches. Phishing, misdirected communications and data handling errors continue to drive incidents, underscoring the importance of user awareness alongside technical controls.
The 2026 Verizon Data Breach Investigations Report highlights that stolen credentials remain the primary attack vector at 39% of breaches, while vulnerability exploitation continues to rise at 20% of breaches, up 34% year-on-year. AI is amplifying attack scale rather than introducing new methods, with 44% of AI-assisted intrusions linked to phishing. Ransomware continues to grow in both frequency and reach, now present in up to 48% of breaches, with average payouts declining as more organisations take the decision not to pay. Threat actors are increasingly targeting small and mid-sized businesses with weaker controls and lower tolerance for disruption. There is also a clear shift toward data extortion, where the value lies in the impact on the victim rather than resale on the dark web.
Supply chain attacks are increasing in severity. By targeting managed service providers and technology vendors, threat actors can scale impact across multiple organisations. These incidents reinforce the importance of robust vendor risk management, access controls and continuous monitoring. Cyber incidents are also becoming increasingly operational in nature, with outages, system downtime and service disruptions more common, reinforcing cyber risk as a core business continuity issue. Exposure remains concentrated in sectors with high data sensitivity and technological reliance, including healthcare, financial services, local government and critical infrastructure.
Cyber risk to critical infrastructure remains a key area of concern. As we previously reported, the Australian Signals Directorate has indicated that over half of the incidents it responds to involve critical infrastructure assets. Recent international developments reinforce this trend, with continued reporting of state-sponsored cyber activity targeting infrastructure systems. In a period of elevated geopolitical tension, cyber operations are increasingly being used alongside traditional measures to advance strategic objectives. Organisations operating within critical supply chains, including those working in the defence, energy, financial services and telecommunications sectors, face heightened exposure.
Legal and regulatory developments
Privacy reform, ASIC expectations and cyber governance duties remain central. Cyber also interacts with management liability and D&O where governance or disclosure failures arise. Organisations should monitor the rollout of Cyber Security Act reforms and ongoing Privacy Act changes. Recent events including the Optus, Vinomofo and FIIG breaches, as well as emerging class actions, highlight the growing intensity of regulatory and legal scrutiny. As we reported previously, ASIC has repeatedly warned that financial services licensees must treat cyber security risk as a key priority without delay, signalling clear escalation in expectations around cyber resilience.
A key shift is the move from simply having controls in place to demonstrating their effectiveness. Boards and senior executives are now expected to actively evidence their cyber resilience. Cyber governance is now firmly established as a core fiduciary responsibility, rather than a matter delegated solely to technical teams. Regulatory and industry guidance increasingly emphasises that geopolitically motivated cyber incidents are a credible and ongoing risk that should be factored into resilience planning.
AI and technology impact
The most significant development in cyber risk continues to be the rapid evolution of advanced AI models. The recent release of Anthropic’s Mythos model has attracted considerable industry attention and is widely regarded as a step-change in capability. As we previously noted alongside ASIC’s open letter on AI Mythos may represent an inflection point between defensive and offensive AI. Unlike earlier tools, Mythos is reportedly capable of autonomously identifying, probing and exploiting weakly defended systems, materially lowering the barrier to entry for sophisticated cyberattacks. Governments are already responding to concerns about advanced AI, with the Five Eye Alliance issuing a joint statement underscoring the emerging cyber security concerns with these technologies.
Organisations now operate in an environment shaped by AI, geopolitical tensions, regulatory pressure, supply chain interdependencies, non-human identities, hyperconnectivity and the emerging risk of quantum decryption. The transition to post-quantum cryptography is increasingly seen as inevitable, with regulators globally beginning to issue guidance on encryption migration presenting a significant challenge particularly for sectors such as financial services and defence, where encrypted data has long-term sensitivity.
What policyholders should do now
Policyholders should take advantage of current market conditions by actively reviewing their cyber insurance programmes. This includes reassessing coverage limits, policy wording, sub-limits, and emerging risk exposures to ensure protection remains aligned with the organisation’s evolving threat landscape. Boards and senior executives should actively evidence resilience through scenario simulations, penetration testing and control validation, and tabletop exercises and incident response drills.
Continue reading our full range of market updates:
- Insurance Market Overview: July 2026
- Claims
- Workplace Risk
- Corporate and Multinational Risk
- Construction, Property and Development
- Financial Lines





