New claims data shows the average cyber loss climbing sharply even as the number of claims falls. The reason the two move in opposite directions is where the cost now sits: in court, not in the incident.
What happened
On 25 August 2026, Chubb published its 2026 Cyber Claims Report. It found that the average cost of a cyber insurance claim rose sharply in 2025 for both middle-market and large companies, even though the overall number of claims fell significantly. In the United States, average claim costs rose about 22 percent for middle-market firms and roughly doubled for large companies. The United Kingdom and Europe showed the same shape, with middle-market costs up about 34 percent and large-company costs up about 98 percent. Chubb attributed the increase to the rising cost of data breach and privacy-related litigation, together with higher business interruption expenses (Infosecurity Magazine, 26 August 2026: https://www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/).
The underlying signal
Fewer claims, higher cost per claim. That combination means the expected loss from a cyber event is being driven less by the technical incident and more by what follows it in litigation. Chubb’s own illustration is blunt: in a privacy suit with 10,000 claimants, non-refundable administrative fees alone can exceed 10 million dollars before a court has ruled on the merits. The incident is no longer the expensive part.
Why it matters beyond the insured companies
Premiums, retentions, and sub-limits are priced off severity trends. A market where the cost per claim is rising even as claim frequency falls is a market that keeps hardening: higher premiums, higher self-insured retentions, and tighter limits on exactly the privacy and class-action exposure that is growing. Any organisation that has treated cyber insurance as its backstop for legal liability should expect that backstop to be narrower and more expensive at the next renewal. The exposure is also uneven by geography. Chubb noted that material third-party litigation costs are present in the United States and largely absent in the United Kingdom and Europe, so a multinational’s US data footprint carries disproportionate weight in its loss estimate.
What exposure this reveals
Two gaps tend to surface. First, incident cost models built around forensics, notification, and recovery understate the tail, because the tail is now litigation that can run for years after the incident itself is closed. A loss estimate that stops at recovery is measuring the wrong thing. Second, data retention gets treated as a compliance question rather than a financial control. The size of a privacy class action scales with the number of affected individuals, so how much personal data an organisation holds, and for how long, is a direct input to the cost of any future breach.
Who should pay attention
Risk and finance functions preparing for cyber renewals. General counsel, given that legal cost is now the dominant driver of claim severity. And whoever owns data retention schedules, because those schedules now have a measurable effect on the cost of an incident that has not happened yet.
What management should consider
Whether the organisation’s cyber loss estimates separate incident response cost from legal liability and model the second over a multi-year horizon. Whether the current policy’s privacy and class-action sub-limits still reflect where the cost has moved. And whether cutting the volume and age of personal data held is being weighed as a way to reduce expected loss, rather than only as a regulatory obligation.
