Cyber and E&O: A Soft Market Meets Rising Volatility

Cyber and E&O: A Soft Market Meets Rising Volatility
September 18, 2026 11 mins

Cyber and E&O: A Soft Market Meets Rising Volatility

Cyber and E&O: Favorable Rates, Growing Exposure

Market conditions remain favorable for cyber and technology E&O buyers, but exposure continues to evolve. Leading organizations are using this period to reassess limits, clarify coverage and strengthen resilience before the next major test of the market.

Key Takeaways
  1. Market conditions continue to favor buyers, with competitive pricing, broad coverage and strong insurer participation.
  2. Insurers are sharpening their focus on the loss drivers most likely to disrupt performance, including AI-enabled activity, critical vendor dependencies and systemic cyber events.
  3. Organizations are increasingly using analytics and quantification to reassess limits, strengthen resilience and support risk financing decisions.

Cyber and technology errors and omissions (E&O) buyers continue to benefit from a soft market in the second half of 2026, supported by favorable terms, competitive pricing and strong insurer participation. That advantage is real, but it should not be misread as a reduction in risk. Insurers continue to focus on the loss drivers most likely to disrupt operations and performance, including AI-enabled activity, third-party dependencies, business interruption and privacy litigation.

The opportunity is to use favorable market conditions to strengthen resilience, not simply reduce cost. Organizations are reassessing limits, evaluating coverage and investing in stronger controls while using analytics and quantification to better understand potential financial exposure.

Where the Market Stands Through H1 2026

Cyber

Buyer-friendly conditions continue across North America and Europe, the Middle East and Africa, with modest decelerating rate reductions, broad coverage, robust capacity and stable limits.

Ransomware and extortion activity remain elevated, but severity has moderated. From 2025 to 2026, average demand amounts declined approximately 29%, while average payments fell about 61%, according to Aon data.

At the same time, reported payment counts rose 88% year over year and H1 2026 claim volume was already approaching prior-year totals, suggesting that frequency remains a significant concern, even as average loss severity declines.

Tech E&O

Tech E&O pricing also remains stable to favorable. Through Q2 2026, Aon clients saw quarterly average reductions of 4% to 7%, building on quarterly average declines of 5% to 8% in 2024.

Results continue to vary by sector, loss history and risk profile. New market entrants and continued growth ambitions among established insurers continue to support strong competition, particularly for buyers using CAT limit structures. Carriers are also expanding coverage and innovation.

The market is not without limits. A systemic event, concentrated vendor loss or rising third-party claims could slow reductions.

  • 4-5%

    Average Q2 2026 reductions, all layers

  • ~18%

    Around 15-18% of Aon clients increased their limits in Q2 2026.

  • 23%

    Aon U.S. clients that improved critical controls through H1 2026

    Source: Aon data

Regional Spotlight: Similar Conditions, Different Pressure Points

  • North America

    Pricing remains favorable across much of North America, although conditions are becoming more differentiated by segment. Aon clients saw average Q2 2026 reductions of 5% across all layers in the U.S. and 13% in Canada, while Canadian middle market reductions were more modest at 4% and flattened in June.

    “Our middle market clients are beginning to see more neutral renewals,” says Katie Andruchow, Cyber Broking Practice Leader, Canada. “Claims specifically in the e-crime or cyber crime space tend to be impacting these portfolios.”

    Capacity is also ample. In 2025, more than 80 insurers participated in North American placements with an average limit deployment of $7 million, up from 57 insurers and $5 million in 2020.

    “Capacity remains strong,” says Matt Chmel, Head of Cyber Solutions, North America. “Buyers have alternatives, and no insurer wants to be first to push the market firmer.”

  • Europe, the Middle East and Africa

    Pricing remains soft and loss ratios low, with Q2 2026 rate reductions averaging 10% across the region. Strong insurer participation continues to support broad coverage and competitive renewal outcomes.

    “There is still ample capacity and very favorable renewal conditions,” says Yue Yang, Managing Director, Cyber Solutions, Europe, the Middle East and Africa. “The buyer-friendly environment is also motivating new buyers to enter the market.”

    Favorable conditions continue to benefit cyber and tech E&O buyers, creating opportunities for both growth and strategic program optimization. As organizations become more confident in their understanding of cyber risk, many are taking the opportunity to reevaluate program design, coverage adequacy and limit strategies.

    Growth continues to be fueled by first-time buyers entering the market, while established insureds are making more data-driven purchasing decisions based on quantified exposure analysis rather than legacy buying patterns.

Cyber Volatility is Building Beneath Favorable Pricing

Insurers are increasingly focused on the risks most likely to turn today’s competitive conditions: control maturity, vendor dependencies, AI governance, privacy practices and large-scale systemic events.

  • AI is changing how organizations think about risk and insurance.

    AI is becoming embedded across products, services and business operations, creating new questions about accountability, liability and insurance response. As adoption expands, organizations are placing greater emphasis on understanding how cyber and technology E&O policies respond to AI-related exposures and whether coverage keeps pace with changing risk.

    Underwriting discussions are becoming more detailed as insurers seek greater clarity around AI governance, data management, vendor oversight and accountability. Organizations integrating AI into business processes, products or services can expect closer scrutiny of how these risks are managed.

    "AI will continue to create new risks and influence multiple lines of insurance, but the cyber and technology E&O market must remain clear about how AI-related exposures are addressed. Greater clarity around policy response helps organizations better understand how coverage may respond when AI contributes to cyber or technology E&O losses," says Søren Stryger, Chief Cyber Broking Officer, Europe, the Middle East and Africa.

    Chris Mee, Product Leader, Cyber Solutions, United States, adds: "AI is not solely a cyber or technology E&O issue. Depending on how AI is deployed, organizations may also need to consider the implications for D&O, crime, employment practices liability and casualty programs. Understanding how exposures interact across policies is becoming just as important as understanding the technology itself."

  • Supply chain concentration remains a critical source of cyber risk.

    As organizations become more digitally interconnected, concentration risk is clearly one of the most important drivers of cyber resilience and insurance decisions. Yet third-party dependencies remain the lowest-scoring cyber domain globally and the largest identified gap in four of five regions, according to Aon data. Understanding which third-party dependencies have the greatest potential to disrupt operations, revenue generation and customer service is becoming increasingly important for risk leaders.

    A cloud outage, compromised software update, managed service provider breach or technology platform failure can disrupt organizations that otherwise maintain strong internal controls. For many organizations, third-party dependencies now represent one of the most significant sources of potential business interruption and operational disruption.

    Leading organizations are incorporating concentration risk into resilience planning and risk financing decisions. Understanding which providers support critical business functions, how quickly they can be replaced and how insurance programs respond when disruptions occur can help organizations better manage the potential impact of third-party failures.

  • The next major systemic event could test the market.

    The cyber insurance market has remained resilient through a series of significant incidents in recent years, supported by strong insurer participation, sustained profitability and continued competition. While systemic cyber risk remains one of the market’s most closely watched exposures, recent events have not materially altered favorable market conditions.

    Future large-scale cyber events, particularly those involving widely used technology providers or critical digital infrastructure, will continue to test assumptions about resilience, underwriting discipline and market capacity. The extent to which such events affect the insurance market will depend on a range of factors, including how losses emerge, how coverage responds and the concentration of insured exposures.

    For risk leaders, the importance of systemic risk extends beyond its potential impact on the insurance market. Concentrated technology dependencies, operational disruption and interconnected digital ecosystems all have the potential to create significant business consequences, whether losses are insured or uninsured. Organizations that evaluate these scenarios and incorporate them into resilience planning may be better positioned regardless of how the market responds.

Private Equity: Cyber Risk Can Move from Portfolio Company to Sponsor

Private equity firms operate through highly connected ecosystems of portfolio companies, fund vehicles, advisers, lenders and service providers. That connectivity creates multiple pathways for cyber risk to extend beyond a single organization. A cyber incident affecting a portfolio company can quickly become a sponsor-level issue when board reporting, financing arrangements, investor communications, shared vendors or active transactions are involved.

Cyber incidents can also expose information that extends well beyond operational data. Data exfiltration can reveal diligence materials, projections, regulatory correspondence, cyber assessments, insurance information and investor communications. Public transaction activity can create additional attention on newly acquired businesses when integration is ongoing and controls may not yet be fully aligned.

As portfolios become increasingly digital and interconnected, many sponsors are taking a more structured approach to cyber resilience. The focus is shifting from individual company assessments to understanding portfolio-wide exposure, identifying common control gaps and evaluating concentrations of risk across critical technologies, vendors and operating models.

Financial quantification can support these decisions by helping sponsors assess whether individual companies, or the portfolio as a whole, may be underinsured against severe but plausible cyber scenarios. It can also provide a more disciplined basis for decisions around limits, retentions and capital allocation.

Insurance program design remains an important consideration. Sponsors should ensure that cyber, crime, D&O and technology E&O programs work together effectively and that roles, responsibilities and notification requirements are clearly understood before an incident occurs.

“The individual-company view is only the starting point,” says Elizabeth Stephens, Private Equity Cyber Practice Leader, United States. “Sponsors can use consistent assessment and analytics across the portfolio to identify common control gaps, understand concentration and make more informed risk financing decisions.”

Turn Favorable Conditions into a Resilience Dividend

Despite continued pricing reductions, many organizations are using favorable market conditions to expand protection rather than reduce spend. Aon data indicates that 15% to 18% of clients increased cyber limits during Q2 2026, while only 0% to 3% reduced them. New buyer programs increased 14% through Q2.

As organizations quantify cyber exposure, many are discovering that existing limits may not fully reflect potential financial impact. Quantification helps connect loss scenarios, control maturity, insurance program design and potential uninsured loss, providing a more disciplined basis for risk financing decisions than peer benchmarking alone.

Current market conditions remain favorable, but organizations should avoid assuming they will persist indefinitely. Those that use today's environment to strengthen controls, clarify coverage and quantify exposure will be better positioned for whatever comes next. That may include a major cyber event, increasing regulatory scrutiny or a shift in the insurance cycle.

Actions for Q4 2026
  • Use favorable market conditions strategically. Reinvest savings where analysis points to limit inadequacy, material sublimits or coverage ambiguity.
  • Review how AI-related exposures may be addressed across cyber, technology E&O, crime, D&O and other relevant insurance programs.
  • Quantify severe but plausible loss scenarios, including ransomware, data theft, privacy litigation, critical vendor outage and systemic cloud or software events.
  • Pressure test third-party dependencies, including critical providers, delegated access, concentration, contractual remedies and recovery alternatives.
  • Accelerate vulnerability and patch management as AI compresses the time between disclosure and exploitation.
  • Run an executive tabletop exercise covering materiality, regulatory reporting, carrier notice, vendor consent, liquidity, communications and board escalation.
  • For private equity, strengthen governance across private equity portfolios, establish portfolio minimums while preserving company-specific risk decisions.
2027: What Risk Leaders Should Watch Next

Three developments will shape the next phase of the market:

  1. Claims development may test underwriting discipline as insurers continue to compete for growth.
  2. A future systemic or supply chain event could provide an important test of how well the market absorbs significant insured losses and whether underwriting discipline can be maintained through a period of heightened claims activity.
  3. Regulation is compressing decision timelines for incident reporting and creating new governance frameworks, particularly for AI.

If you are ready to evaluate your cyber risk program, contact us to discuss practical approaches for strengthening cyber resilience and protecting your organization from cyber attacks and data breaches.

Aon’s Thought Leaders

Katie Andruchow
Cyber Solutions Co-Leader, Canada

Matt Chmel
Head of Cyber Solutions, North America

Pablo Constenla
Head of Cyber and Financial Lines Coverage and Claims, Europe, the Middle East and Africa

Catalina Esteban Loring
Executive Director, Cyber and Commercial E&O, United Kingdom

Chris Mee
Product Leader, Cyber Solutions, United States

David Molony
Head of Cyber Solutions, Europe, the Middle East and Africa

Brent Rieth
Head of Global Cyber Solutions

Ady Sharma
Cyber Solutions Co-Leader, Canada

Greg Sparacio
Middle Market Leader, Cyber Solutions, United States

Elizabeth Stephens
Private Equity Cyber Practice Leader, United States

Søren Stryger
Chief Cyber Broking Officer, Europe, the Middle East and Africa

Stephen Viña
Senior Vice President, Cyber Solutions, North America

Yue Yang
Managing Director, Cyber Solutions, Europe, the Middle East and Africa

General Disclaimer

This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.

Terms of Use

The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.

More Like This

View All
Talk to Our Team

Let’s Connect

Talk to Our Team

Contact our team today to learn more about how we can help your business.

Contact Us