The cyber insurance market in 2025 looks deceptively quiet. Premiums have stabilized after the chaotic 2022-2023 hardening cycle. Capacity is up. Carriers are competing for new business again. By the indicators that drive the trade press, the market should be easier than it's been in years.
But ask any commercial broker writing cyber liability this year, and they'll tell you the same story: the renewal application has gotten harder, not easier. The questions multiplied. The evidence standards tightened. The carrier's tolerance for "we have it" without proof shrank to near zero.
Here's what actually changed, why it changed, and what an SMB should do about it before the next renewal letter arrives.
The premium stabilized. The underwriting did not.
The headline market story is that premiums have come back down. Coalition's 2025 Cyber Claims Report (covering full-year 2024 claims data) and the broader carrier commentary in 2025 describe a market that has normalized after the chaotic 2022-2023 hardening cycle. New entrants (Cowbell, At-Bay, Resilience, Coalition) have aggressive capacity and are willing to write smaller accounts that the legacy carriers historically wouldn't touch.
That competitive pressure has not produced an easier underwriting environment. It's produced a more discriminating one. Marsh's U.S. cyber market commentary (May 2025) is explicit on this point: carriers now weigh roughly a dozen cyber-hygiene controls (MFA, EDR, backup recovery testing, patch management, privileged access, and the rest) and "more favorable terms and pricing" follow from how thoroughly those controls are implemented and documented.
In practice, that means three things have happened to the renewal questionnaire:
- It got longer. The application has expanded substantially over the past three renewal cycles. Where a 2022 SMB application might fit on a single page, the 2025 version typically runs multiple pages of detailed control questions.
- It got more specific. Where the 2022 application asked "Do you have MFA?", the 2025 carrier wants to know where MFA is enforced (email, VPN, RDP, administrative accounts, cloud applications) and how completely.
- It got auditable. Carriers and brokers increasingly want screenshots, configuration exports, policy excerpts, and audit logs to back the answers, not just a yes or no.
A defensible answer in 2025 is not a confident answer. It's an answer backed by an artifact the underwriter can read.
The losses tell the carriers where to push hardest.
The 2024 claims data published in Coalition's 2025 report makes the underwriting evolution easy to understand. Business email compromise and funds transfer fraud accounted for roughly 60% of claims by frequency. Ransomware, while less frequent, was the most costly category: average breach cost approximately $115,000 per claim, with the largest losses far above that.
Aon's October 2025 commentary on the Q2 2025 cyber market underscores why the controls conversation hasn't softened despite premium relief: average ransomware demand grew approximately 104% year over year to around $1.13 million per incident. The exposure is still significant; only the pricing of the policy has eased.
For SMBs filling out a renewal application in 2025, the takeaway is direct. The controls that prevent BEC and funds transfer fraud (MFA on email, authentication hardening, vendor verification procedures, secure financial workflows) and the controls that limit ransomware impact (EDR, segmented and tested backups, patch hygiene) are precisely the questions the carrier is going to weigh most heavily. The renewal isn't a checklist. It's a conversation about whether your environment is positioned against the loss patterns the carrier knows it underwrites.
What underwriters look at now beyond the application
The underwriting evolution of 2024-2025 has moved cyber insurance closer to the underwriting discipline of property and general liability. Carriers increasingly supplement the application with external scans, dark-web monitoring, technographic signals, and, where the carrier operates an active risk platform, agent-based telemetry from the insured environment.
What this means for an SMB filling out a renewal application in 2025:
- The carrier may already know what your perimeter looks like before you submit the application. Mismatches between what the application says and what the external scan shows produce questions.
- Industry-specific risk factors are being weighted more aggressively. A small healthcare practice and a small manufacturer with the same revenue can see materially different premium offers.
- The renewal isn't just "did anything bad happen this year?" It's "did your security posture get better, stay the same, or get worse?" Carriers want to see the program maturing.
The implication: at renewal, the conversation with the carrier has shifted from a checkbox exercise to a documented-evidence conversation. The clients who do well are the ones with a binder of artifacts ready to back the application (control descriptions, configuration exports, policy excerpts, training completion data), not the clients with the lowest premium last year.
What to actually do before the next renewal
The single most useful thing an SMB can do before the next renewal is to assemble the evidence behind the answers it will give on the questionnaire. Not to install new controls (though some may need installing), but to package what already exists in a form the underwriter can read.
A practical checklist for the months before renewal:
- Get a copy of the questionnaire early. Brokers can usually pull a sample 60 to 90 days before the renewal date.
- Walk every answer with the IT lead or MSP. "Yes" only counts if there's an artifact behind it.
- Document the artifacts. Configuration exports, policy excerpts, training records, MFA enforcement screenshots. Save them where you can find them at claim time.
- Identify the gaps. What questions can't be answered yes today? Are they remediable in time, or do they need to be answered honestly with mitigating context?
- Coordinate with the broker. The broker is the carrier's translator. The more the broker can show the underwriter that the program is mature, the better the renewal terms.
The renewal questionnaire is not the broker's job to fill out: it's the policyholder's responsibility, even if the broker drafts it. But the policyholder is rarely the right person to assemble the technical evidence behind the answers. That's the gap the next 12 months of cyber insurance underwriting will keep finding.
The carriers have learned what their losses correlate with. The applications now reflect that learning. The renewal that landed on a desk in 2025 is harder than the one that landed in 2022 because the carrier is now asking the question they wish they had been asking all along.