Skip to content
JLKRosenberger logo
Insights

Cyber Committee Recap: NAIC’s H Committee Reviews Cyber Claims Study

Key Takeaways:

On June 10, 2026, the NAIC’s H Committee Cybersecurity Working Group reviewed the 2025 NetDiligence Cyber Claims Study, which analyzed over 14,000 cyber claims spanning 2020–2024 incidents. The study breaks down incident costs, ransomware trends, and data exposure patterns across small and mid-sized enterprises (SMEs) and large companies, offering a data-driven view of how cyber risk is evolving. Below are five key takeaways from the report.

  1. SMEs absorb nearly half of total cyber incident costs. SMEs filed 98% of claims but bore 49% of costs; large companies filed just 2% of claims yet accounted for 51% ($2.4B of $4.8B).
  2. Ransomware and BEC drive the majority of losses. These caused ~50% of SME claims from 2020–2024 (nearly 55% in 2024). Average ransom demand: $3M. Average paid: $1.2M.
  3. Crisis services costs are climbing.
SME crisis costs (forensics, notification, monitoring, PR) rose from $121K (2020) to $144K (2024), now 47% of total cost, up from 40%.
  4. Business interruption often outpaces direct incident cost. Five-year average BI cost: $1.2M vs. $1.8M incident cost. In 2024: $611K vs. $630K.
  5. Most breach data doesn’t fit a clean category.
76% of claims fell under “Other/Unknown,” with PII (13%) and PHI (3%) far behind, complicating risk assessment.

On June 10, 2026, the Cybersecurity Working Group reviewed the NetDiligence 2025 Cyber Claims Study, which analyzed cyber claims, incident costs, ransomware, business interruption, and data exposure trends across Small and Medium-sized Enterprises (SMEs) and large companies.

This article touches the surface of the insights from the NetDiligence report, but you can download the study for free using this link.

The remaining H Committee Working Groups and Subgroups convened in August to provide updates on their ongoing projects and draft models. Because these projects are still under development and have not been finalized, their updates were excluded from the summarization in this article. However, their work continues to progress.

Cyber Claims Study

The study analyzed 10,402 claims from 2020–2024 incidents, plus 4,108 new and updated 2025 claims from 2022–2024 incidents. Claim severity ranged from less than $1,000 to more than $500 million. SMEs made up 98% of claims and 49% of incident costs; large companies made up only 2% of claims but 51% of total incident costs, or about $2.4 billion of $4.8 billion.

Source: NetDiligence Cyber Claims Study – 2025 Report, p. 2, Figure 1, NetDiligence, 2025.

Crisis Services and Incident Costs

To better understand the financial impacts of such security incidents, it is helpful to look at these three components: breach events, crisis service costs, and incident costs.

Breach events involve the unauthorized access, theft of exposure of sensitive data. Crisis service costs are the immediate expenses associated with responding to a breach event, such as forensics, notification, credit/ID monitoring, and public relations. Incident costs are the aggregate total of all expenses associated with the incident.

For all organizations, crisis services costs ranged from less than $100 to nearly $26 million, while incident costs including Self-Insured Retention (SIR) ranged from less than $1,000 to more than $160 million.

For SMEs, average crisis services costs ranged from $121,000 in 2020 to $144,000 in 2024; crisis services represented 47% of total cost for 2020–2024, up 40% from the 2025 report.

Source: NetDiligence Cyber Claims Study – 2025 Report, p. 10, Figure 11, NetDiligence, 2025.

For large companies, average incident costs ranged from $4.7 million to $22.5 million, with outlier events in 2021 and 2023 driving spikes.

Crisis services represented 20% to 75% of total cost over the five-year period, averaging 25%, compared with 28% in the prior five-year period.

Source: NetDiligence Cyber Claims Study – 2025 Report, p. 14, NetDiligence, 2025.

Ransomware Trends

Ransom amounts and incident costs rose sharply over five years. Ransomware and business email compromise were the top causes of loss, accounting for 50% of SME claims of at least $1,000 from 2020–2024 and nearly 55% in 2024. The five-year average ransom demand for SMEs was $3 million, and the average ransom paid was $1.2 million. Demands reached $150 million, payments reached $75 million, and 50 payments were at least $10 million. Conclusively, ransomware is the primary driver of losses in the report.

Business Interruption Costs

Business Interruption (BI) costs were reported for 316 incidents and has continued to grow since 2020. The five-year average BI cost was about $1.2 million, with average incident cost at about $1.8 million; in 2024, BI averaged $611,000 and incident cost averaged $630,000.

Types of Data Involved in Claims

For cleaner analysis, claims were assigned categories for all revenue sizes. The three most common claim types were Others/Unknown (76%), Personally Identifiable Information (PII) (13%) and Health Information (PHI) (3%). PII claims are cases where sensitive data of specific individuals is exposed, stolen, or compromised. PHI claims are cases where individuals’ medical records, health insurance details, or patient treatment histories are compromised. A less known claim type is the “Files — Critical” claim. This category was created in 2018 for incidents that do not expose records, like in an incident where a ransomware event locks a database, or locks an essential network. The “Other/Unknown” is a “catch all” category that groups together all the remaining data.

The next NAIC H Committee meeting will be held in November 2026.

We’re Here to Help

As Mark Greisiger, President and CEO of NetDiligence, put it, these findings show why organizations of every size need both strong cyber defenses and a response plan they can act on when an incident occurs. As cyber threats continue to grow in frequency and cost, having the right advisors in your corner matters. Our team helps clients assess cyber risk, strengthen internal controls, and prepare for the financial and operational impact of a breach. If you would like to discuss how this might impact your insurance entity, contact your JLK Rosenberger team member, call 818-334-8646, or click here to contact us. We look forward to speaking with you soon.

Author
Oscar Gutierrez

5 minute read

Interested in Learning More?

Our Team is Here to Help.

Let's Talk