Room to boom
The maturing cyber insurance market is tipped to reach new heights by the end of this decade
By Harris Pozderovic
Howden’s fourth annual cyber report – titled Risk, Resilience and Relevance – provides an outlook for huge market growth, but says this can only be achieved if the industry builds on existing momentum.
The broker hails strong risk controls and stable market conditions as key features of its projection, highlighting the “untapped potential” for growth.
The report, which analyses trends in the cyber market, says: “The foundations are now in place for the next phase of development, with opportunities in international geographies and other underserved areas poised to drive growth.”
The strong outlook is spurred by a renewal in market competition, improvements in insurers’ ability to manage claims and returns on investment in technical expertise.
There has been a drop in the average cost of claims and a 15% reduction in premiums since peak 2022 numbers.
“After a period of upheaval – characterised by a rapidly deteriorating loss environment, highly constrained insurance capacity, rising demand globally and a major (perhaps overexaggerated) pricing correction – market conditions have improved over the past 12 months,” Howden says.
“Pricing is now falling, and competitive forces are yielding more tailored underwriting decision-making that reflects companies’ risk profiles.”
Howden projects global cyber premium will be close to $US43 billion by 2030 (current written premium is $US15 billion). The figure marks a slight drop from last year’s forecast, largely due to below-expected performance from the US market, which dominates the sector.
The global broker says those results should incentivise insurers to make breakthroughs in markets outside the US, which it has outlined as one of two “standout opportunities” for the cyber market to maximise its potential.
The report says 54% of projected premium growth to 2030 is driven by non-US markets, particularly Europe.
And it says expansion in the SME market is key to the projections, highlighting that client base as an “incubator of innovation with high growth potential” that has historically been “underserved by the cyber insurance market”.
“Now that pricing tailwinds are reversing, the market needs to refocus on innovation to grow its exposure base and achieve the growth trajectories outlined … By focusing on key issues within its control – including SME penetration (eg easing the buying process), geographic expansion and continued model development – the market can secure long-term relevance,” Howden says.
Resilience to cyberattacks remains a vital indicator of the industry’s strength, with the broker noting ransomware is the costliest form of attack, accounting for more than $US1 billion in losses last year.
Ransomware attack numbers were up by 85% last year compared with 2022 and are expected to rise again this year.
However, the broker says the frequency “only tells part of the story from a loss perspective”, noting losses were driven mainly by downtime costs rather than ransom payments.
There has been a downward trend in the number of victims paying ransoms since 2019. Howden warns an increase in state-affiliated activity is another uncertainty for insurers, with a sharp rise in such attacks in recent years, most notably from Russia and China.
While ransomware is an “ever-present threat”, there are concerns around generative AI and other new technologies that attackers could harness to beat cyber protections. The report says such technologies, which are also used to improve client security, could be a “double-edged sword”.
The broker anticipates public access to AI technologies will “push up the potential aggregation, severity and frequency of claims in predictable areas by enhancing the capabilities of commercial hackers.
“The main implication of AI-driven democratisation of hacking will be a rise in the frequency of low-level claims. Novice threat actors will find it easier to carry out phishing, which was the vector used in 84% of UK business attacks in 2023.
“They will have also access to chatbots to help draft high-quality phishing content, akin to ChatGPT without guardrails, AI-generated reconnaissance on which businesses to target (e.g from machine leaning trained to spot patterns in vulnerability) and even AI-generated ransomware code.”
Howden acknowledges threats from AI systems are “relatively unknown” with the technology still in an early stage of development. It concludes AI’s net impact “will inevitably depend on how defenders respond”, with the industry optimistic about its ability to ward off attacks based on the capabilities of existing systems.
“Gen AI brings opportunities for both cyberattackers and defenders and looks set to significantly impact the threat landscape by enabling more advanced attacks from sophisticated actors and lowering barriers to entry for novice hackers,” Howden says.
“The good news is that new AI-driven defences are developing at pace and effective use of more traditional risk controls can shore up resilience.”

















