What happened
The average cost of cyber insurance claims surged in 2025 even though the volume of claims fell, according to Chubb's 2026 Cyber Claims Report, published August 25. In the US, the average claim cost rose 22% for middle-market firms and 100% for large companies. In the UK and Europe, middle-market severity rose 34% and large-firm severity rose 98%.
Chubb attributes the jump to growing severity: more expensive data breach and privacy-related litigation, plus rising business interruption costs. US averages sit far above UK and European averages because of third-party litigation expenses, which the report says are largely absent in the latter region. For SMEs, claim frequency rose in both regions, with the US average cost falling from $215,297 to $141,931 while the UK and Europe average rose from $51,095 to $82,621.
The insurer also flagged the compliance layer. A growing body of US and EU privacy laws is imposing layered obligations on companies that store or transfer personal data, including opt-out rights for profiling and automated decision-making and disclosure requirements for AI-driven processing. Ransomware actors who leak data alongside encrypting it are increasing litigation risk for victims under data protection laws, and in the US, non-refundable administrative fees can exceed $10 million in a 10,000-claimant suit before the merits are even heard.
Why this is a GRC story
Cyber insurance is a risk-transfer control, and these numbers tell risk teams where exposure actually concentrates: litigation and business interruption, not just ransom payments. If the cost of a breach is increasingly a legal cost, then compliance maturity is not a side topic, it is the main driver of claim severity.
The report connects the dots between privacy law and incident cost. Every state or EU privacy requirement a company has not operationalized becomes a claim dollar when data gets out. The leak-and-encrypt trend matters because it turns an operational incident into a class-action trigger, and the administrative fee structure means even weak claims carry real cost.
What to watch
Watch whether premiums for large firms follow severity, and whether insurers tighten the control requirements they impose on policyholders. The report's own logic suggests underwriters will demand documented privacy and incident-response programs, not just firewalls and endpoint tools.
For SMEs the picture is mixed: US averages fell while UK and Europe averages rose, and frequency is up everywhere. If your company is shopping for coverage, the practical takeaway is that your data inventory, retention practices and breach response plan will increasingly decide both your premium and your payout.
Attribution: Analysis based on Infosecurity Magazine's reporting and Chubb's 2026 Cyber Claims Report. This article is original commentary, not a repost of the source material.
