Cyber · October 2026
A ransomware invoice is not a property claim
Commercial cyber insurance
If a hurricane takes the roof, your property policy is built for that fight. If ransomware locks the point-of-sale system — or someone in the office wires Friday’s payroll to a fake vendor — that same policy usually will not even open the file.
That second fight is what commercial cyber insurance is for. What is new in early fall 2026 is the mix carriers and claims teams are actually talking about: business-email and wire fraud that still account for most claims, ransom demands that now start in seven figures even as most businesses refuse to pay, a vendor or VPN hole that becomes your downtime, and a Florida statute that gives you 30 days to notify people after a breach.
The claim that still shows up most
The price of cyber, for a clean account, has been falling for three years. Marsh’s second-quarter 2026 index put global cyber renewals down 4 percent — the twelfth straight quarterly decline — and U.S. cyber down 2 percent. Willis Towers Watson’s spring update had typical cyber in a minus-5 to plus-5 percent range. Cheap premium is not the same thing as a cheap claim.
Coalition’s 2026 claims report, built on 2025 files across more than 100,000 policyholders, said business email compromise and funds-transfer fraud were 58 percent of the incidents it saw. BEC was the single most common claim type. Funds-transfer fraud — the money actually leaving — was 27 percent of claims, with an average loss of $141,000. At-Bay, looking at more than 6,500 claims, said financial fraud was its most frequent incident type, 30 percent of the book, and that the average amount stolen was $285,000.
The World Economic Forum’s 2026 cybersecurity outlook found that CEOs now rank fraud and phishing ahead of ransomware. Security chiefs still worry more about the locked network. Both groups are looking at the same year. They are just naming different invoices.
A Florida contractor changing a sub’s wiring instructions, a property manager redirecting rent or HOA ACH, a restaurant group changing the produce vendor or the payroll account — that is the everyday file. The email looks like the owner. The invoice looks like last month’s. The money is gone before anyone calls the bank. Defense of the network is not the same coverage as getting the wire back.
If the screens lock, the property policy usually will not open
Ransomware is not the most common cyber claim. It is still the one that can close the shop.
Coalition said the average first ransom demand in 2025 was just over $1 million, up 47 percent, and that 86 percent of the businesses in those files refused to pay. Dual extortion — lock the systems and steal the data — was 70 percent of its ransomware claims and more than twice as expensive as encryption alone. At-Bay put average ransomware severity at $508,000. For companies under $25 million in revenue, severity was up 40 percent, to $422,000. Claims that included business interruption were three times worse than claims that did not. One in ten of those victims was down more than 30 days.
Verizon’s 2026 Data Breach Investigations Report — more than 22,000 confirmed breaches — found ransomware in 48 percent of breaches. Sixty-nine percent of victims did not pay. The median ransom that was paid was $139,875. Refusing the invoice does not reopen the dining room, the job trailer, or the chart.
A commercial property or businessowners policy is built for direct physical loss. A screen that will not unlock is not a burned kitchen. Courts have already said software does not suffer “physical damage” in the way that form requires, and the cyber exclusions that have been going on property and general-liability policies since the early 2020s were written to end the argument. The ransom note, the forensic bill, the extra payroll to rebuild the server, and the weeks of lost receipts sit on the cyber form — if you have one.
IBM’s 2026 Cost of a Data Breach study, a large-organization sample, put the U.S. average breach at $11.5 million and kept healthcare as the most expensive industry, at $6.64 million. A Jupiter medical office or a 40-seat restaurant will not see that number. It will see a weekend it cannot take a card, a Monday it cannot open a chart, and a vendor who wants to be paid from a system that is still offline.
Your vendor’s hole is your downtime
Attackers are not always picking you. They are picking the box you already own.
At-Bay said 73 percent of its 2025 ransomware claims started on a VPN — almost double the share from two years earlier — and that SonicWall was the most-targeted brand, in about one in three of those ransomware files. Coalition, where the compromised technology was confirmed, found VPNs in 59 percent of ransomware incidents. A login panel sitting on the public internet made a claim three to four times more likely. Verizon said breaches with a third party in the chain reached 48 percent of its 2026 dataset, up 60 percent from the year before.
That is the Florida version of Change Healthcare: the billing vendor, the reservations platform, the payroll company, the MSP who owns the firewall and the backups. A contractor whose cameras and job files run through one remote-access box in the shop. A property manager whose tenants pay through a portal the manager does not write. A medical office that never touched the ransomware and still cannot send a claim.
Florida’s breach statute already treats that vendor as your problem. If a third-party agent — the MSP, the biller, the payroll firm — has a breach of your people’s information, it has ten days to tell you. You still own the notices to the people and, if enough of them are in Florida, to the Attorney General. The vendor’s contract almost never picks this up the way you think it does.
The expensive claim a cheap cyber add-on usually will not pay
A lot of packages sell “cyber” as an endorsement on the businessowners policy. AM Best’s 2025 figures, written up in July 2026, put the average premium on those endorsements at $151, against $2,287 for a primary cyber policy. Endorsements are most of the policy count. Primary policies are most of the premium. Those are two different products.
The gap that shows up after a wire is social engineering. Coverage lawyers at Hunton Andrews Kurth — writing in Insurance Journal in June, from Miami — said many cyber forms still treat a voluntary transfer as a fraud loss, not a network loss, and point you to the crime policy. The crime policy often excludes the same fact pattern unless someone bought the social-engineering endorsement. When that endorsement exists, it is commonly capped at $250,000 or less, sometimes sitting under a retention that is larger than the sublimit. Construction and real estate accounts that regularly move seven figures are the ones Hunton named.
Some specialist cyber markets do pay funds-transfer fraud on their own form and will chase the bank. Coalition said it clawed back $21.8 million in 2025. At-Bay said accounts that reported inside three days recovered money 70 percent of the time; after 30 days, 27 percent. Speed is part of the coverage. So is reading the line that actually applies to a spoofed owner email — eCrime, social engineering, funds-transfer fraud, fraudulent instruction — and the dollar figure next to it, not the $1 million on the declarations page.
Silent coverage, a small endorsement, and a primary policy with a real social-engineering limit are three different programs. Know which one you have before the controller hits send.
Florida’s 30-day clock
Florida did not pass a new cyber-insurance rule for ordinary businesses in 2026. It already has a short clock.
Under section 501.171, Florida Statutes, a covered business that has a breach of personal information has to notify each affected person in this state as soon as it can, and no later than 30 days after it determines a breach happened or has reason to believe one did. If 500 or more Floridians are involved, the Department of Legal Affairs — the Attorney General — gets the same 30-day notice. If more than 1,000 people must be notified at once, the credit bureaus do too.
“Personal information” is wider than a stolen credit-card file. It includes name plus Social Security number, driver license, account number with the password, medical history or treatment, health-insurance ID, biometric data, or geolocation — and a username plus password that opens an online account. A restaurant’s reservation book, a property manager’s tenant file and gate fob, a contractor’s payroll, a medical office’s chart can all trip it.
Missing the notice can be treated as an unfair or deceptive trade practice. The civil penalty is calculated per breach, not per person, and can reach $500,000. The statute does not give the customer a private lawsuit by itself. It does give the Attorney General one. Forensics, outside counsel, and those letters are first-party cyber costs. They are not a property claim, and they are not something to start drafting in week five.
Tell your lawyer and your insurance company the same week you have reason to believe the file walked. The vendor who holds the data has ten days to tell you. You do not get to wait for a comfortable report.
What we want you to do this month
- Confirm you actually have a standalone cyber policy — not just a $151 endorsement on the businessowners package, and not just the property and general-liability policies that pay a hurricane or a slip-and-fall.
- Ask whether social engineering, funds-transfer fraud, and business email compromise are on the form, at what sublimit, at what retention, and whether a callback or other verification condition has to be followed before a wire.
- Ask whether cyber business interruption is included, how long the waiting period is, and whether a vendor or cloud outage (contingent BI) is covered or carved out.
- Get the VPN, remote-desktop, and firewall off the public internet if they do not need to be there. Turn on multifactor authentication on email and on any remote access. Test a restore from backup that the attacker cannot also encrypt.
- Write down who you call in the first four hours — carrier claim line, bank recall, the MSP — and who signs the Florida notices if the 30-day clock starts.
We can review the form you already have, or shop a standalone cyber quote.
Or call 561-529-4949.
