European cyber pricing continues to soften despite elevated losses, expanding digital dependencies and growing regulatory and AI-related exposures, writes LSM’s head of cyber and tech E&O for Europe, Oliver Delvos

At a time when cyber risk is intensifying due to AI-enabled threats, expanding digital dependencies and evolving regulatory frameworks, the market is softening. Rates continue to decline, competition remains fierce and the breadth of coverage is increasing. This disconnect between risk and pricing signals an industry approaching a critical inflection point.

Oliver Delvos

Over the past year, Europe’s cyber insurance market has experienced sustained softening. Abundant capacity, combined with Cyber being identified as a promising opportunity for growth, has led to falling premiums and broader terms. Yet this must not necessarily be seen as a reflection of improving risk fundamentals. On the contrary, loss activity continues to evolve in both frequency and severity.

This dynamic stands in contrast to the emerging change in trend seen in the US market, where pricing has stabilised and, in some cases, returned to positive rate movement, and underwriting rigour has largely held. The divergence creates an incoherent global picture, one that may ultimately lead to volatility.

As capacity becomes misaligned with underlying risk, the market is likely approaching a pricing floor. History suggests what may follow is a potential market correction, although whether this will mirror the severity of the 2020 hardening cycle remains to be seen.

Adding to this uncertainty is the prospect of consolidation among carriers and increased investment in insurance technology. As margins tighten, only those insurers able to combine scale with sophisticated risk assessment capabilities will remain competitive.

Artificial intelligence (AI) is not introducing entirely new cyber threats; rather, it is amplifying and accelerating existing ones. What is new, however, is the evolving shift from automation to autonomy. Threat actors are now leveraging AI to dramatically increase the speed, scale and efficiency of attacks, including identifying vulnerabilities and automating parts of the exploitation process.

AI-driven tools test entry points and increasingly execute exploits with minimal human intervention, chaining together multiple low-severity issues into one interconnected, exploitable path. This evolution lowers the cost of attacks and the barrier to entry for cybercrime, enabling less sophisticated actors to operate with unprecedented effectiveness.

The implications are profound. Loss scenarios that were once the domain of large enterprises are rapidly becoming baseline exposures for mid-market companies and SMEs as these tools become more accessible. As AI tools become more democratised, the attack surface expands, not just in size, but in accessibility.

The profile of cyber losses is also shifting. Traditional cyber incidents such as system outages or data breaches are increasingly being supplemented, or even replaced, by losses such as identity compromise of valid user accounts, leading to system access and data exfiltration, fraud and governance failure.

At the same time, attackers are reviving and modernising older tactics. Situations where compromised credentials are used to run high-volume computing workloads on victims’ infrastructure are resurfacing in new forms. These attacks can generate significant financial losses through inflated energy and IT costs, echoing earlier waves of exploitation.

We are also seeing more sophisticated attack methods, including AI-driven impersonation, manipulated documentation and attacks targeting multi-factor authentication through reset mechanisms, further challenging traditional controls. The latter will put further emphasis on having properly functioning controls without gaps in their implementation. Additionally, patching cycles will need to compress further to reduce patching gaps to the lowest possible measure.

In parallel, regulation is increasing, especially in Europe. where new sets of rules are emerging as a critical, and often underestimated, driver of investment in IT resiliency and supply chain security.

A wave of legislative developments, including the EU AI Act, the Cyber Resilience Act, Network and Information Security Directive 2 (NIS2), Digital Operational Resilience Act (DORA) and updates to the Product Liability Directive, are reshaping the governance and liability landscape.

At the same time, GDPR is set to become more relevant once again as AI-enabled tools make it easier to identify, pursue and increasingly automate claims under its statutes. As courts are building a growing body of case law that more clearly quantifies damages, liability exposures across both cyber and technology errors and omissions lines are likely to increase, with greater implications for compliance failures and defence costs.

As already mandated by DORA for Financial Institutions, the question of resiliency now fully extends to third-party IT providers and managed services firms as they are a critical point of failure. Those supply chain risk is now extending to physical suppliers and operational dependencies. A cyber event affecting one node in the supply chain can cascade across multiple organisations, triggering widespread disruption across both digital and physical environments.

Coverage has evolved to reflect this, but with greater breadth comes greater complexity. Insurers must move beyond individual risk assessments to adopt a more in-depth portfolio-level view of dependencies and systemic exposures accounting for various supply chain scenarios.

As we noted on the supply chain above, one of the most significant developments in recent years is the emergence of cyber-physical risk. Cyber incidents are increasingly capable of causing tangible damage from property destruction to operational shutdowns, including disruption to integrated production environments and robotics.

This is particularly evident in environments where operational technology is integrated with IT systems. Business interruption losses linked to cyber events are becoming more common, and often more severe.

However, underwriting cyber-physical risk presents unique challenges. There is limited historical data, valuation methodologies vary across lines of business, and traditional boundaries between cyber, property and potentially energy policies are becoming blurred. The implication is clear: cyber risk can no longer be underwritten in isolation. It must be understood as part of a broader risk ecosystem. Insurers need continuous monitoring, real-time visibility and advanced analytics to understand and manage risk effectively.

Risk selection is paramount. Some leading insurers are investing heavily in proprietary tools, AI-driven vulnerability scanning and integrated cyber risk engineering capabilities to enhance decision-making. The ability to combine data, technology and expertise will define underwriting excellence in the years ahead.

One of the more complex and still evolving questions facing the industry relates to the impact of artificial intelligence across insurance portfolios. Much like the industry grappled with “silent cyber” a decade ago, attention is beginning to turn to how AI-related risks Shape the risk landscape in other lines.

AI-related liabilities may already be accumulating across multiple lines of business, often without explicit recognition or pricing, raising broader questions about how these exposures are identified and managed.

While this remains an area of ongoing consideration rather than a fully defined market position, it highlights the need for continued clarity on how emerging technologies intersect with established insurance coverages.

As the market approaches a potential turning point, discipline and fundamentals will become increasingly important. Insureds must prioritise core cyber hygiene and robust identity and access management, alongside patching, monitoring of edge devices and effective change management.

For insurers, the future will not be defined by how much capacity is deployed, but by how intelligently risk is understood, priced and allocated. This includes anticipating emerging threats, navigating regulatory complexity and investing in the tools and talent needed to stay ahead.

The European cyber insurance market is entering a period of heightened uncertainty. But within that uncertainty lies opportunity for those prepared to adapt. In a world shaped by AI, interconnected systems and evolving liabilities, success will depend on clarity, agility and, above all, a deep understanding of risk in all its forms.