NetDiligence 2026 Study: Cyber Ransom Demands Hit $500M as SME Risks Surge
By Lauren Towner · 16 September 2026

NetDiligence®, a leading provider of cyber risk readiness and response solutions, today released its 2026 Cyber Claims Study, a data-driven analysis of 10,309 real-world cyber insurance claims from incidents occurring between 2021 and 2025.
Sponsoring this year's study are RSM, Experian, Surefire Cyber, and Constangy, Brooks, Smith & Prophete, LLP.
Now in its sixteenth year - grown from fewer than 100 claims analyzed in the study's 2010 debut - the report remains the cyber insurance industry's most comprehensive benchmark of what cyber incidents actually cost, drawing on claims contributed directly by leading cyber insurers.
This year's findings show a market still defined by extremes. Ransom demands climbed as high as $500 million, with payments reaching $90 million - both new highs for the study. At the same time, large companies (just 3% of claims) again accounted for more than half of all incident costs (56%), a reminder of how dramatically scale changes the cost of a cyber event.
"Every year, this study reminds us how wide the range of cyber loss really is - from claims under $1,000 to a single incident that topped half a billion dollars," said Mark Greisiger, President of NetDiligence. "What stands out in this year's data is how much ransomware and business email compromise still drive that range. Together they now touch nearly 64% of SME claims in 2025 alone. We need to remain persistent in our efforts to concisely demonstrate the financial impact of cyber risk to the Main Street business that still remains uninsured or underinsured."
Key Highlights:
- 10,309 total claims analyzed from incidents occurring 2021–2025
- 4,825 new and updated claims collected in 2025, including 1,780 from 2025 events
- Ransomware and Business Email Compromise (BEC) remain the top causes of loss, together touching over half of SME claims
- Ransom demands and payments reached new highs - up to $500M demanded and $90M paid, with 59 payments ≥$10M
This year's dataset was built with contributions from leading cyber insurers, spanning organizations from under $10K to more than $290 billion in annual revenue - a nearly 29-million-fold range. Demographic and financial analyses span 18 business sectors, 7 revenue groupings, 25 causes of loss, and 13 types of data.
SMEs vs. Large Enterprises
As in prior years, small to medium enterprises (SMEs) - organizations with less than $2 billion in annual revenue - accounted for the vast majority of claims (97%). Yet large companies, just 3% of the dataset, represented 56% of all incident costs, driven by their scale and complexity. The average large company in the dataset ($10.1 billion in revenue) was nearly 100 times the size of the average SME ($105 million).
Across all claim sizes, business interruption, legal, and crisis-response costs remained significant contributors to total loss. At SMEs, incidents involving business interruption cost more than five times as much, on average, as those without it. At large companies, legal and regulatory costs averaged over $22 million per claim, with one settlement alone exceeding $500 million.
Registered users of the eRiskHub® cyber risk management portal, powered by NetDiligence, can also access the full study and sector-specific companion reports in their portal, alongside additional tools and resources built on the study's data.
Companies in this story: NetDiligence
People in this story: Mark Greisiger