Cyber insurance in 2026 is a buyer’s market with a strict doorman: European premiums fell 9% in the first quarter, but no insurer will write you at those rates while a legacy VPN or half-deployed MFA sits on your perimeter. Remote access services were the entry point in 87% of ransomware claims, and legacy VPN compromises alone drove 73% of intrusions with a known vector — so underwriters now scan your attack surface before quoting, and price exactly what they find. That makes the premium conversation a security-architecture conversation.
Key takeaways
- The market is soft — Continental European cyber rates dropped 9% in Q1 2026 after a 12% fall in Q4 2025 (Marsh) — but only organisations that clear the control baseline capture those reductions.
- Hard prerequisites, not premium factors: universal MFA, EDR on 100% of endpoints, immutable offline backups and a 14-day critical-patch SLA. Missing any of these means decline or exclusions.
- The claims data points one way: 87% of ransomware claims entered via remote access services, 73% of identified intrusions via legacy VPNs (up from 38% in 2023), 58% via perimeter appliances, 18% via exposed RDP.
- Misrepresentation is fatal: in Travelers v. ICS, claiming enterprise-wide MFA while it only covered the firewall got the policy rescinded ab initio — void from day one.
- Belgian mid-market premiums run roughly €2,500 to €35,000 per year; policyholders in active security programmes file 73% fewer claims than the market average.
What does the 2026 insurance market look like?
Four consecutive years of softening, per Marsh’s European rate index: abundant capacity, twelve straight quarters of global price declines, and insurers competing hard for well-controlled risks. But the same carriers deteriorated their margins in the 2020–2021 ransomware crisis and have not forgotten it. The result is a two-tier market: broad terms and multi-year agreements for organisations that prove their controls, and refusals, sub-limits or punitive terms for those that cannot. Underwriters no longer take your word for it — external attack-surface scans run before any binder is issued, checking for open RDP, exposed login panels and unpatched edge devices. More than 65% of applicants expose at least one web login panel; discrepancies between the questionnaire and the scan end the conversation.
The checklist: prerequisites versus premium factors
| Control | What insurers require | Status | Impact |
|---|---|---|---|
| Multi-factor authentication | On remote access, VPN/ZTNA, email, cloud apps, admin and privileged accounts — everywhere | Hard prerequisite | Partial deployment risks decline or rescission |
| Endpoint detection & response | Behavioural EDR on 100% of servers and workstations | Hard prerequisite | Non-negotiable baseline |
| Immutable/offline backups | Air-gapped, encrypted, restore-tested | Hard prerequisite | Mandatory for ransomware cover |
| Patch management SLA | Critical perimeter vulnerabilities remediated within 14 days | Hard prerequisite | EOL edge appliances trigger refusal or exclusions |
| ZTNA / zero-trust architecture | Identity-verified access, micro-segmentation, no legacy VPN | Premium factor | Unlocks top-tier discounts in the soft market |
| Incident response plan + retainer | Formalised, annually tested, third-party IR firm on call | Premium factor | Lowers deductibles and overall cost |
| Security awareness training | Continuous phishing simulation | Premium factor | Cuts BEC/fraud claim frequency, improves renewals |
What the claims data says about your VPN
The remote-access numbers are the sharpest in the dataset. Coalition’s claims telemetry puts remote access services at the entry point of 87% of ransomware claims, up from 80%. Where the intrusion vector was identified, legacy VPN compromises accounted for 73% — a three-year climb from 38% in 2023 through 66% in 2024, driven by automated exploitation of CVEs in Fortinet, Ivanti and Citrix appliances. Perimeter security appliances initiated 58% of ransomware attacks; exposed RDP another 18%. Stolen credentials opened 47% of ransomware claims and unpatched software 29%. Outside ransomware, business email compromise and funds-transfer fraud make up 60% of claims, with BEC severity up 23% year-over-year.
Underwriters read the same tables, which is why the questionnaire asks precisely what VPN you run, what firmware it is on, and who can reach it — the same exposure quantified for the Benelux in the legacy VPN risk report, and illustrated in practice by the AZ Monica hospital attack.
What do controls actually earn you?
- Fewer claims: policyholders in active security programmes — continuous external scanning plus prompt remediation — experience 73% fewer claims than the market average.
- Lower rates: compliant organisations ride the market’s 5–9% annual reductions; control gaps mean penalties, reduced limits or refusal regardless of the soft cycle.
- Better claim outcomes: reporting funds-transfer fraud within 72 hours qualifies for reduced retentions, and insurer IR panels negotiate ransom demands down by an average of 60% when payment is unavoidable.
The traps: how coverage evaporates
The precedent every broker cites is Travelers v. International Control Services (2022): the application, signed by leadership, asserted enterprise-wide MFA; forensics after the ransomware breach found it only on the external firewall. The court rescinded the policy ab initio — void from inception, premiums returned, every claim gone. The same logic runs through “failure to maintain controls” clauses: declare a control, let it lapse, and the carrier is off risk for the incident, as happened when the City of Hamilton’s partially deployed MFA led to a denial. Add the standard exclusions — state-sponsored attacks under war clauses, and “betterment” clauses that pay to restore your old environment but never to upgrade it — and the pattern is clear: insurance rewards controls that exist and punishes controls that were claimed.
The Belgian picture
Mid-market cyber coverage in Belgium is written by global carriers (AXA XL, Allianz Commercial, Chubb, Baloise, HDI Global, Beazley) and control-focused MGAs such as Coalition and Stoïk that bundle continuous monitoring into the policy; brokers like Vanbreda, ADD, Marsh Belgium and Aon steer the questionnaires. Typical annual premiums run from €2,500 for well-controlled lower-risk profiles to €35,000 or more for complex or higher-risk operations, priced on turnover, sector, data volume and verified control maturity. One boundary matters: insurance transfers financial risk but never substitutes for NIS2 compliance — policies exclude administrative fines where the law prohibits indemnifying them, and no policy shields directors from the personal liability described in NIS2 enforcement in Belgium. Conveniently, the NIS2 control set and the insurer checklist are nearly the same list — build once, satisfy both.
The best-insurability-per-euro sequence
- Universal MFA — closes the 47% stolen-credential vector and eliminates the rescission risk that killed the ICS policy.
- EDR everywhere — counters the 29% software-exploit vector and satisfies a hard prerequisite.
- Replace the legacy VPN with ZTNA — removes the single largest claims driver (73% of identified intrusions, 58% perimeter-appliance attacks) by deleting the exposed listening ports entirely, and moves you into the top underwriting tier where the discounts live. Insurer scans then find nothing to flag: no VPN portal, no open RDP.
- Immutable backups — the ransomware-coverage precondition and your leverage against paying at all.
- IR retainer + awareness training — trims the 60% BEC/fraud claim block and improves renewal terms.
Make the underwriter’s scan come back empty
Priorities one and three converge on a single architectural move. A ZTNA platform enforces MFA on every access by design, publishes no inbound ports for the insurer’s scanner — or an attacker’s — to find, and segments users to applications instead of networks, with the device-posture checks underwriters increasingly ask about built in. That is precisely what Jimber delivers for EU mid-market organisations: MFA-enforced zero-trust access, no exposed VPN portal, segmentation and central logging on one EU-sovereign platform, replacing the end-of-life appliances that underwriters flag — at a flat, predictable cost that makes the insurance business case easy to write down. What a specific policy does with your premium is between you and your broker; what the claims data says is not ambiguous. Book a demo before your renewal questionnaire lands, and answer its remote-access section with a straight face.
Frequently asked questions
Can an insurer deny a claim if MFA was on our VPN but missing on admin accounts?
Yes. Travelers v. International Control Services established that claiming enterprise-wide MFA while it covered only the perimeter is material misrepresentation, allowing the insurer to rescind the policy ab initio — void from inception, all claims lost.
How does replacing a legacy VPN with ZTNA affect our premium?
Legacy VPN compromises account for 73% of ransomware intrusions with a known vector, so removing exposed listening ports repositions you in the highest underwriting tier — the tier that captures the soft market’s 5–9% annual rate reductions and the broadest terms.
What happens if we’re breached through an unpatched VPN appliance?
If your policy carries a failure-to-maintain-controls clause, or the vulnerability exceeded the mandated 14-day critical-patch SLA, the carrier can decline coverage for losses from that breach.
What does cyber insurance cost a Belgian mid-market organisation?
Typically €2,500 to €35,000 per year for organisations of 50–1,000 employees, depending on turnover, sector risk, data volume and verified control maturity.
Are premiums rising or falling in 2026?
Falling — Continental European cyber rates dropped 9% in Q1 2026 and global rates 4% in Q2, the fourth consecutive year of softening. The reductions flow only to organisations that meet the control baseline.
Does NIS2 compliance replace the need for cyber insurance, or vice versa?
Neither replaces the other. NIS2 mandates operational controls; insurance transfers residual financial risk. Policies cannot pay statutory fines where the law prohibits it, and offer no protection against personal director liability or suspension orders.
Why do insurers scan our systems before quoting?
External attack-surface scans independently verify the questionnaire: open RDP ports, exposed login panels, unpatched edge devices, compromised credentials. A mismatch between attestation and telemetry means rejection or mandatory remediation before binding.
Will insurance pay to upgrade our infrastructure after an attack?
Generally no. Betterment exclusions limit payouts to restoring systems to their pre-incident state; security improvements beyond that baseline are your own investment — one more reason to make them before the incident.