What are the key sales KPIs for the Cyber-Insurance Carriers industry in 2027?
PULSEKNOWLEDGE LIBRARY
Cyber-insurance carriers in 2027 run on nine sales and underwriting metrics: direct written premium growth, loss ratio, combined ratio, average premium per insured, ransomware claim frequency per 1,000 policies, average ransom demand trend, vendor-endorsement pull-through, sub-limit negotiation rate, and renewal retention. Together they show whether premium growth is outrunning claim severity.
The outcome you should expect
A carrier that instruments those nine metrics properly stops arguing about anecdotes within one quarter. The change is not that the numbers get better immediately — often they get worse on paper, because the first honest reconciliation between the policy administration system, the claims system, and the broker management system surfaces claims that were never allocated to the right book, and premium that was booked in the wrong segment. Expect that gap. Every carrier that has done this exercise finds it, and the size of the discrepancy is itself the first underwriting finding worth taking to the chief underwriting officer.
What you should expect after the instrumentation settles is a specific set of behavioral shifts in the sales and distribution organization. Underwriters stop treating sub-limits as a concession they grant reluctantly at the end of a negotiation and start treating them as a priced feature they open with. Brokers stop being measured purely on submitted volume and start being measured on bind quality — what share of their submissions clear the security-control floor without a remediation round. Risk-engineering teams, who in most carriers sit awkwardly between underwriting and claims, get a number that belongs to them: pull-through, the share of bound policies that came through an endorsed-vendor referral or an active engineering session.
The financial outcome is narrower than the operational one. Realistically, a mid-market cyber book that goes from ad-hoc metric tracking to disciplined weekly review does not swing its loss ratio twenty points in a year. Loss ratio is a lagging, long-tailed number — incurred-but-not-reported development on a cyber claim can run twelve to twenty-four months, because forensics, business-interruption quantification, and third-party liability all resolve on different clocks. What moves first is the leading set: quote-to-bind conversion, sub-limit attachment, pull-through, and the mix of submissions clearing the control floor. Those move within a quarter. Loss ratio follows them by roughly a year.

The other thing to expect is friction with distribution. When a carrier tightens its control requirements — multi-factor authentication across all remote access and privileged accounts, endpoint detection and response coverage on effectively every endpoint, immutable or air-gapped backups with tested restores, and a documented, exercised incident-response runbook — some percentage of the incumbent book simply cannot meet them at renewal. That shows up as a retention dip before it shows up as a loss-ratio improvement. Carriers that panic at the retention dip and quietly grant exceptions undo the entire exercise. The discipline is to accept a retention number in the low eighties for two or three renewal cycles while the book re-sorts, then watch it climb back as the remaining insureds are the ones who invested in controls.
A related outcome worth naming: the sales conversation itself changes shape. Cyber is one of the few insurance lines where the carrier can credibly tell a prospect "here is what you should fix, and if you fix it we will price you differently." That is closer to a security-vendor sales motion than a traditional property-and-casualty one, and carriers that staff it that way — technical pre-sales alongside underwriting — see the pull-through metric respond first.
What drives that outcome
The mechanics underneath cyber insurance are genuinely different from other lines, and the metrics only make sense once you see why.
Frequency and severity move together. In auto or homeowners, claim frequency wobbles with weather and driving patterns while severity drifts up slowly with repair costs. Cyber inverts this. Frequency cycles with attacker capacity — the availability of ransomware-as-a-service kits, the discovery of a widely deployed edge-device vulnerability, the recruitment cycles of affiliate crews — and severity grows with how much of the insured's revenue depends on continuously available systems. Both can spike in the same quarter from the same cause. A single widely exploited vulnerability in a file-transfer product or a managed-service-provider platform produces a correlated loss event across dozens of unrelated insureds at once. That correlation is the thing traditional actuarial models handle worst, and it is why cyber reinsurance treaties carry event-definition language that other lines never needed.

Vendor endorsement is the underwriting flywheel. Carriers reduce loss ratio not only by pricing risk but by changing it. A carrier that pre-vets a managed detection and response provider, an identity provider, and a backup vendor, then routes insureds toward them — sometimes with premium credits, sometimes with bundled licensing — is buying down its own claim frequency. The measurable version of that is pull-through: what share of bound policies came through that channel. Carriers report meaningfully lower loss ratios on referred business than on cold-broker business, and the causal story is straightforward, though selection bias is real — organizations willing to adopt an endorsed stack were probably better risks to begin with. Any carrier claiming a pull-through loss-ratio differential should be able to show it after controlling for revenue band and industry.
Sub-limits, not headline limits, determine the loss outcome. A policy sold at a $10 million limit may carry a $2 million extortion sub-limit, a separate business-interruption sub-limit with a twelve-hour waiting period, a dependent-business-interruption sub-limit that is smaller still, and a distinct third-party liability tower. The headline number is what the broker markets; the sub-limits are what the carrier actually owes. In the post-reset market, writing without stated sub-limits on the high-severity categories is close to malpractice, which is why sub-limit negotiation rate belongs on the metric list at all — it is a discipline gauge, not a growth gauge.
Reinsurance sets the envelope. Cyber carriers do not underwrite freely. Treaty terms — event definitions, aggregate caps, war and infrastructure exclusions, cession percentages — define what the direct carrier can write and at what net retention. When treaty capacity contracts, the effect reaches the sales floor within weeks: appetite letters narrow, industry classes get shut off, limits get cut. A sales leader who does not know the treaty calendar will be blindsided by a mid-year appetite change and will have already promised capacity they cannot deliver.

The control floor is now a sales qualification step. Ten years ago cyber was underwritten off a two-page application. Now the front end is scan-and-bind for small commercial and a full risk-engineering assessment for anything above the middle market — external attack-surface scanning, questionnaire attestation, sometimes agent-based telemetry. That means the top of the sales funnel has a hard technical filter in it, and conversion metrics need to distinguish "declined on price" from "declined on controls." Those are different problems with different fixes.
Benchmarks and realistic ranges
Treat every range below as a planning band, not a promise — cyber benchmarks move faster than most lines, and a number that was true across the market in one year can be stale eighteen months later. The value is in the relative structure: which numbers should be tight, which should be volatile, and what a bad reading looks like.
Direct written premium growth. The global cyber market grew at explosive rates through the early 2020s, then compressed sharply when the hardening cycle forced rate increases and appetite contraction simultaneously. Mature carriers now plan for growth in the low-to-mid teens rather than thirty-percent-plus. If your growth is dramatically above market, ask whether you are winning on price — because in a line where the losses arrive a year later, cheap growth is indistinguishable from good growth for about four quarters. If growth is well below market, the usual causes are falling off broker placement panels or an appetite letter so narrow the distribution force cannot find qualifying risks.

Loss ratio. Under 60% is a strong book. Sixty to seventy is normal and sustainable. Seventy to eighty is warning territory where the reinsurance conversation gets uncomfortable. Sustained above eighty is the pattern that preceded the market-wide reset, and at that level the carrier is usually forced into some combination of rate action, non-renewal, and limit reduction. Watch it on a rolling twelve-month basis and always alongside the development triangle — a young accident year with a flattering loss ratio is mostly telling you the claims have not matured yet.
Combined ratio. Loss ratio plus expense ratio. Under 95% is underwriting profit; 95 to 100 is roughly break-even; above 100 means the underwriting operation is subsidized by investment income. Technology-led carriers often carry a heavier expense ratio because they are funding scanning infrastructure and risk-engineering headcount, and they justify it with a lower loss ratio. Whether that trade actually pays out is the central question about the model, and the combined ratio is where you read the answer.
Average premium per insured. This varies enormously by segment, so track it by band rather than in aggregate — small commercial, lower middle market, upper middle market, large account. Aggregate average premium is one of the most misleading metrics in the business, because it moves when mix moves even if pricing is flat. A carrier that adds a large volume of small-commercial scan-and-bind policies will show a falling average premium and rising policy count while its rate adequacy is unchanged. Always decompose the change into rate, exposure, and mix.
Ransomware claim frequency per 1,000 policies. This is the single most informative leading indicator on the list. It responds to attacker activity within weeks and to control requirements within a renewal cycle. Track it by industry class as well as in aggregate — healthcare, manufacturing, education, and municipalities behave differently from professional services, and a book-wide average hides a class that is quietly on fire. A sustained rise across two consecutive quarters is the trigger for a pricing review; a rise concentrated in one class is a trigger for an appetite change in that class only.

Average ransom demand trend. Report both mean and median, because the distribution is severely right-skewed — a handful of very large demands drags the mean far above the typical case. The mean tells you about tail exposure and reinsurance adequacy; the median tells you about the everyday claim. Movement in the mean without movement in the median means the tail is getting fatter, which is a sub-limit and treaty question. Movement in both means the whole distribution shifted, which is a rate question.
Vendor-endorsement pull-through. The best technology-led carriers run this substantially higher than traditional carriers, whose referral channel barely exists. If you are standing the program up from zero, expect low single digits in the first two quarters and treat any steady climb as success. The number is only meaningful if you also track loss ratio for referred versus non-referred business at comparable revenue bands.
Sub-limit negotiation rate. In the current market this should be near-universal on the high-severity categories. Anything materially below that means individual underwriters are granting full-limit extortion or business-interruption coverage to win deals, and the metric's real job is to make that visible by underwriter, by broker, and by deal size before the claim arrives.

Renewal retention. Upper eighties is healthy in a stable market. Below eighty usually means one of two things: the carrier is taking rate faster than the market and losing on price, or a competitor with a stronger risk-engineering offering is winning on service. Those look identical in the retention number and completely different in the loss-reason log, which is why the loss-reason field on every non-renewal has to be mandatory and structured rather than free text.
Quote-to-bind conversion. Useful, but only when segmented. A scan-and-bind small-commercial channel and a large-account risk-engineering channel have entirely different natural conversion rates, and blending them produces a number that means nothing. Very high conversion in the upper market is a warning sign, not a triumph — it usually means the carrier is the cheapest quote on the sheet.
Policy count growth, split between new business and renewal. New-business count measures reach into the uninsured and underinsured population; renewal count measures whether the book stays. Reporting only the combined number lets a strong new-business quarter mask an eroding renewal base, and renewal erosion is the earlier warning of the two.
Average policy duration. In a market where terms are almost universally twelve months, duration is really a proxy for how many consecutive renewals an insured completes. Short average duration means the book is shopping every year, which raises acquisition cost and, more dangerously, invites adverse selection — the insureds who shop hardest are often the ones whose risk profile just changed.

Risks, edge cases, and failure modes
Loss ratio drift past the mid-seventies. This is the failure mode that ends carriers, and it rarely announces itself. It arrives as a series of individually defensible exceptions: one large account written outside appetite because the broker relationship mattered, one class kept open a quarter too long, one set of control requirements waived for an incumbent. By the time the rolling twelve-month number crosses seventy-five, the treaty renewal is already compromised, and the remedies available — mid-cycle non-renewal, sharp limit reduction, class exits — are exactly the ones that damage distribution relationships permanently.
Systemic and correlated events. The scenario every cyber actuary loses sleep over is not a large single claim but a common-mode failure: a cloud provider outage, a widely deployed software supply-chain compromise, a vulnerability in an edge appliance that thousands of insureds run. Portfolio-level aggregation modeling — how many insureds share a critical dependency — is a distinct discipline from individual-risk underwriting, and a carrier can have excellent per-account discipline and catastrophic accumulation exposure at the same time. The sales floor's role here is unglamorous but essential: capture the technology stack accurately at submission, because you cannot aggregate what you never recorded.
Writing without sub-limits. One uncapped extortion or business-interruption claim on a large limit can consume several years of underwriting profit on a mid-sized book. The edge case is subtler than "we always use sub-limits" — it is the sub-limit that exists but is set high enough to be decorative, or a business-interruption waiting period short enough that routine outages trigger coverage. Audit the actual terms bound, not the presence of a field in the policy admin system.

Silent cyber in other lines. Cyber loss can arrive through property, crime, general liability, or errors-and-omissions policies that were never priced for it. Carriers have spent years writing affirmative coverage grants and explicit exclusions to clarify this, but legacy paper and ambiguous wordings persist. A cyber book that looks well-managed in isolation can be sitting next to an unmanaged exposure elsewhere in the same enterprise.
War, infrastructure, and state-actor exclusions. Exclusion language around state-sponsored attacks and attacks on critical infrastructure has been repeatedly litigated and repeatedly rewritten. The commercial risk is that a carrier believes an exposure is excluded, prices accordingly, and then finds the wording does not do what underwriting assumed. Any sales conversation that involves promising coverage certainty in this area should route through coverage counsel rather than being resolved on the call.
Stale underwriting models. Frequency and severity in cyber move on a quarterly clock. A pricing model recalibrated once a year is structurally six months behind the threat environment on average. The practical mitigation is a quarterly review against actual frequency and severity data by class, with a documented decision even when the decision is no change.

Metric gaming. Every metric here can be gamed, and each has a characteristic tell. Pull-through inflates when underwriters retroactively tag deals as vendor-referred. Sub-limit rate inflates when a nominal, non-binding sub-limit is attached to satisfy the field. Conversion inflates when quotes are only issued on pre-qualified deals, which hides the real top-of-funnel problem. Retention inflates when a policy is technically renewed at a fraction of prior limit. Build the audit for each of these into the reporting itself — sample and verify rather than trusting the field.
Claims-handling as a retention variable. In this line, the claim is the product. An insured whose first ransomware event is handled well — breach counsel and incident-response vendor engaged within hours, negotiator available, business-interruption quantification handled competently — renews. One who spends the first forty-eight hours arguing about panel-vendor approval does not, and tells their broker why. Claims service quality belongs in the retention analysis as a first-class variable rather than being treated as an operations concern outside the commercial conversation.
Distribution concentration. Carriers that source a large share of premium from a small number of brokers are exposed to a single relationship change. Track premium concentration by producer with the same seriousness as risk concentration by industry class.
A practical rollout plan
Days 1 through 30 — instrument and reconcile. Get the nine metrics defined in writing with an owner and a source system for each. Then reconcile policy administration, claims, and broker management data. They will not agree. Common causes are policies booked to the wrong segment, claims allocated to the wrong accident year, and endorsements that changed limits without updating the exposure record. Establish rolling twelve-month loss ratio, average premium by segment band, and ransomware frequency by industry class as baselines, and freeze those definitions so later comparisons are valid. Make the non-bind and non-renewal loss-reason fields mandatory and structured now, because six months of clean loss-reason data is worth more than any dashboard.

Days 31 through 60 — expose the leading indicators. Ship the pull-through view to distribution and risk engineering. Stand up sub-limit attachment tracking by underwriter and by broker, and review the outliers in person rather than by report — the interesting cases are always specific deals with specific reasoning. Segment quote-to-bind by channel so the small-commercial and large-account funnels stop contaminating each other. Pilot continuous monitoring with one endorsed detection partner on a defined cohort and capture the pre-bind and post-bind comparison honestly, including the selection-bias caveat. Publish the appetite letter and control floor to brokers in plain language; a large share of wasted submission volume comes from brokers guessing at appetite.
Days 61 through 90 — close the loop with pricing and reinsurance. Run the first quarterly underwriting model review against actual frequency and severity by class, and document the decision either way. Recalibrate rate and sub-limit defaults where the data supports it. Assemble the reinsurance package early — treaty conversations go better when the carrier arrives with class-level frequency data, aggregation exposure by shared dependency, and a credible story about the control floor. Present combined-ratio trajectory to the chief financial officer with the development caveat stated explicitly, and take the vendor-program scorecard to the board with referred-versus-non-referred loss ratio at comparable revenue bands.
Ongoing cadence. Daily: new submissions by class, bind run-rate, incident notifications. Weekly: quote-to-bind by channel, pull-through, ransomware frequency trend, control-floor pass rate. Monthly: rolling loss ratio, average premium by band, sub-limit attachment, retention with loss reasons. Quarterly: combined ratio, model recalibration, treaty review, vendor scorecard, and accumulation exposure by shared dependency. During an active ransomware wave, compress the sub-limit and appetite review to a thirty-day cycle rather than waiting for the quarter.
Related questions
How is cyber insurance different from technology errors-and-omissions coverage?
Technology errors-and-omissions covers a technology company's liability for failing to deliver its product or service properly. Cyber covers an organization's own breach response, extortion, business interruption, and third-party privacy liability. Many technology firms buy them combined, which complicates claim allocation.
What security controls do carriers actually require before binding?
The common floor is multi-factor authentication on remote access and privileged accounts, endpoint detection and response across essentially all endpoints, backups that are immutable or offline with tested restores, and a documented, exercised incident-response plan. Requirements tighten by revenue band and industry class.
Why does average premium fall while rates are rising?
Mix. Adding small-commercial policies through a scan-and-bind channel lowers the average premium per policy even when rate per unit of exposure is climbing. Always decompose premium change into rate, exposure, and mix before drawing a pricing conclusion.
How long does a cyber claim take to fully develop?
Longer than most people assume. Forensics and breach response resolve in weeks, business-interruption quantification in months, and third-party liability sometimes over years. Incurred-but-not-reported development means a recent accident year's loss ratio is provisional for a considerable time.
What does a managing general agent do differently from a carrier?
A managing general agent underwrites on behalf of capacity providers rather than holding the risk itself, which lets it move faster on product and technology while its economics depend on fee income and profit commission. Several technology-led cyber players started this way before taking on more risk directly.
FAQ
What is the difference between loss ratio and combined ratio?
Loss ratio is incurred losses divided by earned premium — it measures claims cost alone. Combined ratio adds the expense ratio, capturing acquisition costs, commissions, and operating overhead as well. A carrier can have an attractive loss ratio and still lose money on underwriting if its expense ratio is heavy, which is a live question for technology-led carriers funding scanning and risk-engineering infrastructure.
Why should ransom demand be reported as both a mean and a median?
The distribution is severely right-skewed. A small number of very large demands pulls the mean well above the typical case, so the mean describes tail exposure while the median describes the everyday claim. If the mean rises and the median does not, the tail is thickening and the right response is a sub-limit and reinsurance conversation, not a broad rate increase.
Is a high quote-to-bind conversion rate good?
Not necessarily. In the upper market, unusually high conversion often means the carrier is consistently the cheapest quote on the sheet, which is a rate-adequacy warning rather than a sales success. Conversion is only interpretable when segmented by channel and read alongside rate change and the structured reason codes on lost deals.
How should a carrier prove that its vendor-endorsement program actually works?
By comparing loss ratio for referred versus non-referred business at comparable revenue bands, industry classes, and control levels. Without that control, the difference is largely selection bias — organizations willing to adopt an endorsed security stack were probably better risks already. The honest version of the metric reports both the raw gap and the controlled gap.
What is systemic or accumulation risk in a cyber book?
The exposure created when many unrelated insureds depend on the same cloud platform, software product, or managed-service provider. A single compromise of that shared dependency produces correlated claims across the portfolio at once. It is modeled separately from individual-risk underwriting, and it depends entirely on capturing each insured's technology stack accurately at submission.
Why does renewal retention drop after a carrier tightens its control requirements?
Because part of the incumbent book cannot meet the new floor at renewal and leaves rather than remediate. The dip is expected and typically precedes loss-ratio improvement by a year or more. The failure mode is granting quiet exceptions to protect the retention number, which reintroduces exactly the risk the floor was designed to exclude.
Sources
- https://www.marsh.com/en/services/cyber-risk.html
- https://www.aon.com/cyber-solutions/
- https://www.swissre.com/institute/
- https://www.munichre.com/en/solutions/for-industry-clients/cyber.html
- https://www.beazley.com/en-US/
- https://www.lloyds.com/about-lloyds/our-market/products-and-services/cyber
- https://www.naic.org/cipr-topics/cyber-risk
- https://www.cisa.gov/stopransomware
- https://www.nist.gov/cyberframework
- https://www.iii.org/
Related on PULSE
- [What are the key sales KPIs for the Auto Insurance Carriers industry in 2027?](/knowledge/ik0312)
- [What are the key sales KPIs for the Fine-Tuning Platform industry in 2027?](/knowledge/ik0382)
- [What are the key sales KPIs for the equine breeding industry in 2027?](/knowledge/ik0451)









