Verizon Business and CyberAcuView analyzed 70,000 U.S. cyber insurance claims from January 2019 to October 2025. The findings reveal a financial landscape that's fundamentally different from where most risk management frameworks were calibrated. The median financial impact of a data breach rose from $60,000 in 2019 to $110,000 in 2025. That's an 80% increase, while inflation ran at 23% over the same period.
More than half of paid claims exceeded $83,000, with 10% hitting $920,000 or more. The most extreme 2.5% of cases topped $5 million. These aren't outliers; they're the new reality your insurance broker needs to price for and your board needs to understand.
What the Data Shows
Business interruption emerged as the largest loss driver across the dataset. This isn't just downtime; it's revenue you can't recover, contracts you breach, and customers who move to competitors while your systems are down. For software supply chain and third-party incidents, business interruption accounted for 50% of all losses.
Supply chain breaches remain rare, representing roughly 2% of claims, but when they occur, costs more than double the overall dataset median. In the most extreme cases, losses exceeded $100 million. If you're a vendor to other organizations or rely on third-party software in your critical path, this finding should reshape how you think about vendor risk management and business continuity planning.
Healthcare showed up with 8,640 claims and 5,100 recorded losses, accounting for 23% of total losses despite being one sector among many. The median liability loss in healthcare ran 57% higher than the overall dataset. Ransomware drove 39% of healthcare incidents and represented 60% of total costs, with a median impact of $77,051. Business email compromise appeared in 22% of cases at a median cost of $94,924.
Company size matters, but not in the way you'd expect. The median impact was $38,000 for small and medium businesses, $96,000 for mid-market organizations, and $238,000 for large enterprises. But when you measure impact as a percentage of insured revenue, the SMB segment saw ratios as high as 3% in the top 10% of cases and 7% in the most extreme scenarios. For a company with $10 million in annual revenue, a 7% impact is $700,000. Without insurance, that's existential.
What This Means for Your Team
Your current cyber insurance policy was likely underwritten using assumptions about breach costs that are now three to five years old. If you haven't increased your coverage limits since 2022, you're probably underinsured for business interruption specifically.
The shift toward business interruption as the primary cost driver changes the risk calculus. Traditional controls focused on preventing data exfiltration, but the real financial damage now comes from how long your systems stay offline and how quickly you can restore operations. Your incident response plan needs to prioritize recovery time objectives that map to actual revenue impact, not just technical restoration.
If you operate in healthcare or you're part of a software supply chain, the risk profile is materially different. Healthcare's elevated external liability costs reflect regulatory penalties, notification expenses, and legal settlements that other sectors don't face at the same scale. Software vendors carry concentration risk: one incident can cascade to dozens or hundreds of downstream customers.
For SMBs, the revenue-to-impact ratio reveals something uncomfortable. Even a "small" breach can consume multiple quarters of profit. Your risk transfer strategy through insurance isn't optional; it's a financial control as critical as your firewall.
Action Items by Priority
Immediate (next 30 days):
Request a policy review from your cyber insurance broker. Bring this data to the conversation. Ask specifically about business interruption coverage limits, how they're calculated, and whether your current policy would cover the median impact for your organization size. If your coverage hasn't increased since 2021, it's almost certainly inadequate.
Pull your most recent business impact analysis. If it's more than 18 months old or it doesn't quantify revenue loss by hour of downtime for each critical system, schedule a refresh. You need numbers that connect system availability to financial impact in a way your CFO and your insurer both understand.
Near-term (next 90 days):
Map your third-party vendors to business interruption risk. Which vendors, if compromised, would take your revenue-generating systems offline? How long would restoration take? What's your contractual recourse? Your vendor risk assessment should include recovery time commitments, not just security questionnaires.
Update your incident response plan to prioritize business interruption scenarios. Run a tabletop exercise that assumes ransomware encryption of your primary revenue system. Who makes the decision to pay? How do you communicate with customers? What's your manual workaround? Time each decision point and calculate the revenue impact per hour.
For healthcare organizations: Review your HIPAA Security Rule compliance specifically around backup and disaster recovery (45 CFR § 164.308(a)(7)). The 57% higher liability costs in your sector mean your notification obligations and potential settlement exposure are proportionally higher. Your recovery time objective needs to reflect that.
Strategic (next 12 months):
Reassess your risk appetite statement. If your board approved a risk tolerance that assumed median breach costs of $60,000, that document is now materially wrong. Bring updated financial impact data to your next risk committee meeting and propose revised tolerance thresholds that reflect current costs.
Build business interruption into your risk register as a separate risk category, not a consequence of other incidents. Assign ownership, set metrics (maximum tolerable downtime per critical system), and track it quarterly. This elevates business continuity from an IT problem to an enterprise risk management concern.
Consider whether your current control investments match your actual risk exposure. If business interruption is your primary financial risk but most of your budget goes to perimeter defense, you have a mismatch. Controls that reduce recovery time (tested backups, documented runbooks, cross-trained staff) may deliver better risk reduction per dollar than controls that reduce breach likelihood.
HIPAA Security Rule
Cyber Insurance Overview





