Key Takeaways
- CYGNVS and CyberAcuView are connecting incident coordination with aggregated insurance claims intelligence.
- Shared data could sharpen underwriting, identify costly control gaps, and help organizations respond faster.
- Inconsistent incident classifications and incomplete market data remain significant obstacles.
CYGNVS and CyberAcuView have formed a partnership aimed at turning cyber-insurance claims and incident information into more practical intelligence. The effort combines CYGNVS cyber-resilience and incident-coordination workflows with CyberAcuView's aggregated, insurer-derived claims data.
The basic idea is straightforward: insurers hold a substantial amount of information about attacks, losses, recovery costs, and failed controls, but those records often sit across separate carriers and systems. Bringing that information into incident preparation and response workflows could help insurers and policyholders recognize patterns that would otherwise remain buried.
There is plenty of material to analyze. Verizon Business and CyberAcuView examined approximately 70,000 U.S. cyber-insurance claims recorded from January 2019 through October 2025. About 38,000 of those claims involved paid losses. The median breach impact increased from roughly $60,000 in 2019 to $110,000 in 2025, an 80% rise compared with inflation of approximately 23% over the same period.
That difference matters. It suggests that higher cyber losses cannot be explained by general price increases alone. Business interruption, forensic investigations, legal work, regulatory exposure, data restoration, and third-party dependencies can all influence the final cost of an incident. Claims intelligence can help underwriters see which combinations appear most frequently and which controls tend to limit damage.
Historical claims data is useful only when companies can connect it to current technology and response decisions. A portfolio-level ransomware trend may tell an insurer that losses are changing. It does not automatically tell a security team which identity controls, backup procedures, or communication bottlenecks need attention.
CYGNVS addresses this gap by integrating its incident-coordination environment into cyber-resilience workflows, while CyberAcuView aggregates loss intelligence from participating insurers. Linking those capabilities can create a feedback loop between what happens during real incidents and how organizations prepare for the next one.
Shared classification is likely to be central. The NIST Cybersecurity Framework 2.0 provides a common structure for governing, identifying, protecting, detecting, responding to, and recovering from cyber risk. The MITRE ATT&CK knowledge base offers another reference point by organizing adversary tactics and techniques. Used carefully, these resources can help participants normalize information that may otherwise be recorded in incompatible ways.
Without that normalization, a credential theft event might be classified as ransomware by one carrier, business email compromise by another, and unauthorized access by a third. How useful is a large dataset if similar incidents cannot be compared reliably? Common terminology will not eliminate ambiguity, but it can make aggregated findings more usable.
Portfolio statistics also require caution. Marsh clients reported a 29% year-over-year decline in U.S. and Canadian cyber-claim notifications in 2025, while ransomware claims fell 33%. Those movements may reflect stronger security, shifting attacker behavior, changes in insured populations, or the absence of a major correlated event. A single systemic incident affecting a cloud provider or widely used software component could quickly reverse the trend.
Accumulation risk is the uncomfortable part of the discussion. German supervisor BaFin has reported that insurers are observing accumulation losses more frequently, while comprehensive cyber-claims data remains unavailable across the broader market. In other words, insurers are seeing more evidence of connected losses without yet having a complete view of the exposure.
The commercial opportunity remains sizable. Global cyber-insurance premiums reached approximately $16 billion in 2025, with North America accounting for about two-thirds. Yet only around 10% of small and midsize enterprises globally had cyber coverage. Better claims intelligence could support more precise underwriting for that underserved market, although data quality and participation will shape how far the model can extend.
For policyholders, the most useful outcome would be more than refined pricing. Claims evidence could inform tabletop exercises, incident playbooks, control investments, and recovery planning. For insurers, it could improve portfolio monitoring and reveal concentrations earlier. The CYGNVS and CyberAcuView partnership reflects a broader shift: cyber-insurance data is becoming an operational resource, not merely a record of what went wrong.
⬇️