Insurance data reports ransomware at around 28% of cyber claims but 52% of total claim costs, while business email compromise was the most frequent claim type at roughly 33% of filings with average payouts near $68,000.
Two categories, inverse profiles. It is the clearest available illustration of why frequency and severity have to be managed separately.
BEC Is A Payments Problem
A business email compromise loss is bounded by the transaction. Money moved, it is a known amount, and the remediation is a process change of the kind filed at 26-0712: out-of-band authorisation, callback to a directory number, dual approval.
It is frequent, cheap per event, and genuinely fixable by controls that do not require a security team.
Ransomware Is An Operations Problem
A ransomware claim is unbounded in a way BEC is not, because the loss is business interruption. The JLR file at 26-0119 puts an outer edge on that: £1.9 billion, dominated by lost production rather than by anything paid to an attacker.
Which is why the ransom figure is a poor proxy for the cost, and why the payments-down-44% finding in 26-0603 does not translate into claims costs falling.
The Budgeting Implication
An organisation optimising for incident count will spend on the frequent category and report improvement. An organisation optimising for expected loss will spend on recovery capability, segmentation and offline backups, and its incident count may not move at all.
Both are defensible. Only one of them addresses the half of the money.
This is an analysis file built on published insurer claims data, listed below. Figures cover insured claimants and vary between insurers and years. Corrections: corrections@forensicpost.com.