81% of those surveyed say having proper cyber insurance coverage is critical to the well-being of their company.
When cyber threats evolve, so does our response. Travelers brings together underwriting expertise, claims experience and dedicated Cyber Risk Services specialists to help businesses not just recover from cyber events – but work to help prevent them.
Cyber Insurance Can Help Businesses Be Prepared
Learn How to Get Ahead of Cyber Risks
Why Travelers for cyber liability insurance?
Business interruption
Cyber extortion
Betterment
Why Travelers for cyber liability insurance?
Travelers cyber coverage can be a crucial safeguard against the potentially devastating financial consequences of a cyberattack. Travelers can help businesses customize insurance solutions to their level of risk with coverage options to address:
Who needs cyber liability insurance?
Who needs cyber liability insurance?
Any type of business or organization that uses technology faces cyber risk. As technology becomes more complex and sophisticated, so do the cyber threats. That’s why it’s so critical to be prepared with both cyber liability insurance and an effective cybersecurity plan to help manage and mitigate cyber risk.
Why is cyber insurance necessary?
Why is cyber insurance necessary?
Cyber insurance can help cover costs associated with breaches and cyberattacks. Those costs can include such things as lost income due to a cyber event, notifying customers affected by a breach, recovering compromised data, repairing damaged computer systems and more.
What is cyber liability insurance?
What is cyber liability insurance?
Cyber liability insurance provides a combination of coverage options and services that are designed specifically to help protect businesses against breaches and other cyber events and recover quickly if a cyberattack does take place.
Questions about cyber insurance
18%
18
%
of large businesses lack cyber insurance
24%
24
%
of midsized businesses lack cyber insurance
50%
50
%
of small businesses lack cyber insurance
Companies of all shapes and sizes lack proper cyber coverage
Forensic investigations
Litigation expenses
Regulatory defense expenses/fines
Crisis management expenses
39%
150%
increase in companies reporting cyberattacks in the last 10 years
60%
of businesses that reported an attack were victimized more than once
Top 5 cyber events experienced by businesses
The trend reshaping cyber risk
Most businesses have already crossed the AI threshold – with 89% of organizations reporting AI use and established AI business practices in place at only 59% of organizations.
The threat is real, and so is the gap – which is why Travelers now offers an AI Risk Assessment at no additional cost to eligible cyber policyholders.*
External threats top the list of business leaders’ AI concerns
Attackers using AI to exploit system vulnerabilities
56%
AI-generated phishing, deepfake or social engineering attacks
54%
Sensitive company data being retained to train external AI models
52%
Employees inputting sensitive data into unsanctioned AI tools
51%
Third-party vendors improperly using AI
50%
Inaccurate output from AI tools leading to poor business decisions
48%
AI Cyber Threats
Cyber Trends
Cyber Victimization
Technology
Retail
Professional Services
Nonprofits
Manufacturing
Healthcare
Construction
Banking
56% Security breach/hackers
#1
55% A security breach or cyber event involving AI
#2
53% Income loss caused by vendor/supplier cyber incident
#3
53% Unauthorized access to financial accounts
#4
50% A system glitch causing your company’s computers to go down
#5
AI has emerged as one of the top cyber concerns of business leaders
Cyber Awareness Is Key to Fighting Back
of companies that reported falling victim to a cyber event had a security breach
Transcript
READ TRANSCRIPT
Watch Video
92%
Travelers Cyber Risk Services goes beyond the policy with monitoring, tools and expert guidance that help policyholders stay ahead of evolving threats, all at no additional cost.
GOVERNANCE GAP
Organizations using AI tools day-to-day (any % of workforce)
Cyber Risks Are the #1 Business Concern
Businesses Express Worry About AI Cyber Threats
worry a great deal/some about a data breach or cyber event involving AI
%
1
Understanding cybersecurity risks can go a long way toward helping to protect businesses. To learn more about Cyber coverage options and tools, visit travelers.com/cyber.
Cyber Insurance
Cyber Preparedness
Cyber Awareness
Business Concerns
- Tim Francis, Travelers Enterprise Cyber Lead
It’s important that companies know the steps they can take to help avoid a cyberattack. We’d like to see more businesses taking protective measures and utilizing tactics like multifactor authentication, endpoint detection and response and creating an incident response plan.
Coverage and Services
*The frequency and severity of cyber insurance claims were found to be lower across all policyholder organizations that met a minimum threshold for engaging with the service offerings described above by registering their account on the Cyber Risk Dashboard.
Travelers cyber coverage also includes access to our in-house Cyber Risk Services team, at no additional cost, to help policyholders predict and prevent cyber threats, including:
Always-on threat monitoring and tailored alerts
Expert guidance from our in-house Cyber Risk Services team
24/7 Cyber Risk Dashboard
92% of business leaders express confidence in insurance carriers as a source of cybersecurity expertise and guidance
The AI Factor
READ TRANSCRIPT
94% of businesses are familiar with MFA yet only 60% of survey participants use MFA to ensure that administrative users are validated prior to being granted access in the network.
See how MFA works
63% are keeping systems up to date
58% are backing up data
50% are filtering and scanning email
48% are implementing multifactor authentication (MFA)
47% are migrating to cloud
You can’t govern what you can’t see
Preventive Tactics
The Basics
The basics are working – but there’s more to do
Cyber Preparedness
Cyber Preparedness Can Help Reduce the Risk of Attacks
92%
of business leaders express confidence in insurance carriers as a source of cybersecurity expertise and guidance.
Unauthorized access to financial accounts
Security breach/hackers
A security breach or cyber event involving AI
35% do not have an incident response (IR) plan
34% do not use multifactor authentication (MFA) for remote access
40% do not have a post-incident response team on retainer34% do not simulate cyberattacks to identify system vulnerabilities
28% do not have a written incident response (IR) plan
88% believe having proper cybersecurity controls in place is critical, yet:
Top cyber concerns
Banking
#1
#2
#3
Top Cyber Concerns by Industry
#1
Unauthorized access to financial accounts
#2
A security breach or cyber event involving AI
#3
Becoming a cyber extortion/ransomware victim
Top cyber concerns
CONSTRUCTION
#1
Security breach/hackers
#2
A system glitch causing computers to go down
#3
A security breach or cyber event involving AI
Top cyber concerns
HEALTHCARE
#1
Securitybreach/hackers
#2
Unauthorized accessto financial accounts
#3
Cyber event caused by employees working remotely
Top cyber concerns
MANUFACTURING
#1
Employees putting informationor systems at risk
#2
A security breach or cyber event involving AI
#3
Security breach/hackers
Top cyber concerns
NONPROFITS
#1
A security breach or cyberevent involving AI
#2
Failure to operate/loss of income due to a cyber event
#3
A system glitch causing computers to go down
Top cyber concerns
PROFESSIONAL SERVICES
#1
A security breach or cyber event involving AI
#2
Security breaches/system glitchat a vendor
#3
Failure to operate/loss ofincome due to a cyber event
Top cyber concerns
RETAIL
#1
Unauthorized accessto financial accounts
#2
Remote workers who may cause cyber events, system glitches or breaches
#3
Someone fooling employees into transferring funds into a fraudulent account
Top cyber concerns
TECHNOLOGY
More businesses are prioritizing cybersecurity. Reported adoption of key security controls is up and cyber knowledge is up.
But preparation isn’t a destination – it’s an ongoing discipline.
Preparation is paying off
This year’s results tell an encouraging story: More businesses are getting the fundamentals right.
81% use firewall protection
81% have data backup and infrastructure
76% keep all software up to date and prioritize updates with known patches
But gaps in more advanced defenses remain – and those gaps are exactly where attackers look, so every additional layer of protection matters.
A strong cyber defense goes beyond the basics. Yet critical protective measures are still far from universal:
53% do not simulate cyberattacks to identify system vulnerabilities
51% do not have a post-incident response team on retainer
40% do not have a written incident response (IR) plan
Vendor and supply chain risk deserves the same scrutiny – yet fewer than 6 in 10 businesses formally assess the security posture of their supply chain partners or the vendors who access their systems.
The steps too many businesses are still missing
Nearly half of business leaders worry a great deal/some about the lack of visibility into how, where or by whom AI tools are being used across their organization. That blind spot creates real exposure – employees may be feeding sensitive data into unsanctioned tools without anyone knowing.
Conducting a simple AI audit – cataloging which tools are in use, who is using them and what data they’re touching – is one of the most immediate and foundational steps a business can take.
47% of businesses lack visibility into how AI is being used across their organization
Link to New AI Governance Video
*AI risk assessment included at no additional cost for policyholders with $1M+ cyber limit
AI risks have not appeared in prior Risk Lists – stats marked with indicate these new risks.
Risk Index
Risk Index
The Travelers
The Travelers
The Travelers Risk Index
[ILLUSTRATION - TBD]
89%
30pp
59%
Have established business practices for employees’ use of AI
The 2026 survey explores the top concerns of U.S. business decision-makers from small, medium and large businesses and across a wide range of industries – including a closer look at how AI is reshaping the cyber threat landscape.
Learn what’s driving risk this year – and what businesses should do to stay ahead.
indicate these new risks.
The 2026 survey explores the top concerns of U.S. business decision-makers from small, medium and large businesses across a wide range of industries – including a closer look at how artificial intelligence (AI) is reshaping the cyber threat landscape.
Learn what’s driving risk this year – and what businesses should do to stay ahead.
AI risks have not appeared in prior Risk Lists – stats marked with
AI risks have not appeared in prior Risk Lists – stats marked with an AI symbol indicate these new risks.
69% do not simulate cyberattacks to identify system vulnerabilities68% do not have a post-incident response team on retainer
52% do not have a written incident response (IR) plan
77% believe having proper cybersecurity controls in place is critical, yet:
47% do not have a post-incident response team on retainer45% do not simulate cyberattacks to identify system vulnerabilities
21% do not have a written incident response (IR) plan
93% believe having proper cybersecurity controls in place is critical, yet:
53% do not simulate cyberattacks to identify system vulnerabilities47% do not have a post-incident response team on retainer
31% do not have a written incident response (IR) plan
87% believe having proper cybersecurity controls in place is critical, yet:
59% do not have a post-incident response team on retainer51% do not simulate cyberattacks to identify system vulnerabilities
44% do not have a written incident response (IR) plan
90% believe having proper cybersecurity controls in place is critical, yet:
78% do not simulate cyberattacks to identify system vulnerabilities54% do not have a post-incident response team on retainer
53% do not have a written incident response (IR) plan
88% believe having proper cybersecurity controls in place is critical, yet:
61% do not simulate cyberattacks to identify system vulnerabilities55% do not have a post-incident response team on retainer
48% do not have a written incident response (IR) plan
84% believe having proper cybersecurity controls in place is critical, yet:
46% do not have a post-incident response team on retainer36% do not simulate cyberattacks to identify system vulnerabilities
35% do not have a written incident response (IR) plan
92% believe having proper cybersecurity controls in place is critical, yet:
had income loss caused by a vendor cyber incident
had a system glitch or user error
had a security breach
had employees putting info/systems at risk
had unauthorized access into control systems
38%
33%
31%
24%
25%
Total Number of Injuries
38%
Total Number of Injuries
114,327
47%
of businesses worry a great deal/some about the lack of visibility into how AI is being used across their organization.
%
47
39%
of companies that reported falling victim to a cyber event had a security breach
150%
increase in companies reporting cyberattacks in the last 10 years
60%
of businesses that reported an attack were victimized more than once
had income loss caused by a vendor cyber incident
24%
had unauthorized access into control systems
25%
had employees putting info/systems at risk
31%
had a security breach
33%
had a system glitch or user error
38%
Top 5 cyber events experienced by businesses
Top 5 cyber events experienced by businesses
Cyber event caused by employees working remotely
GOVERNANCE GAP
30%
READ TRANSCRIPT
— it marks where AI is changing the risk picture.
Look for the
Look for the AI symbol it marks where AI is changing the risk picture.
Businesses have never been more cyber aware – of both active cyber threats and their own cybersecurity capabilities. Confidence that companies can navigate cyber events is increasing. But AI is rewriting the threat landscape faster than many companies can respond.
An AI-related event now ranks as the second-highest specific cyber concern, nearly tied with traditional security intrusions such as a security breach with someone gaining unauthorized access to computer systems.
Yet governance is exactly where businesses are most exposed: Nearly 9 in 10 business leaders surveyed report that at least some portion of their workforce uses AI tools on a day-to-day basis – yet fewer than 6 in 10 have formal practices in place to govern it.
Watch Video
A strong cyber defense goes beyond the basics. Yet critical protective measures are still far from universal:
53% do not simulate cyberattacks to identify system vulnerabilities
51% do not have a post-incident response team on retainer
40% do not have a written incident response (IR) plan
Vendor and supply chain risk is no different
< 6 in 10 businesses formally assess who can access their systems
Always-on threat monitoring and alerts: Same-day threat alerts help identify attacks before they escalate, with step-by-step actions tailored to each organization.
In-house Cyber Risk expert guidance: Our dedicated team can provide personalized guidance to help policyholders strengthen security and get more from their existing security investments.
24/7 Cyber Risk Dashboard: Check cyber exposure and view custom security recommendations anytime, day or night.
While businesses can’t predict a cyberattack, Travelers Cyber Risk Services offers threat monitoring, tools and services to help businesses plan to prevent one. Our short video explains.
System Glitch or User Error
38% of affected businesses
Security Breach
33% of affected businesses
Employees Putting Info/Systems at Risk
31% of affected businesses
Unauthorized Access into Operational Control Systems
25% of affected businesses
Income Loss Caused by a Vendor Cyber Incident
24% of affected businesses
Percentages indicate worry a great deal/some.
Percentages indicate worry a great deal/some.
GOVERNANCE GAP
30-POINT