Skip to content
Security & Trust

Verizon's claims data: the typical paid cyber claim is $83,000, with a long tail

Insurance payouts show rising downtime costs and heavier relative losses for small firms. The figures are floors.

W
WebPulse Newsroom
AI-assisted · 5 min read
Share on X LinkedIn
Verizon's claims data: the typical paid cyber claim is $83,000, with a long tail

AI-generated image for WebPulse. About our images

Key finding

Median paid cyber insurance claim: $83,000 (Source: Verizon 2026 Breach Impact Study, as reported by Resilient Cyber (October 1, 2026))

Boards usually hear one of two stories about breaches. Either the average cost is in the millions, or a breach ends the company. Verizon's 2026 Breach Impact Study tells a different story, built from insurance payouts. The typical paid claim is $83,000, with a long tail of very large claims. A separate researcher's work, cited by the Resilient Cyber newsletter, finds that few firms close because of a breach.

This story draws on the Resilient Cyber newsletter's analysis of the study, published October 1, 2026. Verizon's own report was not part of the material reviewed. Where the newsletter adds its own opinion, the text says so.

What the study measured

The research team started with some 70,000 US cyber insurance claims. About 38,000 of them had a recorded payout to the policyholder. CyberAcuView's member insurers standardized the data. The incidents run from the start of 2019 to the end of October 2025.

These are dollars actually paid, not survey answers. The authors chose medians over averages, because a few huge claims distort an average. They also published the full spread of outcomes.

The data has a clear limit. It covers insurable losses only. Uninsured costs, reputational damage and costs outside claims are left out. The authors call the figures floors, not ceilings.

$83,000
Median paid cyber insurance claim
Source: Verizon 2026 Breach Impact Study, as reported by Resilient Cyber (October 1, 2026)

The tail matters more than the middle

Half of paid claims were above $83,000. The top 10% were above $920,000. The top 2.5% were above $5 million. Picture 100 claimants: about 50 sit below the median, around 10 lose more than $920,000, and two or three lose more than $5 million.

The median also climbed, from roughly $60,000 in 2019 to roughly $110,000 in 2024. That is about 80% growth. The newsletter puts US consumer price inflation at around 23% over the same period. Inflation alone does not explain the gap.

How a technical failure becomes a loss

The study sorts payouts into four groups: payments to attackers, business interruption, response and recovery, and external liability such as fines and settlements. Each group traces back to what a system does when it fails.

In a ransomware attack, malicious software locks the files that staff and software need. Work stops until systems come back. That stoppage is business interruption. The cost of rebuilding and recovering data falls under response and recovery.

The study also tracks contingent business interruption. This is downtime caused by a third party's outage rather than an attack on the firm itself. A vendor's failed service can halt your operations while your own systems stay untouched. The dataset began counting this separately in 2024. In its first year it made up 13% of known loss types.

The data does not show how restore speed affects claim size. That link is this publication's inference, not the study's. It is a reasonable one: the longer systems stay down, the longer the downtime clock runs.

Downtime is the cost to watch

Downtime losses are rare. They appear in about one claim in ten. When they do appear, they are the largest of the four types, with a median of $90,000. Response and recovery appears far more often, in 69% of claims, but makes up 29% of total losses.

Between 2023 and 2024, downtime went from about a fifth of known losses to nearly a third. In supply chain or third-party incidents, it made up 50% of known losses across all years. Boards often ask what vendor risk costs. Much of the answer is the time your own operations stand still.

21% to 32%
Business interruption share of known losses, 2023 to 2024
Source: Verizon 2026 Breach Impact Study, as reported by Resilient Cyber (October 1, 2026)

Ransomware is the expensive one

Ransomware makes up 36% of claims but 73% of insured costs. The typical ransomware claim is $303,547. Business email compromise is 12% of claims but only 1% of cost.

One finding cuts against the usual story. About 69% of ransomware victims in the claims did not pay. Nearly half of ransomware claims, 48%, show neither data restoration nor extortion costs. The newsletter suggests attackers may have failed to encrypt systems, or victims chose not to engage. That is the newsletter's interpretation, not a study finding.

73%
Ransomware share of total insured costs
Source: Verizon 2026 Breach Impact Study, as reported by Resilient Cyber (October 1, 2026)

Small firms carry the heavier load

Large enterprises lose more dollars. Their median claim is around $283,000, against roughly $38,000 for firms with revenue under $25 million. Measured against revenue, the picture flips.

Among small firms, the heaviest 10% of claims cost up to 3% of annual revenue. In the heaviest 2.5%, the cost passed 7%. For mid-market and large firms, the ratio stayed at or below 2% even in the worst cases.

Over 7%
Small-business losses as a share of revenue, top 2.5% of claims
Source: Verizon 2026 Breach Impact Study, as reported by Resilient Cyber (October 1, 2026)

Closures are rare, but the study does not explain why

The newsletter's author adds a point from outside the study. Adrian Sanabria has kept a database of companies that ceased to exist because of a cyber incident. After about a decade, it lists roughly 25 to 32 firms. The author says the popular claim that 60% of small businesses fail within six months of an attack has no traceable source.

According to the newsletter, the firms that did collapse lacked incident response plans, containment, usable backups and operational resilience. The breach was the trigger, not the root cause.

The study shows where insured money goes. The newsletter, citing Sanabria's research, argues that preparation separates survivable breaches from fatal ones. The study itself does not test preparation.

Questions to put to your team

Where does your exposure sit on the spread? Ask your broker how your limits compare with the $920,000 and $5 million thresholds.

How long could you operate if a key vendor went down? Third-party downtime now has its own loss category.

Can you restore from backups you have actually tested? Ask for the last test date and the result.

If you are a small firm, what would a loss of 3% to 7% of revenue mean, and who would cover it?

Treat the study's numbers as a floor, not a budget. They show what insurers paid. They do not show what a breach costs you.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: resilientcyber.io.

Share this insight