Frankfurt – September 09, 2026 -- Cyberattack frequency against European mid-sized companies fell to a five-year low in 2025, yet the average claim value tripled between 2020 and 2025, according to Chubb's Cyber Claims Report 2026.
Claim frequency drops while financial severity climbs sharply
Chubb's data shows that while the number of cyber incidents affecting mid-market firms stabilized and declined to its lowest point in five years during 2025, the cost per claim has risen threefold over the preceding five-year period. The insurer attributes the gap partly to artificial intelligence, which is simultaneously helping companies detect vulnerabilities and enabling more sophisticated malicious use of technology that accelerates the scale of exposure.
Supply-chain dependency exposes mid-sized firms to third-party breaches
Jimaan Sane, Head of Growth, Global Cyber at Chubb, said mid-sized companies face the same cyber disruptions as large corporations but lack comparable operational resilience, particularly given their heavier reliance on third-party vendors. Sane noted that when a technology provider is hit by ransomware, the fallout extends to retailers, manufacturers and service firms dependent on that provider's systems—halting sales transactions, disrupting inventory visibility and stopping operations even though the attack originated externally. He said this risk underscores the need for contingent business interruption coverage within any comprehensive cyber risk strategy.
Ransomware and social engineering remain dominant threats for smaller firms
Chris Collier, Vice President - Claims at Chubb, said social engineering fraud, data breaches and ransomware continue to pose significant risks, with consequences that can be devastating for small and mid-sized companies lacking adequate cyber insurance coverage to recover from irreversible losses. Collier added that even when initial ransomware encryption attempts are blocked, data exfiltration can still trigger extensive reporting obligations and remediation costs.
Only 31% of German mid-sized firms meet basic IT security standards
Data cited from the German Insurance Association (GDV) shows significant gaps in mid-market IT security, with only 31% of companies fully meeting basic protection standards.
Insurer points to AI-driven mitigation tools and executive-level oversight
Chubb recommends companies deploy AI-powered risk mitigation tools and elevate cyber risk to a board-level priority rather than treating it solely as an IT function. The company offers policyholders access to tools including incident response, vulnerability management, managed detection and response, data privacy risk management, and user security awareness training, alongside its Cyber Index platform for real-time risk assessment.