At-Bay’s 2025 InsurSec Report shows that cyber claims rose sharply in 2024, driven by more ransomware, growing third-party losses, and persistent financial fraud. The report highlights major incidents such as the CDK Global outage, the expansion of ransomware groups, and the growing impact of email-based deception. #AtBay #CDKGlobal #MOVEit #LockBit #BlackBasta #BlackSuit
Keypoints
- Annual cybersecurity reports typically begin with an introduction explaining the dataset, scope, and purpose, followed by key findings that summarize the most important trends and statistics from the year.
- The main body usually includes chapters organized by threat category or theme, such as ransomware, third-party risk, financial fraud, and the broader cyberthreat landscape, with each section combining charts, incident analysis, and sector-specific observations.
- These reports often conclude with a “Looking Ahead” section that forecasts future risk trends, plus a methodology section that explains how claims, severity, and frequency were measured.
- In this report, overall claim frequency increased 16% in 2024, showing that cyber losses continued to rise across At-Bay insureds.
- Financial fraud remained the most frequent incident type and was responsible for roughly a third of claims for the second year in a row.
- Email was the most common initial entry vector, triggering 43% of all claims, and it was responsible for 83% of financial fraud claims.
- Average claim severity fell 5% to $166K, but the report notes this was mainly because of more frequent low-severity incidents, not because major attacks became less damaging.
- Direct ransomware frequency increased 19% year over year and returned to roughly 2021 levels, while severity rose 13% to $468K.
- Remote access tools such as VPN, RDP, and other corporate access systems were the initial entry vector in 80% of direct ransomware claims, up from 63% in 2023.
- Remote access-related incidents were also the costliest entry vector overall, at 2.4 times higher severity than average, suggesting that unpatched or misconfigured corporate systems remain a major weakness.
- Companies with $25M-$100M in revenue were hit hardest by direct ransomware, with a 46% increase in claim frequency and a 47% increase in severity.
- Manufacturing experienced the highest direct ransomware claim frequency, nearly twice the average, indicating that attackers are targeting industries with weaker control adoption and less regulatory pressure.
- Ransomware groups became more fragmented, with 47 distinct groups identified in 2024 compared with 41 in 2023 and just 16 in 2021.
- The average ransom paid rose to $317K, but only 31% of ransom demands resulted in payment, showing that many attacks now create losses through business interruption and legal costs rather than ransom alone.
- Indirect ransomware increased 43%, showing that third-party and supply chain risk remains a major driver of claims and is becoming more costly.
- The CDK Global ransomware outage was the standout third-party event, heavily affecting auto dealerships and driving the sharp rise in indirect losses, especially in retail trade.
- Indirect ransomware severity reached $241K on average, up 72% from 2023, because outages caused operational disruption rather than only data exposure.
- The report emphasizes that cloud services, outsourced platforms, and business dependencies are expanding the blast radius of cyber incidents well beyond the originally attacked organization.
- Generative AI is making social engineering more effective by helping attackers write more natural, convincing fraud emails and reducing obvious warning signs.
- The report’s recurring theme is that basic security controls still work when properly deployed, with multi-factor authentication, strong encryption, endpoint detection and response, and effective backups all reducing losses.
- The outlook section warns that the end of the war in Ukraine could release a new wave of highly skilled cybercriminals, potentially increasing both ransomware frequency and severity over the next few years.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)