>> All posts

What is loss ratio? (and why cyber insurance people won't stop saying it)

In cyber conversations, loss ratio gets used the way “zero trust” gets used in security: sometimes precisely, often as a vibe word that means “the economics aren’t working.”

If you sell to insurers, buy from them, or sit in a board meeting where someone wields the phrase, you need the actual definition. Not so you can pretend to be an actuary — so you stop nodding along to nonsense.

Disclaimer: This is insurance literacy for practitioners. It is not an actuarial textbook, not advice about any company’s results, and not a promise that any tool (including ours) moves anyone’s loss ratio by a stated amount.

The core definition

The NAIC glossary defines loss ratio as:

the percentage of incurred losses to earned premiums.

In plain English:

Loss ratio ≈ how much loss the insurer incurred on the book ÷ how much premium it earned on that book (over a period), usually expressed as a percent.

  • Earned premium — premium that belongs to the period as coverage was provided (not merely written/sold).
  • Incurred losses — losses attributed to the period, which typically include amounts paid and amounts reserved for claims that are known but not fully settled (definitions and inclusions can vary by context — e.g., whether certain claim expenses sit in the loss ratio or elsewhere).

If a book earns $100 of premium and incurs $65 of losses in the same framing, people will call that a 65% loss ratio.

That single number does not tell you whether the company is “healthy” overall. Expenses still exist. Investment income still exists. One year is not a career. Cyber is still a maturing line with lumpiness.

Cousins you will hear next

Combined ratio

Roughly: loss ratio + expense ratio (underwriting expenses relative to premium). A combined ratio under 100% is the classic shorthand for underwriting profit before considering investment income; over 100% means underwriting loss on that framing. People casually say “loss ratio” when they mean “combined ratio.” Ask which.

Expense ratio

Operating / underwriting expenses ÷ premium. Cyber has real expenses: underwriting staff, panels, vendors, distribution. A “great” loss ratio with a bloated expense structure is not a victory lap.

Accident year vs calendar year (and reporting lags)

When you attribute losses matters. Cyber claims can develop: a quiet breach becomes a loud regulatory matter months later. Reserves get set and revised. That is one reason a single calendar snapshot can mislead outsiders — and why carriers talk about development and severity.

Frequency vs severity

Loss ratio is an aggregate. A book can be fine on frequency and ruined by a handful of severe ransomware or privacy events — or the reverse. Cyber’s modern history has been as much about severity (and systemic correlation) as about ticket volume.

How to hear “loss ratio” in a cyber meeting

Someone says…Often they mean…
“Loss ratios were ugly in [year]”Claims (and maybe reserves) ate too much of earned premium; appetite/pricing/terms reacted
“We’re protecting loss ratio”Underwriting will tighten selection, price, limits, or wording
“That segment hurts the ratio”A vertical, attachment point, or product form is running hot
“Improve the loss ratio with better risks”Select differently / price differently / reduce claim severity — not “buy a dashboard”

Notice what is not automatically implied: that your company’s phishing simulation score is the loss ratio lever. Portfolio outcomes are driven by who was written, at what price and terms, and what losses emerged — including events no questionnaire predicted.

What loss ratio is not

  • Not your personal grade. Your premium is not “your loss ratio.”
  • Not a coverage term on your policy. It is a book metric.
  • Not a promise you can vendor into existence. Anyone who sells “we will cut your loss ratio by X%” without a defined book, period, methodology, and honest caveats is selling a slogan.
  • Not only “claims paid ÷ cash received this month.” Incurred vs paid, earned vs written — the accounting choices matter.

Why cyber people obsess over it anyway

Because cyber has had periods where premium growth and loss experience got out of sync — soft pricing, rising ransomware severity, then corrections via rate, retention, sublimits, and control requirements. When leadership says “fix the cyber loss ratio,” the downstream effects are exactly what insureds experience as “the market hardened.”

U.S. regulators also collect cyber market data through the NAIC’s Cybersecurity Insurance Coverage Supplement (and related reporting). Periodically, NAIC staff publish market reports summarizing premiums, losses, and loss-ratio style views across reporting groups. Those reports are useful context for how the line is supervised and discussed — not a substitute for any one carrier’s private management metrics, and not numbers we will paste here as if they were timeless.

For security leaders: how this changes your job

Understanding loss ratio should make you more practical, not more cynical:

  1. Carriers are not randomly cruel; they are responding to book economics and capital constraints.
  2. Your leverage is claim-relevant risk reduction that underwriting can believe — controls that are real, exposure that is verified, trends that show improvement.
  3. Shopping only on premium without reading quote terms can shift loss to you via retention and sublimits while the carrier’s ratio looks “better.” That might be intentional risk transfer design. Know which game you are playing.

For insurance readers: our stance

BreachBits talks about loss ratio carefully on purpose. We believe better verification of exploitable exposure helps underwriting select and monitor risks in a way that is aligned with claim reality. That is a theory of signal quality. It is not a guaranteed ratio outcome on your book. Anyone in this channel who cannot hold that distinction will eventually embarrass themselves in front of an actuary.

Authoritative starting points

  • NAIC Glossary — Loss Ratio
  • Current NAIC cybersecurity insurance market reports via content.naic.org (search “cybersecurity insurance” / Cyber Supplement)
  • Your own carrier’s or reinsurer’s definitions in management reporting — internal metrics may include or exclude ALAE/DCC differently than a glossary one-liner

Next: the timeline from first conversation to on-risk and renewal — application → bind → renew.

See your cyber risk, proven.