The 2025 Midyear Cyber Risk Report: Houston Businesses Face Evolving Ransomware Threats
2025 Cyber Risk Report Shows Businesses Face 17% Increase In Ransomware Attack Severity – Cyber Insurance Claims Drop 53% But Successful Attacks Hit Businesses Harder Than Ever
Claims to Houston-area insurers fell by more than half in early 2025. That number sounds like good news, and it is the most dangerous line in the whole report to read on its own.
The 2025 Midyear Cyber Risk Report is Resilience's read on real cyber insurance claims from the first half of 2025. Its headline is a paradox: far fewer claims, far more expensive ones. For a Houston business, the useful part is not the trend line - it is the four assumptions the data quietly demolishes.
Most write-ups of this report lead with the 53% drop in claims and stop there. That framing invites exactly the wrong conclusion, which is that the threat eased off. It did not. Ransomware got 17% more severe and now drives 76% of every dollar of insured loss. The mix of what causes those losses shifted too, toward your vendors and toward the money-movement side of your business. This post walks through four things Houston SMBs assume about cyber risk and sets each one against the report's actual claims figures.
What Does the 2025 Midyear Cyber Risk Report Overturn?
Four assumptions Houston businesses carry into a renewal meeting, next to what Resilience's claims data actually shows.
The gap between what a Houston SMB assumes about cyber risk and what shows up in real insurance claims is where the budget goes wrong. The 2025 report closes four of those gaps with hard numbers on severity, targeting, attack vector, and vendor exposure.
Here is the contrast, four beliefs deep. On the left is the comfortable version many owners repeat. On the right is what the Resilience claims portfolio recorded for the first half of 2025.
If Claims Dropped 53%, Why Is the Threat Worse?
The "claims are down" headline, and the severity trend it hides.
Fewer cyber insurance claims does not mean less danger. In the first half of 2025, Resilience recorded a 53% drop in claim frequency compared to a year earlier, but the average ransomware claim grew 17% more severe and now exceeds $1.18 million. Frequency fell; the cost of getting hit rose.
Read the drop in isolation and the obvious conclusion is that attackers eased off. The claims data says the opposite happened. Successful attacks got more selective and more expensive. A ransomware incident that led to an incurred claim averaged around $705,000 in 2024; in 2025 that figure passed $1.18 million. The overall average loss per incurred claim slipped 11%, but ransomware pulled sharply the other way, which is why it now accounts for 76% of every dollar of insured loss in the portfolio.
Jeremy Gittler, Global Head of Claims at Resilience, put the trap plainly in the report: the frequency number tells you nothing about what a single bad day now costs you.
- Frequency and severity moved in opposite directions. A 53% drop in claims sat next to a 17% jump in ransomware severity. The average is not the story; the tail is.
- One incident can now clear seven figures. An average ransomware claim above $1.18 million is a business-ending number for most 10-to-200-person Houston firms without coverage and recovery in place.
- The "good news" is a budgeting trap. Reading fewer claims as lower risk is exactly how the security line item gets cut the year before it is needed most.
Is Ransomware Really a Big-Company Problem?
Why the 76%-of-losses figure lands on small businesses too.
Ransomware drove 76% of all incurred losses in the Resilience portfolio in the first half of 2025 - 91% once you count losses from a vendor hit by ransomware. It is the single most financially damaging cyber peril, and it does not skip a business because the business is small.
The assumption is that ransomware crews chase big payouts, so a 30-person accounting practice in Katy or a mid-size construction firm in Cypress falls below the threshold. The claims data does not support that comfort. Ransomware is the top cause of loss across the whole portfolio, and the reason it stays there is that the attack model works at any size. Payment rates actually fell - only 14% of ransomware claims in early 2025 involved a known extortion payment, down from 22% the year before, because more organizations restored from backups. That is progress, and it is also why attackers lean harder on double extortion, stealing data and threatening to publish it so a clean backup is no longer a full escape.
For a smaller Houston business, the danger is rarely the ransom check itself. It is the days or weeks of downtime while systems are rebuilt, the client data sitting on a leak site, and the recovery bill that dwarfs the demand. That is what pushes a single ransomware claim past $1.18 million on average.
- Ransomware is the loss leader. At 76% of incurred losses, it outweighs every other cause combined, which is why it deserves the first security dollar, not the last.
- Backups moved the fight, not ended it. Lower payment rates are real progress, but double extortion means a backup alone no longer neutralizes the threat of a public leak.
- Downtime is the real bill. For a Houston SMB, business interruption and recovery, not the ransom, are what make an incident catastrophic.
Is Email Still a Small Piece of the Risk?
The vector that quietly drives most of the losses.
Email and the human behind it are not a minor risk in the 2025 data - they are the main one. Social engineering accounted for 57% of incurred claims and 60% of incurred losses in the first half of 2025. Phishing alone drove 19% of claims and 49% of losses. The inbox is the front door most attackers walk through.
The comfortable version says a spam filter and an annual training video have the email problem handled. The claims data says social engineering is the dominant path to a loss, and it is getting harder to stop, not easier. Resilience reports that AI-generated phishing campaigns now hit a 54% success rate, against roughly 12% for traditional attempts. Attackers have moved past bad grammar and obvious links into browser-based phishing and voice impersonation that can bypass multi-factor authentication and fool a finance clerk into approving a wire.
That last part connects directly to money movement. Transfer fraud - what the report calls payment-control failure - made up 26% of incurred claims but only 8% of losses, because those attacks are usually capped by policy sub-limits. Do not let the small loss share mislead you: the FBI's 2024 Internet Crime Report logged more than 21,000 business email compromise complaints totaling over $2.7 billion, the second most damaging category of cybercrime after investment fraud. The frequency is high; the coverage just hides the true cost.
- Social engineering is the top loss cause after ransomware. At 60% of losses, the human-and-email layer is where most breaches begin, not a side risk.
- AI raised the hit rate. A 54% success rate on AI phishing versus 12% on old attempts means your people face far more convincing attempts than the training deck assumes.
- Transfer fraud is common but under-reported. 26% of claims trace to a payment-control failure; policy sub-limits mask how much a business email compromise actually costs.
Close the Email and Money-Movement Gap
The single highest-value control against the 2025 loss pattern is layered email defense plus a hard rule on verifying payment changes out of band. CinchOps builds both into its cybersecurity and managed IT programs for Houston-area businesses.
Explore CinchOps cybersecurity →When a Vendor Gets Breached, Whose Loss Is It?
The rise of third-party risk as the second-largest loss driver.
A vendor's breach becomes your loss. In the Resilience portfolio, vendor-related incidents accounted for 22% of losses in 2024 and 15% in the first half of 2025, making third-party risk the second-largest loss driver behind ransomware. When a supplier goes down, your business interruption is a real, insurable loss - and it is yours.
The old belief is that a supplier's security is the supplier's problem. The 2025 report treats that as one of the more expensive assumptions a business can hold. In 2024, vendor-related incidents made up more than a third of all claims notices. The dollars followed: when a managed platform, a software provider, or a payment processor that many companies rely on gets hit, the outage ripples out to every customer at once. The report points to the spring 2025 retail attacks, where the companies directly breached were also key suppliers, so losses spread far beyond the initial victims.
For a Houston SMB, this reframes vendor selection as a security decision, not just a procurement one. The construction firm whose project-management SaaS is down cannot bill. The CPA practice whose document platform is encrypted cannot serve clients at filing time. Ratings and a one-time questionnaire capture a vendor's posture at a single moment; real exposure needs ongoing attention to which suppliers, if they failed, would stop your business.
- Vendor risk is now second only to ransomware. At 15% of H1 2025 losses, third-party incidents are a top-tier driver, not an edge case.
- Concentration is the multiplier. One breached provider serving many companies turns a single incident into simultaneous losses across its whole customer base.
- Business interruption is the mechanism. You rarely lose data in a vendor incident; you lose the ability to operate, and that downtime is the insurable loss.
Every renewal season, a Houston owner shows me the lower claim numbers and asks if we can trim the security budget. In 35 years doing this, that is the exact conversation that precedes a bad year. The 2025 report is telling you the same thing I do: the odds of getting hit went down a little, and the price of getting hit went way up. You do not plan for the average day. You plan for the $1.18 million one.
How CinchOps Helps Houston Businesses Answer This Report
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees - and builds the exact controls the 2025 claims data says prevent losses.
Each of the four assumptions this report overturns maps to a concrete set of protections we put in place and manage:
- Ransomware defense and recovery. Endpoint protection, network segmentation to stop lateral movement, and tested backup and disaster recovery so a $1.18 million-average incident does not end the business - the answer to "ransomware hits big companies."
- Layered email and identity security. Email filtering, multi-factor authentication, and awareness training tuned to AI-driven phishing - the answer to "email is a minor risk."
- Payment-verification controls. Out-of-band verification rules for any change to wire or vendor payment details - the answer to transfer fraud sitting behind 26% of claims.
- Vendor risk management. Ongoing monitoring of the third parties your operation depends on, so a supplier's breach does not quietly become your business interruption - the answer to "that is the vendor's problem."
- 24/7 monitoring and response. Detection that catches an intrusion in progress and contains it before it becomes an incurred claim.
If you run a business in Houston, Katy, or Cypress - whether you are a CPA firm, a construction company, or a law firm - the takeaway from the 2025 report is not to relax because claims fell. It is to fund the controls that keep a rare bad day from being a fatal one. If your renewal made cyber risk feel smaller this year, talk to CinchOps and we will show you where the real exposure moved.
Frequently Asked Questions
What is the 2025 Midyear Cyber Risk Report?
It is a report from cyber insurer Resilience analyzing real cyber insurance claims from the first half of 2025. It tracks which security failures turn into financial losses. Its central finding is that claim frequency fell 53% while severity rose, with ransomware driving 76% of all incurred losses.
Why did cyber insurance claims drop but risk go up?
Claim frequency fell 53% in the first half of 2025, but the incidents that succeeded were more damaging. Ransomware severity rose 17% year over year, pushing the average ransomware claim above $1.18 million. Fewer attacks landed, but each one cost far more, so overall risk did not ease.
What is the biggest cyber loss driver for businesses in 2025?
Ransomware, by a wide margin. The Resilience report attributes 76% of incurred losses to ransomware, rising to 91% once losses from a vendor hit by ransomware are included. Vendor-related risk was the second-largest loss driver, and social engineering caused about 60% of losses.