Summary
- Munich Re has agreed to acquire At-Bay for an enterprise value of $575m.
- At-Bay combines cyber insurance with security monitoring and managed detection services aimed largely at smaller organisations.
- Technical risk data is giving insurers a way to influence exposure throughout a policy rather than assessing it only at renewal.
German reinsurance group Munich Re has agreed to acquire cyber insurer and security provider At-Bay for an enterprise value of $575m, tightening the connection between underwriting digital risk and monitoring the systems that create it.
The transaction will place At-Bay under Hartford Steam Boiler, Munich Re’s technology-focused specialty insurance business, subject to regulatory approvals and other closing conditions. Completion is expected during the first quarter of 2027.
At-Bay primarily serves small and medium-sized US businesses, combining cyber insurance with services intended to detect vulnerabilities and reduce the likelihood of claims. Munich Re says the company had $278m in gross written premiums at the end of 2025, alongside $23m in cyber service revenue.
The acquisition consequently gives a large incumbent insurer ownership of more than an insurance portfolio. At-Bay continuously monitors aspects of insured organisations’ technical exposure and feeds security information back into risk management and underwriting, bringing the condition of a customer’s systems closer to the financial risk carried by the insurer.
Cyber cover becomes a continuous service
Commercial insurance has traditionally assessed risk at defined points: when a policy is written, renewed, or when an incident creates a claim. Cybersecurity fits that rhythm poorly because an organisation’s exposure can change between those moments as vulnerabilities emerge, software is added, credentials leak, employees move, and attackers change tactics.
At-Bay was built around the idea that an insurer can have more direct visibility into some of those changes. Its security operation includes vulnerability monitoring and managed detection services alongside insurance products, giving the provider an opportunity to intervene before an incident rather than solely pricing the likely cost afterwards.
Munich Re and HSB have been involved with At-Bay since its early development, making the acquisition an expansion of an existing relationship rather than a sudden entry into cyber insurance. Munich Re Ventures was already among At-Bay’s investors.
Mike Kerner, a member of Munich Re’s board of management, said the acquisition would become “an essential component of our future cyber offering”. HSB president and chief executive Jeffrey O’Shaughnessy described the market as moving towards “vertically integrated insurer-security platforms”.
That phrase captures where competition is developing. Cyber insurers are not only competing over premiums and policy wording; they are trying to improve the information used to decide which organisations to insure, how to price the exposure, and which interventions can reduce the frequency or severity of losses.
Security data changes the underwriting model
Technical data can improve that process because many conditions associated with cyber incidents are observable. Internet-facing vulnerabilities, insecure remote-access systems, exposed credentials, missing controls, and unusual network activity can be measured more frequently than conventional insurance questionnaires are completed.
An insurer with access to those signals can request remediation before offering cover, alter underwriting decisions according to observed exposure, provide services intended to reduce losses, and analyse claims across a large portfolio to identify which technical characteristics correlate with incidents.
That integration also creates tension. Customers may be uncomfortable with insurers continuously observing aspects of their security posture, while automated technical measurements can be incomplete or misleading when interpreted without context.
Providers combining defence and underwriting will also need clear boundaries around how information collected for security is used during pricing, renewal, and claims decisions. The same telemetry can have very different consequences depending on which part of the organisation is using it.
The model is particularly relevant to smaller companies, which often lack substantial internal security teams while remaining exposed to ransomware, credential theft, business email compromise, and vulnerable software. Munich Re says At-Bay protects close to 40,000 US organisations, creating a substantial dataset linking security conditions with insurance outcomes.
Rotem Iram, At-Bay’s chief executive and co-founder, has built the company around closing that protection gap, while Munich Re expects its capital and distribution to support further growth. The strategic test is whether combining operational security with underwriting can improve loss performance as well as generate additional service revenue.
That becomes more important as cyber insurance pricing becomes competitive. Insurers cannot indefinitely compensate for uncertain exposure by raising premiums, particularly as additional capital enters the market.
A provider capable of reducing the frequency or severity of incidents could therefore gain an advantage over one that merely transfers the financial consequences after an attack. Cyber risk is unusual in insurance because the insurer can potentially influence parts of the underlying exposure through technology.
The $575m acquisition turns that proposition into a larger bet for Munich Re. If the model works, the distinction between a cyber insurer and a security provider will become less tidy, with policy economics depending increasingly on technology designed to identify and reduce risk before anybody makes a claim.












