Estimated reading time: 9 minutes
Security leaders trust AI with almost nothing. Their carriers approved ransom payments in half the cases where money moved.
A third party made the payment decision in half of the ransomware cases where a ransom got paid. Arctic Wolf names the cyber insurer as the example. The finding sits on page 13 of the company’s 2026 AI & Cybersecurity Trends Report, released July 28. The report leads with something else. It frames the year’s story as an AI trust gap, and that gap is real. For cyber insurance underwriters and claims teams, the payment data matters more.
The Payment Gap
Of respondents hit by ransomware, 56% paid some portion of the demand. Arctic Wolf splits that group in two. Half the payment decisions came from the victim organization. The other half came from a third party acting on the organization’s behalf.
North America pays the most. Among regional respondents hit by ransomware, 74% saw a payment made. Direct payments account for 38%. Payments through an insurer or other third party account for 35%. That is the highest rate in the study.
Europe reported 57%. Asia-Pacific and Japan reported 43%.
Now set that against Arctic Wolf’s own casebook. The company’s 2026 Threat Report shows 23% of its ransomware incident response cases involved any payment. The other 77% closed with nothing paid to the attacker.
Kerry Shafer-Page, Arctic Wolf’s Vice President of Incident Response, reads the gap as a pattern. Organizations without expert guidance rush to pay. They treat payment as the fastest route out. The report’s verdict on that route runs three words: “It rarely is.” Many threat actors negotiate for a living and exploit that urgency.
The comparison deserves a caveat. The survey covers 1,350 organizations across many vendors. The 23% figure covers Arctic Wolf’s own clients, who bought incident response services. Those clients selected themselves. Arctic Wolf also sells the retainers it credits for the difference.
The trend inside Arctic Wolf’s book still moved. Its 2025 Threat Report put the no-payment rate at 70%. This year it reads 77%.
Security Leaders Will Let AI Act. They Will Not Let It Stand Down.
The adoption numbers look settled. LLMs now run in 94% of organizations. Another 94% say AI capabilities shape their security purchasing. Just over half, 51%, treat AI functionality as a hard requirement when evaluating vendors.
Then the trust numbers arrive. Only 14% have made AI central to their security operations strategy.
Blocking a malicious IP address or domain at the firewall is the single task a majority trusts AI to handle alone. That majority is 53%. Every other task falls below half. Generating incident summaries reaches 49%. Locking out a compromised account reaches 44%. Automatically patching a known critical vulnerability reaches 42%.
The lowest number is the most revealing. Only 29% trust AI to dismiss an alert it believes is a non-issue. Leaders will let a machine take an action. They will not let it decide that nothing is wrong.
Data privacy tops the list of reasons at 51%. Lack of human intuition follows at 49%. Hallucination risk, manipulation risk, and unclear accountability fill out the top five. AI also ranks as the top cybersecurity concern for the second year running, cited by 35%. Ransomware sits second at 25%.
Adam Marrè, Arctic Wolf’s Chief Information Security Officer, framed the finding in the announcement. “The challenge now is trust,” Marrè said.
Confidence Runs Ahead Of Results
Some 96% of leaders say their teams can keep pace with today’s threats. That figure includes 53% who describe themselves as very confident.
In the same survey, 63% confirmed at least one significant cybersecurity incident in the previous 12 months. A further 7% suspect an incident happened without detection.
Only 13% of affected organizations escaped without losing time or productivity. Nearly half, 48%, lost two weeks or more. Around 9% reported disruption lasting two quarters or longer.
Confidence runs higher among organizations that got hit. Arctic Wolf raises survivorship bias as one reading. For carriers, that gap has a practical shape. Self-reported readiness on a renewal application may not predict much.
What Brokers Should Check Before Renewal
Incident response retainer adoption climbed from 64% two years ago to 74% now. Among organizations holding one, 62% used it at least once in the past year.
Arctic Wolf flags a coverage trap worth passing to clients. Prepaid retainer hours may fall outside a cyber policy. The report tells buyers to verify coverage with their carrier first. Its own verdict on the likely answer runs four words: “they probably aren’t.”
A second item belongs on every renewal checklist. Carriers usually approve reputable incident response vendors outside their preapproved panel. Arctic Wolf recommends securing that approval in writing when the retainer is signed. Chasing it during an incident costs hours nobody has.
Hours-based retainers create a third problem. Some 53% of leaders reported scrambling to use hours before they expired.
Arctic Wolf has commercial skin in this argument. It sells a coverage-based alternative, launched in May 2025. Dan Schiappa, the company’s president of technology and services, framed the pitch at launch. “It’s no longer a question of if, but when a severe cyberattack will occur,” Schiappa said.
Insurers Are Becoming The Disclosure Driver
Disclosure remains near-universal. Some 94% of organizations disclosed their cybersecurity incident.
The reasons are shifting. Legal requirement drove 45% of disclosures, down from 51% a year ago. A requirement from an insurance provider or other outside entity drove 36%, up from 34%.
Two small moves in opposite directions. Insurers are gaining ground on regulators as the reason incidents surface. Only 13% disclosed voluntarily to help the wider security community.
Insurance pressure shows up in strategy too. The report ranks the drivers of 12-month cybersecurity strategy by industry. Most sectors put data transformation and secure AI adoption first. Government and public sector organizations put increased cyber insurance costs or loss of policy first instead.
Public sector buyers are being moved by their carriers more than by AI.
Regional Signals For UK And EU Buyers
EMEA respondents named the United States the second-largest nation-state threat to their business. China placed first. Russia placed third.
Digital sovereignty now drives purchasing across the region. Around 48% call it extremely important to their cybersecurity strategy. Another 40% call it important. Half are actively screening vendors on headquarters location, data residency, and government access risk.
The DACH region has gone further. Buyers there require that AI stay controllable and regional. They require that large language models be explicitly permitted. They require that humans remain in the loop.
Those are procurement conditions, not preferences. Any insurtech selling AI-assisted underwriting into Germany, Austria, or Switzerland will meet them.
Elsewhere, Singapore reported the highest trust in autonomous AI and some of the worst outcomes. Some 61% experienced a major incident. Around 13% reported disruption lasting six to nine months.
About The Survey
Sapio Research conducted the survey in April 2026 on Arctic Wolf’s behalf. It covers 1,350 IT and security decision-makers at director level or above. Respondents came from the United States, United Kingdom, Canada, ANZ, DACH, the Nordics, Benelux, Singapore, Japan, and South Africa. Arctic Wolf reports a margin of error of 2.7 percentage points at 95% confidence.
Read the findings with the sponsor in view. Arctic Wolf sells managed detection and response, incident response retainers, and an AI platform built around a validation layer. Each headline problem in the report maps to something the company sells. The closing section makes the argument directly, arguing that a product still requiring customer assembly amounts to “a toolkit.”
Two numbers in the report also conflict. Pages 19 and 20 put the incident rate at 70%, while page 10 and the announcement put it at 63%. The higher figure appears to fold in the 7% who suspect an undetected incident. The report does not say so.
Arctic Wolf’s insurance footprint keeps growing regardless. Chubb named the company a preferred managed detection and response provider in February. Nick Schneider, the company’s president and CEO, called the selection “powerful validation” at the time.
FAQ: Arctic Wolf 2026 AI And Cybersecurity Trends Report
Arctic Wolf found that 56% of ransomware victims paid some portion of the demand. In half those cases, the victim organization made the decision. In the other half, a third party made it, and Arctic Wolf cites the cyber insurer acting on the organization’s behalf as the example.
North America. Among regional respondents hit by ransomware, 74% saw a payment made. Direct payments accounted for 38% and payments through an insurer or third party accounted for 35%. Europe reported 57%, and Asia-Pacific and Japan reported 43%.
Arctic Wolf’s 2026 Threat Report shows 23% of its ransomware incident response cases involved any payment. The company attributes the gap to expert negotiation and says organizations without guidance rush to pay. The comparison is not controlled. Arctic Wolf clients bought incident response services and selected themselves into that population.
Only one task cleared a majority. Some 53% trust AI to block malicious IP addresses or domains at the firewall. Generating incident summaries reached 49%, locking out a compromised account 44%, and automatic patching 42%. Dismissing an alert believed to be a non-issue ranked lowest at 29%.
Often not. Arctic Wolf advises buyers to confirm coverage with their carrier before purchasing a prepaid retainer, and states that prepaid hours probably are not covered. The report also recommends securing written carrier approval for any incident response vendor outside the carrier’s preapproved panel before an incident occurs.
Some 74% hold one, up from 64% two years ago. Among those, 62% used it at least once in the past year. Roughly 53% of leaders reported pressure to use contracted hours before losing them.
Legal requirement drove 45% of disclosures, down from 51% the previous year. A requirement from an insurance provider or other outside entity drove 36%, up from 34%. Some 94% of organizations disclosed their incident overall, while 13% disclosed voluntarily to share findings with the security community.
Related Cyber Insurance Posts
- Cowbell Launches OMNI With 53% Growth. Loss Ratio Is Too Early To Judge.
- Arctic Wolf’s 2024 Security Operations Report Highlights Growing Cybersecurity Challenges(Opens in a new browser tab)
- LevelBlue Launches Incident Response Retainer Aligned With Cyber Insurance Requirements(Opens in a new browser tab)
- In 74% of Ransomware Attacks, the Crooks Got At Least Some $: Arctic Wolf Survey(Opens in a new browser tab)