Treatise 05: Empirical Cyber Insurance Market Observations
J. McKenney
This is a short field-observations note in Working Group WG-01-UI (Underwriter & Insurance). It records observed underwriting telemetry practice as a companion to the working group's introductory overview, WG-01-UI-1-Overview, without repeating that paper's foundational actuarial mathematics, and it names the same Annualized Loss Expectancy calculation the overview introduces.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
These are field observations on how cyber insurance is underwritten today, not a derivation of new theory. Six practices recur across the market: continuous outside-in scanning of an applicant's digital footprint in place of a one-time questionnaire; the actuarial mathematics for pricing heavy-tailed rather than normally distributed losses; the modeling of systemic risk that spreads across many policyholders through shared digital infrastructure; the calculation of business-interruption claims; the telemetry-driven captive model used by companies that self-insure; and the loading and discount factors that turn a technical price into a commercial one. Named constructs run from Annualized Loss Expectancy and zero-inflated Poisson frequency to Hawkes processes for contagion, an eight to twelve hour time deductible for interruption cover, and a one million dollar extortion sublimit inside a ten million dollar policy.
None of the six sections claims to be exhaustive or to establish a market-wide statistic. Each names the model or practice in use, and where a number appears it is a stated range rather than a fitted or measured figure. Section 3 is explicit about this: it names the Hawkes model choice and states plainly that it cites no study for the clustering effect it describes.
Read with the working group's overview, WG-01-UI-1-Overview, this note gives a practitioner a compact account of what has changed in cyber underwriting practice, continuous telemetry, heavy-tailed pricing, and captive self-insurance, without repeating the actuarial foundations the overview already covers.
Abstract#
Insurance companies and underwriters are moving away from static questionnaires toward quantitative models driven by continuous telemetry, actuarial mathematics, and systemic risk modeling. This note records six observed practices: outside-in continuous assessment through platforms such as BitSight, SecurityScorecard, and CyberCube; heavy-tailed actuarial mathematics using Annualized Loss Expectancy, zero-inflated Poisson frequency, and Monte Carlo simulation over log-normal severity; systemic accumulation modeling with epidemic network models and Hawkes processes; cyber business interruption calculated as Rate of Gross Profit on the turnover shortfall; captive OT risk auditing, as in Heineken's factory telemetry; and premium modification, where global MFA yields a 15 to 20 percent discount and a flat unsegmented network a 20 to 50 percent surcharge. Each section names the models and platforms in use without asserting a market-wide statistic beyond what is stated.
1. Continuous Telemetry and Outside-In Assessment#
Underwriters now use platforms like BitSight, SecurityScorecard, and CyberCube to conduct continuous, non-intrusive "outside-in" scans of an applicant's digital footprint. They map the attack surface by evaluating internet-facing assets, exposed vulnerabilities (CVEs), the enforcement of Multi-Factor Authentication (MFA), and Endpoint Detection and Response (EDR) software. This allows insurers to monitor emerging vulnerabilities mid-policy, transitioning their role from pure risk transfer to active risk mitigation partners. Additionally, third-party penetration testing has become a strict prerequisite to validate controls against threats like SQL injections, and underwriters heavily weight an organization's adherence to frameworks like NIST 800-53 or ISO/IEC 27001.
2. Advanced Actuarial Mathematics and Loss Estimation#
Cyber risk does not follow a standard "normal" (bell curve) distribution; instead, it follows heavy-tailed "Power Law" or Generalized Pareto distributions, meaning a single extreme event can cause losses exceeding the sum of all other claims in a decade. To price this, actuaries use:
- Annualized Loss Expectancy (ALE): Calculated by multiplying the Single Loss Expectancy (the cost of one incident) by the Annual Rate of Occurrence to establish the baseline "Pure Premium".
- Zero-Inflated Poisson Models: Used to model breach frequency, accommodating the fact that most organizations experience zero material breaches, while a minority experience cascading incidents.
- Monte Carlo Simulations: Underwriters use tens of thousands of probabilistic simulations based on Log-Normal distributions to account for "Black Swan" events and determine the "Tail Risk" threshold at which they must cede risk to external reinsurers.
3. Systemic Accumulation Risk Modeling#
Unlike physical catastrophes, cyber risk is borderless and systemic, propagating downward through shared digital infrastructure like cloud platforms and software supply chains. To model this non-diversifiable accumulation risk, actuaries deploy:
- Epidemic Network Models: Drawing from biological epidemiology to simulate how malware spreads through interconnected supply chains.
- Hawkes Processes: Self-exciting point models used to capture "contagion," reflecting the reported clustering in which one major cyber event temporarily raises the probability of subsequent events. This note cites no study for the clustering and states none of its own; the model choice is the observation being recorded here, not a fitted excitation rate.
- Realistic Disaster Scenarios: Catastrophe modeling platforms stress-test an insurer's entire portfolio against theoretical extreme events, such as a widespread software supply chain compromise or a coordinated attack on the power grid, to ensure the insurer remains solvent.
4. Cyber Business Interruption (CBI) Focus#
For industrial and manufacturing entities, the most expensive aspect of a cyberattack is typically operational downtime, rather than ransomware payouts or data recovery. Underwriters calculate CBI claims using the Rate of Gross Profit applied to the shortfall in turnover. Insurers typically mandate "time deductibles"; waiting periods of 8 to 12 hours before coverage triggers; and heavily discount premiums if a company can prove a Mean Time to Resolve (MTTR) below this window.
5. Inside-Out OT Risk Auditing (Captive Models)#
For critical infrastructure and manufacturing, underwriters must also account for Operational Technology (OT) risks, analyzing the "Digital-Physical Interface" where an IT breach could shut down physical machinery. For example, companies operating their own captive insurance models, like Heineken, use real-time telemetry from their own factory networks to dynamically adjust premiums. If a specific brewery demonstrates strong OT network segmentation or an exceptionally low employee phishing click rate, the underwriter immediately applies a "Premium Credit" to reduce their internal insurance costs.
6. Premium Modification and Liability Caps#
Finally, underwriters bridge the gap between the baseline technical price and the commercial price using loading factors (surcharges) and discount factors (credits). For instance, implementing global MFA can yield a 15 to 20 percent discount multiplier, while maintaining a flat, unsegmented network can trigger a 20 to 50 percent surcharge. To protect their balance sheets from catastrophic severity, insurers aggressively apply strict sublimits (e.g., a maximum $1 million payout for extortion within a $10 million policy) and liability caps.
7. References#
The platforms and control frameworks recorded above are BitSight, SecurityScorecard and CyberCube for outside-in assessment, and NIST 800-53 and ISO/IEC 27001 as the frameworks underwriters weight. The actuarial models recorded above are Annualized Loss Expectancy, zero-inflated Poisson breach-frequency models, Monte Carlo simulation over log-normal severity, epidemic network models, and Hawkes processes.