Physics-Grounded Cyber Underwriting: Deriving Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE) from Unified BIM+BOM Asset Registers
J. McKenney
This paper belongs to the WG-01-UI underwriter-insurance working group alongside WG-01-UI-Quantitative-Cyber-Physical-FMECA, which derives Annualized Loss Expectancy from component-level failure-mode scoring rather than, as this paper does, from a unified physical and cyber asset graph; the two are companion treatments of the same underwriting problem rather than entries in a numbered series, and neither names an unpublished sibling.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Insurers who write cyber cover for factories, pipelines and data centres price the risk from a checklist: multi-factor login, endpoint monitoring, penetration tests. None of those questions says whether an attacker inside the network can actually break a piece of physical equipment such as a chiller or a transformer, or what repair and replacement would cost.
This paper prices the risk from the physical asset register itself. It combines the plant's engineering model, the piping and instrumentation diagrams and equipment specifications used to build and maintain it, with a full inventory of the hardware and software running its control systems. From the two it derives what a single successful attack on a given piece of equipment would cost, an estimate of how often such an attack is likely, and multiplies them into an annual expected loss.
Because one vulnerable software component can sit inside many unrelated facilities, a single exploit can cause losses at many sites at once, which behaves differently from the independent, spread-out losses ordinary insurance is priced against. The paper models this correlated tail risk statistically and uses the result to size how large a captive reserve or reinsurance treaty must be to cover the loss.
The claims rest on the derivation and on the standards cited for how the asset and vulnerability data is structured; it presents no results from a live underwriting book.
Abstract#
Commercial property and cyber insurance markets struggle to underwrite cyber-physical infrastructure: qualitative security questionnaires do not predict physical asset damage, and classical actuarial models lack exposure metrics for cyber-induced mechanical destruction. After the introduction of war, state-sponsored cyber, and infrastructure exclusions such as the state-backed cyber-attack exclusion required by Lloyd's Market Bulletin Y5381, industrial operators and hyperscale data center owners carry unhedged balance-sheet liabilities. From research by J. McKenney and the Eigenia Systems Research Group, this monograph presents a physics-grounded actuarial framework derived from the unified DEXPI 2.0 (BIM and P&ID) and CycloneDX 1.6+ (5-BOM) cyber digital twin graph (G_CPDT). It derives Single Loss Expectancy (SLE), Annualized Rate of Occurrence (ARO), and Annualized Loss Expectancy (ALE) by coupling topological asset vulnerability to multi-physics damage functions (Phi_damage). To resolve systemic accumulation across interdependent utilities, joint failure is modeled with the Clayton copula, which carries non-zero lower tail dependence (lambda_L = 2 to the power minus one over theta) during grid and cooling shocks. Return on Security Investment (ROSI) justifies hardware root-of-trust retrofits, and captive insurance vehicles and reinsurance treaties set attachment points and policy limits from verified digital twin state.
1. The Breakdown of Qualitative Cyber Underwriting#
Commercial insurance relies fundamentally on the law of large numbers and empirical historical loss distributions. In marine cargo, commercial fire, and structural engineering insurance, centuries of actuarial observation allow syndicates to price risk with tight confidence intervals. Underwriters consult standardized building codes, fire separation ratings, and sprinkler hydraulic calculations to quantify maximum foreseeable loss ().
In contrast, cyber insurance for industrial operational technology () and cyber-physical infrastructure has historically relied on qualitative questionnaires:
- Does the enterprise mandate multi-factor authentication () for remote administrative access?
- Is an endpoint detection and response () agent installed across all workstations?
- Are annual third-party penetration tests executed against external perimeters?
These surface surveys provide zero insight into whether an adversary traversing an unsegmented Purdue Level 2 network can issue unauthorized Modbus write commands to trip a 100 MW chiller bypass valve, or alter protective relay setpoints on an 11 kV busbar to induce transformer core saturation and tank rupture.
1.1 The Structural Consequences of Actuarial Failure#
The failure to ground cyber underwriting in physical mechanics has led to severe market dislocations:
- Systemic Accumulation Risk: Widely deployed software and firmware libraries (e.g., embedded TCP/IP stacks, RTOS kernels, or Modbus protocol parsers) exist identically across hundreds of independent facilities worldwide. A single zero-day vulnerability creates catastrophic accumulation that exceeds the statutory solvency capital of the global reinsurance market.
- Market Retraction & Sweeping Exclusions: Confronted with unquantifiable accumulation, underwriters have introduced draconian exclusions. Lloyd's Market Bulletin Y5381, issued by the Corporation of Lloyd's on 16 August 2022, requires that stand-alone cyber-attack policies written or renewed from 31 March 2023 exclude losses arising from war and from state-backed cyber attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state. Because attribution in cyber warfare is fraught with evidentiary disputes, insured operators face total coverage litigation precisely when catastrophic losses occur.
- Trapped Balance-Sheet Capital: Corporate risk managers cannot objectively quantify their physical downside exposure from cyber attack paths. Consequently, facilities either under-fund captive insurance retention layers, or over-pay for illusory commercial policies that deny coverage under exclusion clauses during major physical incidents.
The pipeline this paper derives runs from the two source graphs to the reinsurance layer, as follows.
2. Deriving Single Loss Expectancy (SLE) from Unified Digital Twin Topology#
In classical risk management, Single Loss Expectancy () is defined as:
In qualitative insurance underwriting, is arbitrarily estimated (e.g., assuming a standard 20 percent facility loss). In the physics-grounded framework established by J. McKenney, both and are computed deterministically from the unified cyber-physical digital twin graph:
Where:
- represents physical engineering components extracted from DEXPI 2.0 P&ID schemas (pumps, heat exchangers, valves, piping segments, transformers).
- represents cyber assets extracted from CycloneDX 1.6+ 5-BOM records (controllers, firmware images, cryptographic keys, communication ports).
- defines cyber-physical actuation and sensing edges, binding digital logic directly to mechanical equipment.
2.1 Asset Valuation Decomposition ()#
Asset valuation for any physical component is decomposed into direct replacement cost, physical reconstruction expenses, and downstream business interruption ():
Where:
- is the capital acquisition cost of the replacement asset, verified from the enterprise bill of materials.
- and account for certified rigging, electrical installation, and safety loop re-validation under IEC 61511.
- is the Mean Time to Replace, incorporating global supply chain procurement lead times. For specialized high-voltage autotransformers or liquid-cooled semiconductor heat exchangers, can span 12 to 24 months.
- represents the gross operating profit lost per unit time, formulated as:
2.2 Mathematical Exposure Factor () as a Multi-Physics Damage Function#
The Exposure Factor is not a static coefficient. It is a non-linear continuous mapping of the maximum physical stress state reached during an adversarial transient:
Depending on the physical domain of asset , the stress parameter represents temperature, fluid pressure, dielectric field strength, or mechanical angular velocity. We formulate three canonical physical damage kernels:
1. Thermal Degradation Kernel (Semiconductors & Transformer Insulation)#
For semiconductor junction temperatures in high-density compute infrastructure, or hot-spot temperatures in oil-immersed power transformers:
For silicon GPUs, (thermal throttling initiates), (emergency hardware shutdown trip), and (organic package substrate glass transition region, where irreversible package damage begins).
2. Hydraulic Joukowsky Water Hammer Kernel (Cooling Conduits & Valves)#
When an adversary maliciously commands an emergency isolation valve to slam shut within closing time , the resulting Joukowsky pressure transient induces circumferential hoop stress . The structural damage factor is governed by the material yield strength and ultimate tensile strength :
Where models work-hardening and micro-crack coalescence prior to catastrophic conduit rupture.
3. Deriving Annualized Rate of Occurrence (ARO) from Multi-BOM Security Posture#
In conventional risk engineering, the Annualized Rate of Occurrence () represents the estimated frequency of a damaging breach per calendar year. Rather than relying on aggregate industry averages, the physics-grounded framework computes for every cyber node by evaluating verified controls across the five CycloneDX BOM dimensions:
Where is the baseline threat activity rate for the industrial sector (calibrated from verified CISA KEV and ENISA threat telemetry), and represents rigorous empirical discount or penalty multipliers:
| BOM Dimension | Control Criterion / Metric | Secure State () | Insecure State () |
|---|---|---|---|
| Hardware Silicon Root-of-Trust | OCP Caliptra / TPM 2.0 measured boot active () | Legacy unmeasured NOR flash without signature verification () | |
| VEX Exploitability & Reachability | 100% of CVEs verified not_affected via static/dynamic call graphs () | Remotely exploitable CVEs in CISA KEV catalog without mitigation () | |
| Purdue Conduits & Zone Isolation | Hardware-enforced unidirectional optical data diodes () | Flat, routable Layer 2 bridge between enterprise IT and OT () | |
| Post-Quantum Cryptography & TLS | NIST FIPS 203/204 PQC (ML-KEM/ML-DSA) and mTLS 1.3 () | Hardcoded static credentials, Telnet, or cleartext Modbus TCP () | |
| Remote Telemetry & Vendor Tunnels | Air-gapped deployment with zero external SaaS egress () | Direct reverse SSH/VPN vendor tunnels over public WAN () |
3.1 Composite Annualized Loss Expectancy ()#
The total unhedged Annualized Loss Expectancy for a facility across all asset nodes is obtained by summing the product of node-specific and reachable :
4. Multivariate Loss Accumulation: The Clayton Copula Tail Risk Model#
A central vulnerability of classical actuarial models in critical infrastructure is the assumption of independence, or at best linear Pearson correlation, between distinct subsystems. During a cyber incident, failures do not manifest as independent Poisson processes. An attacker who breaches the building management system () can simultaneously sever primary electrical feeds while blinding the secondary emergency cooling loop.
Linear correlation models underestimate catastrophic joint tail events. We model the joint survival distribution of coupled critical infrastructure assets using the bivariate Clayton Copula, an Archimedean copula exhibiting strong asymmetric lower tail dependence:
Where and are the cumulative marginal probability distributions of loss severity for two interconnected subsystems (e.g., , ).
4.1 Derivation of Asymmetric Lower Tail Dependence ()#
The lower tail dependence coefficient quantifies the conditional probability of experiencing an extreme loss in asset , given that asset has suffered an extreme loss in the lower tail:
Substituting the Clayton copula generator into the limit:
Factoring out of the bracket:
Evaluating the limit as :
In contrast, the upper tail dependence coefficient for the Clayton copula is strictly zero:
This mathematical property mirrors industrial reality: under nominal operating conditions, electrical substation perturbations and chiller fluid dynamics operate independently (). However, under extreme adversarial shocks (), the lower tail dependence surges (), dictating that a primary power collapse carries a 75.8 percent conditional probability of simultaneous cooling collapse. Reinsurers relying on Gaussian models assume , mispricing catastrophic accumulation by orders of magnitude.
5. Return on Security Investment (ROSI) in a 100 MW Datacenter#
Chief Financial Officers and risk committees cannot justify multimillion-dollar engineering hardening on qualitative fear, uncertainty, and doubt (). translates technical digital twin parameters into standard corporate capital allocation metrics:
Where , and represents the annualized total cost of ownership (capital expenditure amortized plus annual operational maintenance).
5.1 Empirical Case Study: High-Density AI Liquid Cooling Manifold#
Consider a 100 MW high-density compute facility housing 16 high-density server halls. Each hall contains 32 Cooling Distribution Units () servicing direct-to-chip cold plates.
Baseline Posture (Unmitigated)#
- Asset Valuation: The physical replacement value of compute silicon, high-bandwidth memory (), and networking fabric across one dependent row is . Downstream business interruption for long-lead silicon () adds , yielding .
- Exposure Factor: In an unmitigated firmware compromise, an attacker forces proportional valves closed while suppressing temperature telemetry. Junction temperature reaches the emergency hardware shutdown trip point in 14.8 seconds, and with that protection suppressed it climbs on past the organic substrate glass transition region, where the damage becomes irreversible: .
- Occurrence Rate: Controllers run unverified firmware on legacy microcontrollers (), with unpatched network daemons (), and routed Modbus TCP (). Baseline threat rate .
Hardened Posture (Digital Twin Recommended Controls)#
The operator implements two physics-grounded engineering interventions:
- Silicon Root of Trust Retrofit: Replacement of legacy mainboards with OCP Caliptra-enabled cryptographic controllers (, ).
- Autonomous Analog Thermal Shunt: Installation of hardwired, spring-actuated bimetallic thermal dump valves that actuate mechanically at , entirely bypassing digital bus logic. Even if digital controllers are compromised, physical damage is bounded to transient thermal throttling: (residual labor inspection and fluid refilling).
Financial ROI Computation#
- Annual Loss Reduction (): .
- Capital Cost: One-time retrofitting cost of across 32 CDUs, plus calibration overhead.
- Three-Year Net Present Value & ROSI:
6. Structuring Captive Retention Layers and Parametric Reinsurance#
Armed with a continuous, cryptographically verified digital twin graph , industrial operators can transform their relationship with global reinsurance syndicates. Instead of purchasing broad commercial policies burdened by Lloyd's Y5381 exclusions, operators deploy a two-tiered alternative risk transfer () structure:
6.1 Narrowing Exclusion Disputes via Cryptographic Telemetry#
The state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 requires turns on whether a state-backed attack significantly impaired the ability of a state to function or the security capabilities of a state, and on the basis on which the attack is attributed to a state. Under traditional policies, forensic investigations drag on for years while insurers withhold payments.
Under the physics-grounded model:
- The reinsurance contract is structured as a parametric treaty with attachment point and limit .
- Payment triggers are bound strictly to immutable physical sensor states recorded by hardware-secured tamper-proof telemetry units (e.g., fluid discharge , transformer gas chromatography acetylene, or measured junction temperature for ).
- When the physical threshold is exceeded, the parametric payout executes automatically within 14 business days, so quantum is settled on the measured state of the plant rather than on a reconstruction of the intrusion.
7. Implementation Roadmap & Standards Alignment#
To operationalize physics-grounded cyber underwriting across industrial assets, organizations must execute a phased four-stage deployment:
- Topological Extraction: Ingest physical CAD/P&ID assets conforming to the ISO 15926 series and DEXPI 2.0 schema, populating with pipe geometries, design pressures, and component asset valuations.
- Multi-BOM Harmonization: Generate CycloneDX 1.6+ records across all five dimensions (HBOM, SBOM, OBOM, CBOM, SaaSBOM), ensuring hardware roots of trust (Caliptra/TPM) are cryptographically validated.
- Multi-Physics Simulation: Run automated transient thermal and hydraulic stress walks across all cyber-actuated physical paths, computing empirical exposure factors .
- Actuarial Calibration: Fit empirical damage distributions to the Clayton copula (), establish captive capitalization levels, and execute parametric reinsurance treaties with syndicates.
Regulatory and Normative Standards Mapping#
- IEC 62443-3-2: Formal risk assessment and zone/conduit partition verification.
- IEC 61511 / IEC 61508: Safety Instrumented System () independence and functional safety verification.
- EU Cyber Resilience Act (Regulation 2024/2847): Machine-readable vulnerability handling and mandatory SBOM maintenance under Articles 10 and 11.
- Lloyd's Market Bulletin Y5381: The state-backed cyber-attack exclusion clause it requires, read against physical telemetry demarcation.
8. Conclusion#
The historical reliance of commercial insurance on qualitative checklists has created a systemic vulnerability across global critical infrastructure. By unifying physical engineering models (DEXPI 2.0) with comprehensive cyber bills of materials (CycloneDX 1.6+), the framework formulated by J. McKenney and Eigenia establishes the world's first mathematically defensible, physics-grounded cyber underwriting architecture.
Deriving Single Loss Expectancy () from non-linear physical damage kernels, computing Annualized Rate of Occurrence () across five BOM security dimensions, and modeling systemic accumulation via the Clayton copula transforms cyber risk from an unquantifiable balance-sheet threat into a predictable, capital-efficient engineering discipline. Industrial operators and hyperscale facility owners obtain the empirical clarity needed to fund hardware roots of trust, optimize captive reserves, and secure bulletproof parametric reinsurance treaties in an era of escalating geopolitical volatility.
9. References#
The method applies the ISO 15926 series, DEXPI 2.0, CycloneDX 1.6+, IEC 62443-3-2, and Lloyd's Market Bulletin Y5381.