Cyber Insurance: Emerging Risks and Pricing
The actuarial challenges of pricing cyber insurance in a rapidly evolving risk landscape.
The Cyber Risk Landscape
Cyber insurance covers losses arising from data breaches, ransomware attacks, business interruption due to system failures, and liability from privacy violations. The market has grown rapidly, but actuaries face fundamental challenges in pricing these risks. The threat landscape evolves constantly as attackers develop new techniques and exploit new vulnerabilities. Historical loss data is limited and may not reflect future risk. Accumulation risk (a single vulnerability or attack affecting many policyholders simultaneously) is poorly understood and potentially enormous, as demonstrated by events like the SolarWinds breach and WannaCry ransomware.
Pricing Approaches
Actuaries pricing cyber insurance use a combination of traditional actuarial methods and cybersecurity expertise. Exposure rating based on company characteristics (industry, size, security posture, data holdings) supplements limited experience rating. Cyber risk models from vendors attempt to simulate attack scenarios and estimate aggregate losses. Key pricing variables include revenue, industry sector, number of records held, security controls in place, and prior breach history. The rapidly evolving nature of cyber risk requires frequent assumption updates, and policies often include strict sub-limits for specific coverages (ransomware, business interruption) to manage the insurer's exposure.