Cyber Risk: Models Still in the Draft Stage
A surge in attacks, the complexity of their impacts, and a scarcity of reliable data… Cyber risk remains a headache for insurers. Faced with the scale of potential claims, the industry is seeking to refine its models, which are still largely immature.
A systemic and evolving risk
Cyber risk is no longer a minor issue: it has become systemic. Ransomware attacks, data theft, and malicious IT outages affect companies of all sizes and across all sectors. In 2023, the average cost of a cyberattack exceeded $4.5 million worldwide (source: IBM), and some major claims now exceed individual underwriting capacities.
Problem: Actuarial modeling of cyber risk remains incomplete. Unlike natural disasters or the auto industry, historical data is scarce, scenarios are difficult to replicate, and the nature of attacks is constantly evolving. How can one model a risk that changes every six months, often obscured by the confidentiality of the victims?
Data collection remains too fragmented
The main challenge is accessing reliable and usable data. Many companies that fall victim to attacks do not report them (or report them only partially), which prevents the creation of robust statistical databases. Insurers must therefore work with incomplete, heterogeneous, and even biased datasets.
Some initiatives are emerging, such as the Cyber Risk Observatory led by the France Assureurs Federation or joint efforts by specialized stakeholders (Cybermalveillance.gouv.fr, ANSSI, CNIL, cybersecurity startups, etc.). But information sharing remains limited, particularly due to concerns about reputation or trade secrets.
New Tools for Dynamic Scenarios
To better model risk, insurers are exploring new approaches that combine data science, mapping of interconnections between companies, and systemic scenarios. The goal is to build “what-if” models capable of anticipating domino effects (e.g., an attack on a SaaS provider affecting thousands of customers).
The challenge is to feed these models with vulnerability indicators, such as internal cybersecurity practices, the frequency of software updates, or exposure to third parties. Companies like Moody’s, Kovrr, and Munich Re are developing risk scores or simulators based on AI and behavioral analytics.
But standardization is still lacking. Without a common taxonomy, insurers struggle to compare exposures or aggregate useful data. And on the policyholder side, questionnaires often remain too self-reported to accurately reflect the reality of the risk.
Toward a shared approach to cyber risk?
Faced with this impasse, several experts are advocating for a shared approachto cyber risk, similar to national pools for terrorist or nuclear risks. In France, the idea of a “cyber pool” has been raised by France Assureurs, but remains only at the conceptual stage.
In the meantime, reinsurers play a key role in supporting capacity, but they, too, are calling for greater transparency regarding data and stress scenarios. In the absence of better risk modeling, some players prefer to sharply limit their exposure or even withdraw from the market.
Cyber risk is currently the weak link in the insurance chain: too volatile, too opaque, and too asymmetric. If the industry wants to remain relevant in the face of this major threat, it will have to develop new modeling methods that are more collaborative, more transparent, and more dynamic. Otherwise, cyber risk will remain uninsurable… and uncompensated.



