Skip to main content
Dark data centre corridor lined with server racks lit in teal and indigo

Risk research

Pricing the outage: how we model systemic cyber aggregation

A single cloud region failure can touch thousands of policies at once. We break down the dependency mapping behind our cyber accumulation view, and why we cap systemic exposure at portfolio rather than treaty level.

14 July 2026 / 11 min read

Analytics team - Global RE Risk Science

Dark data centre corridor lined with server racks lit in teal and indigo

Why aggregation is the first question

Cyber severity is rarely driven by one insured. The larger concern is a shared dependency that can create losses across hundreds or thousands of policies at the same time.

Global RE reviews cloud regions, managed service providers, payment infrastructure, and identity platforms as accumulation points before considering price or line size.

How the exposure view is built

The analysis starts with declared technology dependencies and is then cross-checked against industry concentration assumptions. Where data is thin, the exposure is stress-tested rather than treated as diversified by default.

Scenario work considers outage duration, contractual notification duties, business interruption waiting periods, liability triggers, and whether one event can activate more than one coverage part.

What changes the underwriting answer

Strong segmentation, named supplier limits, precise event definitions, and transparent cedant controls can all improve the underwriting view. Broad dependent-business-interruption language without dependency data usually has the opposite effect.

The result is an appetite decision that reflects probable accumulation, not only the expected loss on an individual account.