Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. On 10 March 2021, a fire destroyed the SBG2 building at OVHcloud's Strasbourg site and damaged neighbouring buildings. Millions of hosted websites became unreachable. Why is this loss heavier than a warehouse fire of the same floor area?
Because on top of building damage comes the simultaneous interruption of thousands of third-party businesses
A data centre concentrates in one building a conventional industrial peril and an exposure that is anything but. The conventional peril reads easily: a room dense with live electrical equipment, cabling and flammable material in quantity, and awkward firefighting since water destroys electronics while gas struggles to contain a fire already developed. Compartmentation between rooms and buildings then decides the scale, a contained fire producing a partial loss and a spread a total loss of the site. What changes everything is the second layer: the building hosts not merely its owner's business but that of thousands of unrelated clients, in different sectors, all stopping on the same day without suffering any physical damage themselves. The loss is therefore both property damage and multiplied business interruption, and the two sit in neither the same policies nor with the same insureds. This is why analysing such a site never stops at the building's insured value: the useful question is how many businesses stop with it, and for how long.
Glossary entry · incendie-data-center2. After the Strasbourg fire, hosting was rebuilt elsewhere within days. Some clients who had kept no backup outside the destroyed building never recovered their data. What does that force one to distinguish?
Interruption, which time repairs, and data destruction, which it does not
These are two losses of different natures produced by one event, and confusing them leads to mispricing both. An interrupted service is restored: machines come back up elsewhere, the loss is measured in margin not earned during the outage, and it stops when service returns. Data destroyed with no usable copy elsewhere is gone for good, and how quickly service resumes changes nothing. Strasbourg shows this by contrast, since hosting was rebuilt while some clients' data was not. The particular difficulty of this second head is one of valuation first: a physical server is replaced at a price written on an invoice, whereas the value of a customer database, source code or accounting history depends entirely on whether it can be reconstituted, and two firms of the same size can show unrelated figures here. The practical point to watch is the backup held on the production site itself, more common than one imagines in small organisations: it gives the feeling of redundancy where there is only local accumulation, since the same fire takes original and copy alike.
Glossary entry · perte-donnees-permanente3. An operator advertises Uptime Institute Tier IV. The underwriter asks for the certificates and receives only one, for the design. What have they just learned?
That resilience is certified on paper, with no proof of what was built or is operated
The classification ranks sites by their redundancy architecture, from Tier I with none to fault-tolerant Tier IV, whose theoretical annual downtime is measured in minutes. It is a major determinant of business interruption risk, and a properly certified Tier IV carries an incomparably lower probability of outage than a Tier II. The detail that decides, and that one must know to ask for, is that certification comes in three distinct exercises: the design level, the level actually constructed, and the level as operated. An operator can therefore advertise Tier IV in complete good faith while holding only the first, when real resilience rests on the other two. A drawing says nothing about shortcuts taken on site, and a properly constructed site can be run with procedures that cancel its redundancy, for instance by keeping both power chains on one bus during maintenance. The useful underwriting question is thus never which Tier is advertised, but which of the three certificates exist and when they were last renewed.
Glossary entry · classification-tier-uptime4. A site has dual power chains, duplicated cooling and several generators. All of it sits in one building. What does that architecture not protect against?
A peril that reaches the whole building, primary and backup sitting in the same place
Internal redundancy answers one precise question: what happens if a component fails while the others keep running. An N+1 or dual-chain architecture answers it very well, and that is what a high certification measures. It does not answer a different question: what happens if the building itself is compromised. Fire, flood, natural catastrophe or total loss of external power draw no distinction between primary and backup systems when both are co-located, and a site rated highly on availability can therefore suffer a total loss. This is exactly what Strasbourg showed in 2021: conventional internal redundancy was in place and could do nothing against a loss that took the whole building. The distinction is poorly understood outside engineering circles, and it explains why the only answer to this risk is of another order, an architecture spread across several distant sites, which is a matter of service design rather than building equipment. For an insurer, the practical consequence is that a good Tier lowers the frequency of interruptions without lowering the severity of the extreme scenario.
Glossary entry · redondance-intra-site-limites5. In August 2016, a faulty electrical control module prevented the changeover to backup generators at a Delta Air Lines data centre in Atlanta. Thousands of flights were cancelled over several days, at an estimated cost of around 150 million dollars. What makes this peril so hard to assess before it happens?
The backup chain is exercised in real conditions only exceptionally, so a fault can stay latent for years
The backup power arrangement is a chain, and a chain is worth only its weakest link: the UPS carries the load immediately while the generators start, then the generators take over for a longer period. A failure at any link, degraded batteries, a faulty control module, a generator that will not start, a badly synchronised changeover, turns a normally invisible mains outage into a complete stop. What makes this peril insidious is that the chain is exercised in real conditions only rarely: most tests are run unloaded or partially, so a latent fault can stay invisible for years before revealing itself at the worst moment, meaning the one outage that mattered. Delta adds the lesson most useful to an insurer: the 150 million did not come from the faulty module, whose price is negligible, nor even from the length of the power failure, but from the time needed to bring back reservation and crew-rostering systems stopped abruptly. Severity is decided in the recovery, not in the outage, and it is the realism of testing that moves the frequency.
Glossary entry · defaillance-onduleur-generateur6. In July 2022, a record heatwave in the United Kingdom exceeded the cooling capacity of Google and Oracle sites near London, which suffered several hours of outage. Once the episode has passed, what is the insurance question about?
The thermal margin adopted at design, judged against up-to-date climate scenarios
A site is sized for a range of outside temperatures, drawn from the local weather history available when it was designed. When an episode passes beyond that range, cooling can no longer remove the heat the equipment produces, and the operator must shed load or shut down servers to avoid destroying them: a climate hazard becomes a service outage, with no component having failed. What interests the insurer therefore lies upstream, in the thermal assumption itself, and the question arises exactly as actuarial non-stationarity does: a site designed to old norms is calibrated on a climate that is no longer the one it meets, and the fault lies not in the equipment but in the reference used to size it. Two identical sites can thus present very different risks depending on when they were designed and on whether the operator has revised its margin since. This is also what separates this peril from a breakdown: it is predictable in principle, forecast days ahead in its occurrence, and yet unavoidable when the margin is missing.
Glossary entry · risque-canicule-data-center7. On 28 February 2017, a mistyped command during a maintenance operation stopped Amazon Web Services' S3 storage for around four hours. Thousands of client sites and applications stopped, having suffered no damage of their own. What must one of those clients' policies carry for its loss to be covered?
An extension addressing interruption caused by a third-party supplier's outage
Conventional business interruption cover triggers on physical damage suffered by the insured, and that is exactly what is missing here: the client suffered nothing, its hardware works, its premises are intact, and yet its business stops because infrastructure it depends on stopped elsewhere. The supplier interruption extension answers this situation, now structural given that most firms no longer host their own infrastructure and depend on a small number of providers for critical applications. For the insurer the clause moves the analysis from the insured's physical site to its supplier's, and to the precise technical architecture it relies on, which the end client often does not know itself, starting with the hosting region and whether its application fails over automatically. The 2017 event is instructive on one last point: the cause was a mistyped command during maintenance, neither malicious nor physical, a reminder that a clause describing an attack trigger would not bite here, and that the word cyber in a heading says nothing about what is actually covered.
Glossary entry · clause-interruption-fournisseur-cloud8. Loudoun County in Northern Virginia holds one of the highest densities of data centres in the world, and a very large share of global internet traffic passes through it. The operators there are competitors with no shared ownership. What does that produce for an insurer?
An accumulation no operator measures, since it exists only at sector level
Clustering is rational for each operator taken alone: you settle where power is available and cheap, where tax is favourable, where fibre is already laid and where other digital infrastructure already sits. Each of those decisions is defensible, and their sum produces at sector level an accumulation nobody decided and no player measures, since it appears on none of their balance sheets. A local event, a regional grid failure, a natural catastrophe, saturation of grid connection capacity, can then strike simultaneously a significant share of the world's digital infrastructure, hosted by operators who are nonetheless competitors. It is the same mechanism as tail correlation in actuarial work: risks independent in normal conditions, because nothing links these firms, and joined at the extreme because they share a dependency nobody had written down. For underwriting, the practical consequence is that a book can look diversified by operator, by client sector and by contract while being concentrated on a map, and the only way to see it is to ask where the sites physically are.
Glossary entry · concentration-geographique-data-center9. A data centre dedicated to training artificial intelligence models shows unprecedented rack densities, recently designed liquid cooling and graphics processor clusters whose supply is tight. Why does its insurability deteriorate relative to a traditional centre?
Because several risk determinants deteriorate at once, among them the time to reinstate
A data centre's insurability is not a global judgement but the aggregate of several determinants that can be named one by one: the level of redundancy, rack density, the cooling technology and its own perils, dependence on the grid and the autonomy available, the site's physical climate exposure, the concentration of value, and the replacement time for critical equipment. What makes the artificial intelligence training case particular is that these determinants do not move one at a time but together, and all in the same direction. Densities reach unprecedented levels, concentrating value and heat in the same place. Liquid cooling, still thinly documented by loss experience, adds a leakage peril at the very heart of the racks. The unit value of the clusters rises sharply. And supply tensions lengthen the time to reinstate, which mechanically lengthens the indemnifiable interruption. That last point is often the heaviest and the least seen: the severity of an industrial loss is measured as much in weeks waiting for a part as in physical damage, and it is what makes the insurability of these sites an underwriting subject in its own right.
Glossary entry · assurabilite-data-center