Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. In the worked case, the cedant declares a single event and sets the start time at March 3, 02:10, with a one hundred and sixty-eight hour window. The second wave strikes from March 12 to 14. What becomes of that second wave?
It falls outside the window, which closed on March 10 at 02:10, and no placement of the window could have saved both waves
One hundred and sixty-eight hours is seven days, and eleven days separate March 3 from March 14: no placement of the window covers both waves. It is a question of arithmetic, not of characterization, and that is what makes it unanswerable. The unity of the attack, which the most natural intuition invokes, is a fact about the world; the window is a fact about the contract, and the contract decides. Moving the start time to March 12 only picks the other wave, the one costing 9 million instead of the first one's 22. The useful work is therefore not to argue unity, which is lost in advance on the chronology, but to look for whether the second cluster can aggregate with other claims from its own week.
Glossary entry · traite-excedent-sinistres2. Still in the worked case: first event of 22 million, second of 9 million, priority of 10 million, limit of 30 million. What does the cedant retain, and what did it believe it would retain?
It retains 19 million out of 31, having believed it would retain 10: the first event recovers 12, the second never reaches its own priority
The first event cedes 22 million, of which 12 are recovered above the 10 million priority. The second, at 9 million, never reaches its own priority and stays fully retained. Total retained, 10 plus 9, that is 19 million out of 31 ceded. The gap with the expected 10 million is not a pricing surprise, it is the direct consequence of a chronology nobody looked at before notifying. The 20 million answer reasons correctly on the principle, two events pay two priorities, but applies that principle to a second event that does not reach its own: you do not pay a priority, you retain everything falling below it.
Glossary entry · accumulation-cumul3. The case mentions that the vendor was compromised on January 14, six weeks before the encryption. Why is that date the file's real trap?
Because if the wording anchors the event on the cause rather than the manifestation, the window ran from January 14 to 21 and closed six weeks before the first damage
In this case the 31 million would then be retained in full, with no exclusion invoked and no cover refused. That is what makes the flaw so hard to spot: it looks like nothing anyone monitors in a claim file. And the asymmetry is cruel, because reaching back to the cause looks more generous: a window is not an extent, it is a duration that runs, and its starting point does not say how far back you reach, it says when it expires. That sentence is negotiated at placement and never at the claim, where the chronology is already fixed and the wording already signed.
Glossary entry · spof-accumulation-cyber4. The module contrasts two clocks. The waiting period runs on each insured, the aggregation window on the portfolio. What is the practical consequence?
Nothing synchronizes them, and the gap widens on the heaviest files, those with the longest interruption
Both clauses are coherent taken separately, which is why nobody brings them together: the mismatch appears only when they are read side by side. An insured whose interruption begins late in the window sees its waiting period run as the window closes, and the indemnifiable part of its loss can sit entirely outside the ceded event. Long interruptions are the most exposed, which is to say the claims the treaty was bought for. The answer invoking an averaging effect is the most tempting and the most wrong: a mismatch that systematically strikes the heaviest files does not average out, it concentrates.
Glossary entry · delai-carence5. The module notes that a single event saves one priority but consumes only one limit. From what point does splitting into two events return more?
Once the total loss exceeds the priority plus the limit, the unprotected top then costing more than the second priority
As long as the loss stays below the top of the layer, a single event recovers everything above the priority, and splitting would only add a second priority to retain. Above the top, the limit caps recovery and the excess stays fully retained: that excess is what splitting goes after, by dropping it into a second layer with its own limit. The trade-off is therefore priced case by case, and the answer excluding it on principle ignores the cap. There remains what this module does not yet say and the reinstatement module will add: a second event also consumes a second reinstatement, and the right objective is not the recovery on this loss, it is the recovery on the year.
Glossary entry · point-attachement