Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A group describes its group security policy in the questionnaire, and it is true. Why can the cover still bear on a risk that was not described?
Because an answer can be perfectly accurate on a SCOPE that is not the risk's: a recently acquired subsidiary runs on its own servers, its own directory and its own admin accounts, and none of the group policy is yet true there
The previous module dealt with the sincerity of answers; this one deals with what the questionnaire does not ask, and there is no false disclosure to look for here. The answer turning the policy into a set of objectives excuses any inaccuracy in advance and mistakes the subject: that policy is indeed applied, on the group's system. The one limiting the questionnaire to head office invents a documentary architecture. The one contrasting consolidation with the insurance perimeter describes a real administrative lag, which sometimes explains a missing entity, not a description that is off-scope while the entity is listed.
Glossary entry · declaration-de-risque2. IT integration of an acquisition produces a risk maximum at a precise moment. When, and why not at the start?
Between the FIRST INTERCONNECTION and the last harmonization: while the networks are separate, an attacker entering the subsidiary stays there; the day a trust link is opened, a path is created without practices yet aligned
Separation is a protection, and that is what makes the curve counterintuitive: risk rises when integration starts, not when it is announced. The answer on acquisition day puts the maximum where attention goes, and that is precisely when the two networks are not yet talking. The one at the end of the project describes a real loss of knowledge, occurring exactly when practices are at last aligned. The one aiming at the extension of the contract confuses the insurer's exposure with the company's risk: extending cover changes nothing about the paths an attacker can take.
Glossary entry · spof-accumulation-cyber3. Three entities regularly escape insurance charts. What do the joint venture, the foreign branch and the entity being sold have in common?
Nobody quite considers them theirs: yet the joint venture shares access with both shareholders, the foreign branch has its local IT person and its locally signed contract, and the security of the entity being sold is no longer funded by anyone
It is not size or applicable law that makes them vanish, it is a failure of ownership: each belongs to someone else, or is already leaving, or is not quite one's own. The answer on size is false for the joint venture, which can be substantial, and misses the mechanism. The one on foreign law applies to only one of the three and describes a drafting difficulty, not an inventory one. The one on personal data introduces an irrelevant test, the scope of cyber risk not being limited to the data held.
Glossary entry · carence-fournisseur4. Two groups of ten subsidiaries file the same questionnaire and declare the same revenue. What question separates their risks, and what does it measure?
Is there an account, a directory or an administration tool whose compromise would open MORE THAN ONE entity: ten independent systems make ten possible losses each bounded, a single directory makes one possible loss taking them all in a night
It is the LINKS and not the entities that decide the extent, and no market questionnaire asks this, which makes it all the more useful. The three other answers bear on characteristics of entities taken one by one: the nature of the systems, digital dependency, history. All three are genuine underwriting information, and none says whether the maximum loss is one subsidiary or the whole group. It should be added that the answer may be that nobody knows, and that answer is information: it says the extent is not bounded, which is an underwriting fact.
Glossary entry · accumulation-cumul5. The question of links also arises for the insured, on its own account. What does it decide there?
What its business interruption cover must be able to absorb: a group that has measured its links knows what share of its activity can stop AT THE SAME TIME, one that has not sizes on its largest subsidiary and finds it should have sized on their sum
Sizing the program is the decision this measurement governs, and it is the insured's decision, not the underwriter's. The three other answers name insurance architecture choices that genuinely arise and come afterward: the shape of the program, the allocation of premium, a single deductible. Each is argued once you know how much activity can fall together, and none answers that question. The one on a single deductible is nearest the subject, since it touches aggregation, and it handles a calculation consequence when the stake is how much cover to buy.
Glossary entry · perte-exploitation