Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. In 2008, Milly and co-authors published in Science that stationarity is dead for hydrology: a flood model calibrated on 1950 to 2020 underestimates the 2021 to 2025 loss experience by forty per cent. An actuary wants to price cyber on five years of history. What does that precedent hold against them?
That history describes a threat only if it has stayed the same, which cyber has not
All actuarial pricing rests on an assumption rarely stated because it goes without saying elsewhere: the distribution that produced past losses is the one that will produce future losses. It holds for factory fire, whose physical causes do not change from one decade to the next. It stopped holding for hydrology, and the 2008 finding is exactly that: it is not that data are missing, it is that the data available describe a climate that no longer exists. Cyber shows the same break, faster, because the threat is adversarial: attack techniques, the vulnerabilities exploited and network topology transform within quarters, and an attacker changes method precisely when the defence adapts, which no flood does. This is why lengthening the history repairs nothing and even worsens matters, since one adds years that are less and less representative. Choosing a fat-tailed distribution is useful for other reasons, but it bears on the shape of the distribution, not on its drift: a badly calibrated law stays badly calibrated. The point to hold on to is that this is a limit of the method itself, not an execution fault a more careful actuary would fix.
Glossary entry · non-stationnarite-actuarielle2. A company has had a single cyber loss in five years. The actuary refuses to price on that experience alone and weights it against the average loss experience of its sector. What exactly are they doing, and what does the move not solve?
Giving experience a weight that grows with its volume, without making the reference any more stable
Credibility formalises a trade-off common sense already poses: one loss in five years says almost nothing about the specific risk, and pricing on it would treat a single draw as a trend. Individual experience is therefore given a weight between zero and one, growing with the volume and stability of the data, with the remainder placed on a broader reference. Pricing is thus a weighted average, avoiding both over-reaction to an isolated loss and blindness to a real specificity. This framework, formalised notably by Bühlmann, is sound and worth handling well. But its assumption must also be seen, and that is where cyber strains it: the collective reference is supposed to be more reliable than individual experience, because it rests on more observations. That assumption is reasonable in motor, where a segment average is stable from year to year. It is far less so in cyber, where the sector average itself moves from one year to the next under non-stationarity. Credibility repairs a shortage of individual data; it does not repair a reference that is drifting, and the two difficulties compound.
Glossary entry · theorie-credibilite3. A portfolio of a thousand SMEs spans different sectors and countries, and the correlation of their losses in normal conditions is low. Eight hundred of them use the same security tool, the one whose 19 July 2024 update took 8.5 million systems offline. What does the measured correlation fail to say?
That a dependence of zero in normal conditions can become close to one in the tail
Two risks can be nearly independent day to day and perfectly joined at the extreme, which is exactly the case here. In normal conditions these thousand companies have no reason to suffer losses together: they share no customers, no market, no geography, and the measured linear correlation confirms it. On the day of the event, the effective correlation of the eight hundred sharing the tool is close to one, since a single file triggers all their losses at once. The consequence is quantifiable and brutal: capital computed under a moderate correlation assumption is massively insufficient, the more so because the portfolio looked diversified. This is also the criticism aimed at Gaussian copulas, which assume zero tail dependence and which the Solvency II standard formula uses, where Student or Archimedean copulas capture a positive one; the 2008 crisis had already shown what the convenient assumption costs. What a professional should retain is a reflex rather than a formula: a dependence measured in the ordinary regime says nothing about the regime that decides solvency, and the only way to correct it is to hunt shared dependencies one by one, among common suppliers.
Glossary entry · correlation-de-queue4. Two cyber portfolios show the same expected loss cost. The first is made of funds transfer frauds, numerous and individually modest; the second of industrial ransomware, rare and very costly. What does the frequency and severity decomposition give that expected cost alone does not?
The dispersion around the mean, and therefore the capital each portfolio ties up
Frequency times severity gives the expected loss cost, the core of the pure premium; but two portfolios with the same mean bear no resemblance to each other as soon as one looks around that mean. A portfolio of many small losses is close to the textbook case of the law of large numbers: the annual result departs little from its expectation, and what the insurer sells there resembles a claims-handling service. A portfolio of rare, heavy losses has the same mean and an incomparable dispersion: several years with nothing, then one year that carries off several years of profit. What the decomposition illuminates is therefore the nature of the risk rather than its average price, and that is what decides tied-up capital, the volatility of the result and the place of reinsurance in the structure. It also illuminates the levers: frequency is acted on through prevention and hygiene, severity through business continuity and the ability to restart. Cyber has the peculiarity of combining both profiles in one portfolio, which makes reading them separately all the more necessary. Modelling reflects this, with distinct laws for each component, a counting law for frequency and a fat-tailed law for severity.
Glossary entry · frequence-severite5. A reinsurer runs its property book against European windstorm: the catastrophe model returns an average annual loss of 180 million euros and a two-hundred-year probable maximum loss of 1.4 billion. The same is wanted for cyber. Which of the four modules poses the heaviest difficulty?
Hazard, for want of an event catalogue that physics would allow one to simulate
A catastrophe model exists precisely because loss history is too thin to price a rare peril, and it does without by simulating. Its strength lies in the hazard module: thousands of plausible storms can be generated because the atmosphere obeys stable physical laws, observed for a century, that hold no intentions. The other three modules transpose to cyber with no obstacle of principle. Exposure can be collected, it is simply of another nature, systems and dependencies rather than buildings and square metres. Vulnerability can be estimated, with cruder functions of the same kind. The financial module applies as it stands, cyber policies carrying deductibles, limits and sub-limits like any other. The difficulty is therefore concentrated in hazard, and it is fundamental: there is no physics of the attacker, their frequency is not a fact of nature but the result of an adversarial decision, and a catalogue of cyber events ages as techniques change. This is why market cyber models rest on constructed scenarios, the outage of a major host, the vulnerability of a widely deployed library, rather than on a generated catalogue: a simulation that cannot be done is replaced by assumptions that can at least be argued over.
Glossary entry · modele-catastrophe6. Cyber is described as non-stationary. What does that property rule out in ordinary actuarial work?
Assuming a distribution fitted on the past stays valid tomorrow
A fundamental difficulty in cyber is the shortage of homogeneous historical data, and it has two faces worth separating. The first is volume: cyber is a recent risk and the history is short. The second is deeper and is non-stationarity: loss experience moves with attackers' offensive capability, so yesterday's data does not describe the same phenomenon as tomorrow's. In fire or life, a distribution is fitted on the past and projected, because the underlying physical or biological mechanism does not change. In cyber the adversary adapts, tools spread, criminal business models recombine, and a distribution fitted on three years ages while it is being used. Computing an average remains possible, and working from scenarios is precisely one of the answers; what becomes illegitimate is the projection assumption, which is exactly what classical actuarial work takes for granted.
Glossary entry · quantification-risque-cyber