Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A property policy written in 2015 mentions cyber neither to include nor to exclude it. Ransomware halts the plant. What is this exposure called?
Silent cyber, also called non-affirmative cyber
The exposure is implicit: it was neither priced nor reserved, and the insurer discovers it at claim time. That is the double problem, an unmeasured charge plus accumulation risk, since one event can hit several lines at once.
Glossary entry · silent-cyber2. In the litigation that followed NotPetya, what was the central legal question?
Whether the war exclusion applied to a state-attributed attack
The insurer invoked the war exclusion on the grounds that the attack was state-attributed. The case showed that a clause drafted for conventional armed conflict did not settle the case of malicious code, and pushed the market to rewrite those exclusions for cyber.
Glossary entry · clause-exclusion-guerre3. Why is accumulation a sharper problem in cyber than in fire?
Because a cyber loss is not bounded by geography
Fire insurance relies on geographic dispersion: two buildings a thousand kilometres apart do not burn together. A flaw in software used everywhere ignores that dispersion, which is why CRESTA zones, which cut the world into accumulation areas, have no simple cyber equivalent.
Glossary entry · accumulation-cumul4. A single cloud provider hosts a large share of a portfolio's insureds. What is that dependency called?
A single point of failure
The portfolio looks diversified by sector and size while resting on a single technical dependency. Apparent diversification says nothing about real diversification, and that is what accumulation analysis exists to uncover.
Glossary entry · spof-accumulation-cyber5. From 2019 onward, what did the Lloyd's market require of every policy?
That it state its position on cyber, either including or excluding it
The requirement was not to exclude but to decide. Silence was the problem: it left the exposure invisible on both sides of the contract. A policy that explicitly excludes is measurable; a silent policy is not.
Glossary entry · affirmation-cyber6. What does double extortion mean in a ransomware attack?
Encrypting the data and additionally threatening to publish it
Encryption alone is defeated by a clean backup. By exfiltrating data before encrypting, the attacker keeps leverage even over a victim who restores: a backup protects availability, not confidentiality.
Glossary entry · double-extorsion7. After a ransomware attack, which cost component usually dominates the loss for an industrial company?
Business interruption from the production stoppage
The ransom is the most visible line and rarely the heaviest. The production stoppage runs until systems are rebuilt, and that duration is often counted in weeks. This is why the waiting period and the indemnity period matter more, in a cyber policy, than the headline limit.
Glossary entry · perte-exploitation8. Why do classic actuarial methods fit cyber poorly?
Because the history is short and the risk is not stationary
Classic pricing assumes the past informs the future. In cyber, the adversary adapts, technologies change and so do regulations: non-stationarity is structural. A loss triangle fed by ten years of data describes a world that no longer exists.
Glossary entry · quantification-risque-cyber