Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A cyber insurer wants to price from its loss experience of the past three years, analyzed by attacker group. What makes that exercise misleading?
Brands dissolve and reform under other names after law enforcement operations, so the series does not track a stable population
Ransomware as a service is a division of labor modeled on the software economy: operators build and maintain the ransomware, its payment infrastructure and its leak site, affiliates handle intrusion and deployment, and the ransom is split on a negotiated key, often 70 to 80 percent to the affiliate. The technical barrier falls, since running a campaign no longer requires knowing how to code. For the insurer this model explains the industrialization of attacks and the growing correlation of claims when one strain hits several insureds. But the ecosystem is volatile: after a law enforcement operation the brand disappears and the same actors return under another name. LockBit ran for years this way, until its partial dismantling by Operation Cronos in 2024. A series indexed on brands therefore measures labels, not populations.
Glossary entry · raas2. Administrator access to a company is put up for sale on an underground forum, then used by a ransomware affiliate several weeks later. What contractual difficulty does that create?
Dating the triggering event, since the initial compromise precedes the declared claim by several weeks
The initial access broker does one thing only: obtain access to corporate networks, then resell it on underground forums, notably to ransomware affiliates. What is sold takes the form of valid credentials, remote desktop access, an exploitable vulnerability or an already-open session. Intrusion and monetization have become two separate trades. For underwriting this shifts part of the analysis toward authentication hygiene, exposure of remote services, and patching speed. And it creates a difficulty the contract must settle: an access can be resold months before it is used, so the compromise and the declared claim sometimes fall on either side of a change of insurer.
Glossary entry · iab3. Since the market hardened around 2021, the absence of multi-factor authentication on remote access frequently leads to a declination or to degraded terms. What does the insurer gain from that requirement, beyond a reduction in risk?
A signal about the insured's security maturity, which mitigates adverse selection
Multi-factor authentication requires at least two proofs of identity of different natures, so that a stolen password is no longer enough to open the account. It is among the most effective measures against credential theft, that is, against exactly what the initial access market sells. But the requirement does a second job: deploying it across all sensitive access, mail, remote access, administrator accounts, presupposes an organization that knows its own estate. It therefore sorts submissions as much as it reduces risk, and that sorting function is what mitigates adverse selection. A file declined on this point often comes back accepted on markedly better terms once the rollout is done.
Glossary entry · authentification-multifacteur4. Big game hunting ransoms are calibrated on the victim's public financial analysis, often between 0.5 and 3 percent of annual revenue. What consequence does a cyber insurer draw for its book?
The heaviest claims concentrate on the insureds carrying the broadest cover
Big game hunting is the deliberate shift to targeting large organizations able to pay several million, against the mass campaigns that aimed at hundreds of thousands of modest targets for a few hundred or thousand dollars. It was made possible by the maturing of the as-a-service model, by access brokers supplying qualified targets, and by the professionalization of negotiation units. For the insurer this bifurcation creates an adverse correlation: the costliest claims land on the insureds who carry precisely the broadest cover. The widening gap between mean and median payment is the statistical signature of that concentration, which is why a mean on its own says nothing useful about a book.
Glossary entry · big-game-hunting5. WannaCry spread from 12 May 2017 by exploiting a vulnerability for which Microsoft had published the MS17-010 patch in March 2017. What does an underwriter take from that two-month gap?
That the variable separating hit insureds from the rest is patching delay, and that it is observable before the loss
WannaCry was a worm-type ransomware: unlike classic ransomware requiring a human action, it moved machine to machine unaided, across networks that had not applied the patch published two months earlier. Within hours more than 200,000 systems in 150 countries were hit, including the British NHS, Spanish telecoms and car plants in France and Romania, for worldwide economic damage estimated above four billion dollars. For models it is the canonical self-propagating attack: correlation of claims is near perfect across vulnerable networks, which makes pooling inoperative, and the scenario remains a reference in cyber probable maximum loss models. What separated the hit from the rest was not luck but a patching cadence, and that is measurable at underwriting.
Glossary entry · wannacry6. In February 2024, the compromise of Change Healthcare disrupted around 94 percent of American care providers and affected some 192.7 million people. A cyber insurer had nonetheless selected its insured hospitals one by one. What does that event defeat?
Diversification, since a shared link no insured controls produces a correlated loss
Change Healthcare is a health payments processing platform used by nearly every American establishment. Its compromise in February 2024 was the largest cyberattack in the history of American medicine: around 192.7 million people affected, close to two thirds of the population, and some 94 percent of care providers disrupted. It is the emblematic case of accumulation through a supplier: a single upstream compromise strikes thousands of insureds resting on the same infrastructure at once. Careful selection of each hospital changes nothing, because the dependency being underwritten appeared in no individual file. This is therefore not an underwriting failure but a limit of diversification, and the two are not corrected the same way.
Glossary entry · change-healthcare7. A cloud outage lasts between fifteen and sixteen hours, against a time deductible of eight to twelve hours depending on the contract. Insured loss estimates for that single event run from 38 to 581 million dollars. What does that factor of fifteen measure?
The loss's sensitivity to the deductible threshold, since the density of outage durations concentrates exactly around it
A time deductible is a deductible expressed in duration, below which an interruption gives rise to no payment. It is usually set between eight and twelve hours by market convention, with no actuarial study of the distribution of outage durations. Yet that distribution is dense between a few hours and a day, which is exactly where the threshold sits: moving it by four hours does not change the loss by 20 percent, it changes it by an order of magnitude. The insured loss from a hyperscaler outage is therefore not set by the event, it is set by the clause. The practical consequence is clear: a cyber catastrophe exposure is read in the wordings before it is read in the models.
Glossary entry · franchise-temporelle8. A piece of malware displays a ransom demand while the data has already been destroyed beyond recovery. What is this tool called, and what does the disguise change for the insurer?
A wiper, whose disguise blurs attribution and therefore the application of the war exclusion
A wiper aims at destruction rather than gain: it corrupts files and sometimes systems irreversibly, with no prospect of recovery. Its logic is sabotage, often tied to geopolitical motives, and some pose as ransomware precisely to blur attribution. NotPetya, in 2017, is the emblematic case: under the appearance of ransomware it erased the data of countless companies for billions of dollars in damage. For insurance three difficulties compound: catastrophic scale, the impossibility of recovery which worsens the business interruption, and above all the question of state attribution, which can bring the war exclusion into play and which fed the whole silent cyber debate.
Glossary entry · logiciel-effacement9. A cyber policy carries an LMA clause in its B version, without an attribution clause, and the insurer invokes the state cyber operation exclusion. No official attribution has been published. Who must establish what?
The insurer, which bears the burden of proving attribution under the law applicable to the contract
Attribution is technical, legal and political at once, and it conditions the application of state cyber operation exclusions. Version A clauses (5564A, 5565A, 5566A, 5567A) carry an explicit attribution clause: insured and insurer take into account the objectively reasonable evidence available, including a formal or official attribution by the government of the state where the affected system is located. That wording does not shift the burden of proof, which stays with the insurer, it orients the method of assessment. Version B clauses have none, and attribution must then be proved under the law of the contract. The Hamilton variant adds an independent umpire where disagreement persists. Finally, the absence of official attribution does not mean no state is responsible: Colonial Pipeline in 2021, imputed to the DarkSide group with no state attribution, was handled as ordinary cybercrime, whereas WannaCry was officially attributed to North Korea by the United States and the United Kingdom.
Glossary entry · attribution-etatique