07

Solvency II Tested by Cyber Risk

Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.

Solvency IICyber RiskSCREIOPADORAJuly 24, 2026
1 in 200
The reference event for the Solvency Capital Requirement, a loss with a 0.5 % probability over one year
30 %
Cap on the operational risk capital charge in the standard formula, the only explicit home for cyber risk borne by the insurer
$15.3bn
Global cyber insurance premiums in 2024, less than 1 % of the property and casualty market (Munich Re)
$20 to 46bn
Modelled cyber accumulation potential for the industry at a 1-in-200-year horizon, above annual premiums (Munich Re)

I.A Probabilistic Architecture and Its Postulates

Three pillars and one central measure

In force since 2016, the Solvency II prudential framework is the cornerstone of the regulation of European insurers and reinsurers. Its architecture is organised around three complementary pillars. The first sets the quantitative requirements for capital and reserving. The second governs corporate governance, risk management and the internal assessment of solvency. The third imposes transparency through a detailed regime of prudential reporting and market disclosure. This tripartite structure is not decorative, it distributes the treatment of each risk across a capital dimension, a governance dimension and an information dimension, and cyber risk, as we shall see, is handled very unevenly depending on the pillar considered.

At the heart of the first pillar lies the Solvency Capital Requirement, known by its acronym SCR. Its definition is strikingly demanding, it corresponds to the amount of own funds needed to absorb a loss with an occurrence probability of 0.5 % over a one-year horizon, that is, a loss expected on average only once every two hundred years. This value-at-risk at the 99.5 % level, the so-called one-in-two-hundred-year event, is the keystone of the entire edifice. The insurer calculates it either through a standard formula provided by the regulator, or through its own internal model, approved by the supervisor and generally reserved for large groups with the necessary actuarial resources.

The modular mechanics of the standard formula

The standard formula proceeds by breaking risk down into modules, market, counterparty default, life, health and non-life underwriting, to which operational risk is added. Each module is the subject of a capital calculation, and the modules are then aggregated not by simple addition but by means of correlation matrices. This aggregation procedure is the conceptual core of the formula, and its founding assumption deserves to be made explicit, the various risks do not all materialise simultaneously, so that the total required capital is lower than the sum of the modular charges. This is the diversification benefit, which rewards an insurer whose exposures are decorrelated. The entire robustness of the formula therefore rests on the stability and moderation of these correlations.

This construction presupposes two things that classical actuarial science takes for granted. First, that the risks be sufficiently independent that a shock will not mechanically trigger several others in cascade. Second, that one has a loss history deep and stationary enough to credibly calibrate a distribution tail as remote as the one-in-two-hundred-year percentile. Cyber risk, by its very nature, contradicts both of these premises, and it is precisely this twofold contradiction that makes it the revealer of the limits of the edifice.

II.Cyber, a Risk with Two Faces

The risk the insurer bears

Before being a product it sells, cyber is first a risk the insurer bears in its own operations. An insurance company is a heavily digitalised enterprise, whose systems for policy administration, pricing, claims settlement and the storage of personal data constitute so many attack surfaces. An intrusion, a ransomware attack or a cloud infrastructure outage can paralyse its activity, compromise policyholder data and engage its liability. In the prudential taxonomy, this risk falls under operational risk, that is, the risk of losses resulting from a failure of procedures, people, systems or external events.

The risk the insurer sells

Cyber is then a risk the insurer knowingly transfers onto its balance sheet by marketing cyber insurance policies, whether explicit coverage, known as affirmative, or implicit guarantees lodged in traditional contracts, the silent cyber discussed in an earlier article in this series. This cyber underwriting risk has grown rapidly. Munich Re estimated the global cyber insurance market at 15.3 billion dollars in premiums in 2024, less than 1 % of the property and casualty market, and anticipated a doubling by 2030 at an annual rate above 10 %1. Geographic concentration remains strong, with North America accounting for about 69 % of premiums and Europe for 21 %1. The prudential question is then how Solvency II captures these two faces of cyber, the one the insurer bears and the one it sells.

TWO FRONTS, ONE COMMON ORIGIN
A single cyber event can strike the insurer on both its faces at once. A major outage at a cloud provider interrupts the insurer's own operations, triggering its operational risk, while simultaneously generating a wave of claims under the cyber policies it has underwritten, triggering its underwriting risk. This concurrence, unthinkable for a natural peril, is the signature of cyber risk and the source of its elusiveness for an architecture that treats these two risks in separate modules.

III.The Blind Spots of the Standard Formula

An operational risk treated as a flat charge

The treatment of the cyber risk borne by the insurer illustrates the crudeness of the operational risk module of the standard formula. This capital is calculated on a flat-rate basis, by applying factors to bases such as earned premiums and technical provisions, with no sensitivity whatsoever to the actual quality of the entity's cybersecurity. A company with state-of-the-art protection and a negligent company are charged the same amount, provided their volumes are comparable. More constraining still, this operational capital is capped at 30 % of the basic Solvency Capital Requirement2. Operational risk, and therefore the cyber risk it harbours, can thus never represent more than a conventional fraction of the total requirement, regardless of actual exposure. The implicit message of the formula is clear, operational risk is conceived as a second-order risk, an assumption increasingly hard to defend in the age of systemic cyberattacks.

An underwriting risk without a dedicated module

The cyber risk sold by the insurer suffers from a symmetrical blind spot. The standard formula contains no specifically cyber underwriting module. The exposure is diluted within the non-life underwriting module, inside premium and reserve risk, calibrated on generic sectoral factors, and the non-life catastrophe module, which details sub-modules for natural catastrophes and for certain man-made catastrophes such as fire or marine risks, provides for no cyber catastrophe scenario. Yet it is precisely the catastrophic dimension, that is, the accumulation of a large number of claims triggered by a single event, that constitutes the central danger of cyber insurance. The standard formula therefore measures cyber risk with instruments designed for risks of a radically different nature.

THE ONE-IN-TWO-HUNDRED COINCIDENCE
Munich Re estimates the industry's cyber accumulation potential, at a return horizon of up to two hundred years, at between 20 and 46 billion dollars. Yet the two-hundred-year return horizon is exactly the one that defines the Solvency Capital Requirement. The extreme scenario that Solvency II requires insurers to provision for therefore corresponds, in the case of cyber, to a potential loss that exceeds the total annual premiums of the market, estimated at 15.3 billion dollars. Provisioning for such a loss assumes the ability to estimate it, which the youth and instability of cyber data render extraordinarily uncertain1.

The silent residue

To these two blind spots is added the persistence of silent cyber, that is, non-affirmative cyber exposures lodged in traditional policies. The contractual clarification imposed by the London market's LMA 21-042 directive, analysed in an earlier article, has no binding regulatory equivalent on the continent, where EIOPA confined itself in 2022 to recommendations on the management of non-affirmative cyber and its exclusions3. A residual cyber exposure, poorly tracked and therefore poorly capitalised, thus remains scattered across European property portfolios, escaping by construction any dedicated prudential measure.

IV.Accumulation, the Breaking Point of Modularity

When correlation ceases to be a stable parameter

The deepest flaw is not the absence of this or that module, it is the unsuitability of the modular logic itself to cyber risk. The standard formula assumes moderate and stable correlations between risks. Cyber frontally violates this assumption, because a single systemic event can simultaneously trigger correlated losses across an entire underwriting portfolio, across the operational functioning of the insurer, and even across its financial assets if the event disrupts markets. Examples are not lacking. The NotPetya attack of 2017 and the CrowdStrike incident of 2024, both examined in this series, showed that a single technical cause could strike tens of thousands of organisations within a few hours, shattering the independence of claims on which mutualisation rests.

This tail correlation, that is, the fact that risks become strongly dependent precisely in extreme scenarios, is the Achilles' heel of any aggregation-based approach. The correlation matrices of the standard formula are calibrated on average conditions and structurally underestimate the dependence that manifests itself in catastrophe. The diversification benefit the formula grants then becomes an accounting illusion, because the assumed diversification disappears at the very moment the insurer would need it most. A major cyber event turns an apparently diversified portfolio into a single concentrated exposure.

Internal models, a partial answer

Large cyber insurers rely on internal models, which in principle allow a finer representation of accumulation, through the simulation of systemic scenarios and the explicit modelling of dependencies. This path nonetheless runs into an irreducible difficulty, the scarcity and instability of data. Where fire or motor risk draws on decades of stationary history, cyber risk evolves faster than data accumulates, as the attack surface, offensive techniques and dependence on the same critical providers transform from one year to the next. The internal model therefore shifts the problem without solving it, substituting for the absence of a module a dependence on proprietary models whose calibration rests on fragile assumptions that are difficult for the supervisor to verify.

The treatment of cyber by prudential building block
Operational risk, standard formulaFlat-rate and capped · not risk-sensitive
Underwriting, catastrophe moduleNo dedicated cyber scenario
Internal modelFiner · limited by data
Prudential reporting, template S.14.03New granularity on underwriting
Governance and ORSA, Pillar 2Forward-looking scenarios integrated
Operational resilience, DORADedicated framework since 2025

V.The Regulatory Response, Seeing Before Pricing

Making the risk visible

Faced with a risk it cannot yet capitalise correctly, the European authority has adopted a sequential strategy whose logic deserves to be commended, beginning by making the risk visible before claiming to price it. The Solvency II review thus introduced a specific prudential reporting template, template S.14.03 on cyber underwriting risk, which requires the non-life insurers concerned to report their cyber exposure in a granular manner, by product group4. This template falls under the third pillar, that of transparency, and not the first, that of capital. It creates no additional charge, but it provides the supervisor with a map of the market's affirmative cyber exposure, an indispensable precondition for any future calibration.

Testing the risk through scenarios

EIOPA has in parallel developed a stress-testing methodology specific to cyber, published in 2023, which defines underwriting scenarios such as a widespread cloud outage, a wave of ransomware or a prolonged power cut, to be applied at the granular level of products and policyholders5. Cyber underwriting risk is there defined as the insurer's capacity to absorb, from a solvency standpoint, the financial impact of a cyber loss. This scenario-based approach circumvents the impossibility of calibrating a complete distribution by testing the resilience of the balance sheet to shocks defined a priori, a more modest approach but one better suited to a risk whose distribution tail escapes classical statistical estimation.

Governing what one cannot price

The second pillar completes this apparatus by shifting the burden toward governance. The Own Risk and Solvency Assessment, the ORSA, requires each insurer to conduct a forward-looking analysis of its own risks, in which cyber must now feature through scenarios suited to its profile. In February 2026, EIOPA revised its Guidelines on the supervisory review process to explicitly incorporate IT and cyber risks, calling on national supervisors to place them at the heart of their examination6. Where the first pillar struggles to set a figure, the second organises a qualitative and continuous vigilance, an implicit acknowledgement that cyber is better governed than capitalised.

THE DORA RELAY
The operational resilience dimension, long deficient within Solvency II, has been taken up by a separate text, the Digital Operational Resilience Act, or DORA, applicable to financial entities including insurers since 17 January 2025. DORA imposes structured ICT risk management, the reporting of major incidents, resilience testing, and a framework for the risk associated with critical ICT providers. The cyber risk borne by the insurer is thus addressed by a dedicated framework, where the standard formula made do with a capped flat charge, while the cyber risk it sells remains the least developed workstream.

VI.Toward a Cyber-Native Prudence?

The timeline of the review

The revised directive of 4 December 2024, which amends Solvency II, will enter into application on 30 January 2027, accompanied by a delegated regulation adopted in October 20257. This review strengthens proportionality, integrates requirements relating to climate risk and reinforces macroprudential tools, but it creates no cyber capital module within the standard formula. The regulator's deliberate choice is to advance through transparency and governance rather than through a capital charge whose calibration would, given the current state of data, be largely arbitrary. This caution is consistent with a risk whose distribution is not yet estimable, but it leaves a gap between the sophistication of the exposure and the crudeness of its translation into capital.

The conditions for a genuine treatment

A cyber-native prudential treatment would require lifting several locks. It would first need pooled sectoral data, rich and homogeneous enough to calibrate credible accumulation scenarios, something to which S.14.03 reporting is beginning to contribute. It would then need models capable of explicitly representing the tail correlation between underwriting, operations and assets, where the modular formula dissolves it. It would finally need to settle a question of substance, whether a share of cyber accumulation risk, like a share of the climate risk discussed earlier in this series, falls within a capacity that the market alone can bear, or whether it calls for a market-wide mechanism or a public backstop, along the lines of the arrangements envisaged for extreme natural catastrophes.

The trajectory of Solvency II in the face of cyber illustrates a more general truth about financial regulation, a prudential framework can capitalise only what it can measure, and it can measure only what it has a history of. Cyber risk, because it is young, shifting and systemic, lays this limit bare. The European response, made of greater transparency, stress tests and reinforced governance, is not an admission of impotence but the expression of methodological caution, refusing to quantify a distribution tail it does not master, and building first the conditions for its future measurability. The real question of the coming years will not be whether cyber will eventually enter the standard formula, but whether the industry and the supervisor will manage to accumulate, quickly and collectively enough, the knowledge that will make this integration something other than an exercise in calibrated arbitrariness.

2016 Solvency II enters into application, with no provision specific to cyber risk, neither in capital nor in reporting.
2019 The UK PRA insurance stress test incorporates a cyber underwriting scenario including non-affirmative losses.
2022 EIOPA publishes its recommendations on the management of non-affirmative cyber and its exclusions, without binding force.
2023 EIOPA publishes its cyber stress-testing methodology, with cloud outage, ransomware and power cut scenarios.
17 January 2025 DORA enters into application, finally giving the digital operational resilience of insurers a dedicated framework.
February 2026 EIOPA revises its supervisory review process guidelines to explicitly include IT and cyber risks.
30 January 2027 Application of the revised directive and of the S.14.03 reporting template on cyber underwriting risk, with no dedicated capital module.
SOURCES AND REFERENCES
  1. Munich Re, Cyber Insurance: Risks and Trends 2025, April 2025; global premiums of $15.3bn in 2024 and $16.3bn expected in 2025, North America and Europe breakdown, modelled accumulation potential of $20 to 46bn at a two-hundred-year return horizon.
  2. Commission Delegated Regulation (EU) 2015/35 supplementing the Solvency II Directive, provisions on the calculation of the operational risk capital charge and its cap at 30 % of the basic Solvency Capital Requirement; see also The Standard Formula, A Guide to Solvency II, Capital Requirements chapter, Skadden, 2024.
  3. EIOPA, supervisory statements on the management of non-affirmative cyber underwriting risk and the use of exclusions, 2022.
  4. EIOPA, prudential reporting template S.14.03, Cyber underwriting risk, proposed as part of the 2020 review of Solvency II; granular reporting of cyber exposure by product group.
  5. EIOPA, Methodological Principles of Insurance Stress Testing, Cyber Component, July 2023; definition of cyber underwriting risk and cloud outage, ransomware and power cut scenarios.
  6. EIOPA, revised Guidelines on the supervisory review process, 13 February 2026; explicit integration of IT and cyber risks into Pillar 2.
  7. Directive (EU) 2025/2 of 27 November 2024 amending the Solvency II Directive, application on 30 January 2027; Commission Delegated Regulation (EU) 2026/269 of 29 October 2025 aligning the level 2 measures.
  8. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, known as DORA, applicable to financial entities including insurers since 17 January 2025.
  9. IAIS, Cyber Risk Underwriting: Identified Challenges and Supervisory Considerations for Sustainable Market Development, 2020.
  10. Bank of England, Prudential Regulation Authority, 2019 General Insurance Stress Test, cyber underwriting scenario and non-affirmative losses.
  11. EIOPA, Understanding Cyber Insurance, a Structured Dialogue with Insurance Companies, 2018; and EIOPA strategy on cyber underwriting.
  12. ACPR Banque de France, Cyber Risk in the Insurance Sector, Analyses et Synthèses no. 130, 2021.
Related articles
05

Ransomware as a Financial Asset

Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.

CyberRansomware
Read →
03

Silent Cyber: from Grey Zone to Explicit Clause

Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties

Silent CyberLloyd's
Read →
06

ILS and Catastrophe Bonds

The Insurance-Linked Securities market represents a quiet revolution in global finance: for the first time, catastrophe risk migrates off insurer balance sheets into the portfolios of pension funds and institutional investors.

ILSCatastrophe bonds
Read →
Editorials you might enjoy
HS02

Why your insurer no longer wants your house

One morning, a letter tells you your home will not be reinsured. You have done nothing wrong, your house has not changed. What has changed is that chance, the thing all insurance rests on, has quietly left your postcode.

Climate RiskInsurability
Read →