Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.
In force since 2016, the Solvency II prudential framework is the cornerstone of the regulation of European insurers and reinsurers. Its architecture is organised around three complementary pillars. The first sets the quantitative requirements for capital and reserving. The second governs corporate governance, risk management and the internal assessment of solvency. The third imposes transparency through a detailed regime of prudential reporting and market disclosure. This tripartite structure is not decorative, it distributes the treatment of each risk across a capital dimension, a governance dimension and an information dimension, and cyber risk, as we shall see, is handled very unevenly depending on the pillar considered.
At the heart of the first pillar lies the Solvency Capital Requirement, known by its acronym SCR. Its definition is strikingly demanding, it corresponds to the amount of own funds needed to absorb a loss with an occurrence probability of 0.5 % over a one-year horizon, that is, a loss expected on average only once every two hundred years. This value-at-risk at the 99.5 % level, the so-called one-in-two-hundred-year event, is the keystone of the entire edifice. The insurer calculates it either through a standard formula provided by the regulator, or through its own internal model, approved by the supervisor and generally reserved for large groups with the necessary actuarial resources.
The standard formula proceeds by breaking risk down into modules, market, counterparty default, life, health and non-life underwriting, to which operational risk is added. Each module is the subject of a capital calculation, and the modules are then aggregated not by simple addition but by means of correlation matrices. This aggregation procedure is the conceptual core of the formula, and its founding assumption deserves to be made explicit, the various risks do not all materialise simultaneously, so that the total required capital is lower than the sum of the modular charges. This is the diversification benefit, which rewards an insurer whose exposures are decorrelated. The entire robustness of the formula therefore rests on the stability and moderation of these correlations.
This construction presupposes two things that classical actuarial science takes for granted. First, that the risks be sufficiently independent that a shock will not mechanically trigger several others in cascade. Second, that one has a loss history deep and stationary enough to credibly calibrate a distribution tail as remote as the one-in-two-hundred-year percentile. Cyber risk, by its very nature, contradicts both of these premises, and it is precisely this twofold contradiction that makes it the revealer of the limits of the edifice.
Before being a product it sells, cyber is first a risk the insurer bears in its own operations. An insurance company is a heavily digitalised enterprise, whose systems for policy administration, pricing, claims settlement and the storage of personal data constitute so many attack surfaces. An intrusion, a ransomware attack or a cloud infrastructure outage can paralyse its activity, compromise policyholder data and engage its liability. In the prudential taxonomy, this risk falls under operational risk, that is, the risk of losses resulting from a failure of procedures, people, systems or external events.
Cyber is then a risk the insurer knowingly transfers onto its balance sheet by marketing cyber insurance policies, whether explicit coverage, known as affirmative, or implicit guarantees lodged in traditional contracts, the silent cyber discussed in an earlier article in this series. This cyber underwriting risk has grown rapidly. Munich Re estimated the global cyber insurance market at 15.3 billion dollars in premiums in 2024, less than 1 % of the property and casualty market, and anticipated a doubling by 2030 at an annual rate above 10 %1. Geographic concentration remains strong, with North America accounting for about 69 % of premiums and Europe for 21 %1. The prudential question is then how Solvency II captures these two faces of cyber, the one the insurer bears and the one it sells.
The treatment of the cyber risk borne by the insurer illustrates the crudeness of the operational risk module of the standard formula. This capital is calculated on a flat-rate basis, by applying factors to bases such as earned premiums and technical provisions, with no sensitivity whatsoever to the actual quality of the entity's cybersecurity. A company with state-of-the-art protection and a negligent company are charged the same amount, provided their volumes are comparable. More constraining still, this operational capital is capped at 30 % of the basic Solvency Capital Requirement2. Operational risk, and therefore the cyber risk it harbours, can thus never represent more than a conventional fraction of the total requirement, regardless of actual exposure. The implicit message of the formula is clear, operational risk is conceived as a second-order risk, an assumption increasingly hard to defend in the age of systemic cyberattacks.
The cyber risk sold by the insurer suffers from a symmetrical blind spot. The standard formula contains no specifically cyber underwriting module. The exposure is diluted within the non-life underwriting module, inside premium and reserve risk, calibrated on generic sectoral factors, and the non-life catastrophe module, which details sub-modules for natural catastrophes and for certain man-made catastrophes such as fire or marine risks, provides for no cyber catastrophe scenario. Yet it is precisely the catastrophic dimension, that is, the accumulation of a large number of claims triggered by a single event, that constitutes the central danger of cyber insurance. The standard formula therefore measures cyber risk with instruments designed for risks of a radically different nature.
To these two blind spots is added the persistence of silent cyber, that is, non-affirmative cyber exposures lodged in traditional policies. The contractual clarification imposed by the London market's LMA 21-042 directive, analysed in an earlier article, has no binding regulatory equivalent on the continent, where EIOPA confined itself in 2022 to recommendations on the management of non-affirmative cyber and its exclusions3. A residual cyber exposure, poorly tracked and therefore poorly capitalised, thus remains scattered across European property portfolios, escaping by construction any dedicated prudential measure.
The deepest flaw is not the absence of this or that module, it is the unsuitability of the modular logic itself to cyber risk. The standard formula assumes moderate and stable correlations between risks. Cyber frontally violates this assumption, because a single systemic event can simultaneously trigger correlated losses across an entire underwriting portfolio, across the operational functioning of the insurer, and even across its financial assets if the event disrupts markets. Examples are not lacking. The NotPetya attack of 2017 and the CrowdStrike incident of 2024, both examined in this series, showed that a single technical cause could strike tens of thousands of organisations within a few hours, shattering the independence of claims on which mutualisation rests.
This tail correlation, that is, the fact that risks become strongly dependent precisely in extreme scenarios, is the Achilles' heel of any aggregation-based approach. The correlation matrices of the standard formula are calibrated on average conditions and structurally underestimate the dependence that manifests itself in catastrophe. The diversification benefit the formula grants then becomes an accounting illusion, because the assumed diversification disappears at the very moment the insurer would need it most. A major cyber event turns an apparently diversified portfolio into a single concentrated exposure.
Large cyber insurers rely on internal models, which in principle allow a finer representation of accumulation, through the simulation of systemic scenarios and the explicit modelling of dependencies. This path nonetheless runs into an irreducible difficulty, the scarcity and instability of data. Where fire or motor risk draws on decades of stationary history, cyber risk evolves faster than data accumulates, as the attack surface, offensive techniques and dependence on the same critical providers transform from one year to the next. The internal model therefore shifts the problem without solving it, substituting for the absence of a module a dependence on proprietary models whose calibration rests on fragile assumptions that are difficult for the supervisor to verify.
Faced with a risk it cannot yet capitalise correctly, the European authority has adopted a sequential strategy whose logic deserves to be commended, beginning by making the risk visible before claiming to price it. The Solvency II review thus introduced a specific prudential reporting template, template S.14.03 on cyber underwriting risk, which requires the non-life insurers concerned to report their cyber exposure in a granular manner, by product group4. This template falls under the third pillar, that of transparency, and not the first, that of capital. It creates no additional charge, but it provides the supervisor with a map of the market's affirmative cyber exposure, an indispensable precondition for any future calibration.
EIOPA has in parallel developed a stress-testing methodology specific to cyber, published in 2023, which defines underwriting scenarios such as a widespread cloud outage, a wave of ransomware or a prolonged power cut, to be applied at the granular level of products and policyholders5. Cyber underwriting risk is there defined as the insurer's capacity to absorb, from a solvency standpoint, the financial impact of a cyber loss. This scenario-based approach circumvents the impossibility of calibrating a complete distribution by testing the resilience of the balance sheet to shocks defined a priori, a more modest approach but one better suited to a risk whose distribution tail escapes classical statistical estimation.
The second pillar completes this apparatus by shifting the burden toward governance. The Own Risk and Solvency Assessment, the ORSA, requires each insurer to conduct a forward-looking analysis of its own risks, in which cyber must now feature through scenarios suited to its profile. In February 2026, EIOPA revised its Guidelines on the supervisory review process to explicitly incorporate IT and cyber risks, calling on national supervisors to place them at the heart of their examination6. Where the first pillar struggles to set a figure, the second organises a qualitative and continuous vigilance, an implicit acknowledgement that cyber is better governed than capitalised.
The revised directive of 4 December 2024, which amends Solvency II, will enter into application on 30 January 2027, accompanied by a delegated regulation adopted in October 20257. This review strengthens proportionality, integrates requirements relating to climate risk and reinforces macroprudential tools, but it creates no cyber capital module within the standard formula. The regulator's deliberate choice is to advance through transparency and governance rather than through a capital charge whose calibration would, given the current state of data, be largely arbitrary. This caution is consistent with a risk whose distribution is not yet estimable, but it leaves a gap between the sophistication of the exposure and the crudeness of its translation into capital.
A cyber-native prudential treatment would require lifting several locks. It would first need pooled sectoral data, rich and homogeneous enough to calibrate credible accumulation scenarios, something to which S.14.03 reporting is beginning to contribute. It would then need models capable of explicitly representing the tail correlation between underwriting, operations and assets, where the modular formula dissolves it. It would finally need to settle a question of substance, whether a share of cyber accumulation risk, like a share of the climate risk discussed earlier in this series, falls within a capacity that the market alone can bear, or whether it calls for a market-wide mechanism or a public backstop, along the lines of the arrangements envisaged for extreme natural catastrophes.
The trajectory of Solvency II in the face of cyber illustrates a more general truth about financial regulation, a prudential framework can capitalise only what it can measure, and it can measure only what it has a history of. Cyber risk, because it is young, shifting and systemic, lays this limit bare. The European response, made of greater transparency, stress tests and reinforced governance, is not an admission of impotence but the expression of methodological caution, refusing to quantify a distribution tail it does not master, and building first the conditions for its future measurability. The real question of the coming years will not be whether cyber will eventually enter the standard formula, but whether the industry and the supervisor will manage to accumulate, quickly and collectively enough, the knowledge that will make this integration something other than an exercise in calibrated arbitrariness.
Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.
Revisiting the Lloyd's LMA 21-042 directive and its implications for Property & Casualty reinsurance treaties
The Insurance-Linked Securities market represents a quiet revolution in global finance: for the first time, catastrophe risk migrates off insurer balance sheets into the portfolios of pension funds and institutional investors.
One morning, a letter tells you your home will not be reinsured. You have done nothing wrong, your house has not changed. What has changed is that chance, the thing all insurance rests on, has quietly left your postcode.