The regulator asks a simple question, how much money must you hold to survive your worst year in two centuries. For a book of hurricanes, the actuary answers without flinching. For a book of ransomware, the room falls silent.
Picture the scene in a European insurer's offices. The supervisor asks its ritual question, the one that underpins the whole prudential regime of the continent, how much capital must you set aside to absorb your worst year in two hundred. Facing the natural-catastrophe book, the actuary answers with confidence, they have centuries of storm records, well-understood physics, tested models. Then the same question turns to the cyber book, and an awkward silence settles. Because no one holds two centuries of ransomware data. Ransomware has barely a decade of existence, and it rewrites its own rules every year. The regulator's question, perfectly reasonable for a hurricane, becomes almost absurd for a ransom, and that gap is the subject of this issue.
Here is the thesis. Solvency II is a magnificent machine for turning a risk into a capital figure, but it runs on two fuels, history and independence. Cyber has neither. Ransomware is too young to offer a past to lean on, and it is too correlated to respect the diversification the whole regime presupposes. When Solvency II meets a ransom, it produces a number that looks solid and is in fact a confident guess about the unknowable. The danger is not that the number is wrong, it is that it looks right.
To see why, we must return to the heart of Solvency II, the solvency capital requirement. The idea is of limpid elegance, an insurer must hold enough own funds to survive a loss that occurs only once every two hundred years, which actuaries express as a threshold of ninety-nine point five percent over one year. To compute that amount, you need two ingredients, a distribution of possible losses, drawn from history, and an assumption about how risks combine, usually diversification, the idea that not everything goes wrong at the same time.
A good image is that of a levee built to withstand the highest flood in two hundred years. You can only build the levee to the right height if you hold two centuries of river records. For floods, you have them. For cyber, imagine a river that only started flowing ten years ago, whose bed shifts every spring, and above all upstream of which stands an intelligent adversary deliberately engineering new floods to surprise you. Two problems then arise, and each attacks one ingredient of the calculation.
The first problem is the absence of history. The distribution of cyber losses rests on data that is scarce, short and non-stationary, meaning its properties change over time. Extrapolating a two-hundred-year loss from ten volatile years amounts to guessing the height of a millennial flood having seen only a few springs. The second problem is the absence of independence. Cyber accumulates, a single shared software flaw, a single common cloud provider, a single well-built worm can strike thousands of insureds at once. We saw it in July 2024, when a faulty update simultaneously paralysed millions of systems worldwide. Yet diversification, that magic which lets an insurer hold far less capital than the sum of individual worst cases, evaporates the moment everything can fall together. The losses no longer offset each other, they stack.
The consequence is that the capital required for cyber ends up in an uncomfortable position. Either it understates the tail of the distribution, and the insurer holds too little own funds against a correlated catastrophe that, when the day comes, will strike its whole book at once. Or, if the risk is honestly loaded to the level of its real potential, the required capital becomes so heavy that cyber looks barely insurable, unprofitable, discouraging supply at the very moment demand explodes. Between these two hazards there is no comfortable position, only a permanent trade-off between a prudence that smothers the market and a confidence that exposes it.
The most troubling part is the false precision. A figure as crisp as ninety-nine point five percent applied to a risk you cannot model dresses uncertainty in a veneer of rigour. The number looks computed, it is largely guessed, and this appearance of mastery is precisely what lulls vigilance. An insurer displaying a cyber capital figure calculated to the decimal seems in control, when it may be holding a fragile estimate of a phenomenon that refuses to be counted. The precision of the number is inversely proportional to the certainty it ought to inspire.
To this difficulty is added a question of horizon. Solvency II reasons over one year, it asks how much capital it takes to absorb the worst year. Yet cyber does not always unfold in twelve months. A flaw can be exploited in silence for months, a wave of litigation can arise long after the attack, and a systemic accumulation can build slowly, contract after contract, before revealing itself all at once. Measuring over one year a risk that forms over several amounts to photographing a wave at the instant it looks calmest. The annual horizon, perfectly suited to market shocks that resolve quickly, lets slip precisely the most dangerous dimension of cyber, its capacity to accumulate in the shadows before breaking.
Here we must distinguish two ways of computing this capital, because they fail differently. The largest insurers use internal models, tailor-made and validated by the supervisor, finer but also more opaque, and sometimes inclined to an optimism no outsider can easily contradict. The others fall back on the standard formula, a uniform and prudent calculation, but crude in the face of a risk as peculiar as cyber. Neither path is satisfactory, the first risks flattering the risk, the second caricaturing it, and the supervisor ends up arbitrating between a suspect precision and an ill-suited simplicity, never holding the data that would settle it.
The debate that opens here is real, and both camps have serious arguments. Defenders of the framework recall that it is adaptable, one can add cyber-specific modules, stress scenarios, prudence margins, and that an imperfect number beats no number at all, because it at least forces the insurer to reserve and the supervisor to watch. An improvable framework is still a framework, and the alternative, the absence of prudential discipline, would be far worse.
Critics reply that applying a precise percentile to an unmodelable risk is false precision, and above all that it creates a systemic blind spot. If all insurers use similar models, fed by the same scarce data and the same modelling vendors, they will all understate the risk in the same way, and so be surprised together. This is the danger of a monoculture of models, where the uniformity of methods recreates, at the level of the whole sector, the very correlation each insurer thought it had diversified away. To this is added a perverse incentive, the harder cyber is to capitalise, the more insurers cap limits, multiply exclusions or retreat, shrinking cover at the worst moment. A regime designed to make each insurer solid individually could thus, faced with a correlated risk, make the system fragile collectively, because everyone holds the same underestimated number.
A final pitfall undermines the calculation from below, the uncertainty over what is actually covered. Many cyber contracts exclude acts of war, yet a major attack has a strong chance of being the work of a state or its proxy. The insurer could therefore invoke the exclusion to avoid paying, but attributing a cyberattack to a state is notoriously uncertain and slow. The capital computed then rests on a cover whose perimeter stays blurred, liable to retract at the worst moment or, conversely, to force the insurer to pay a loss it thought excluded. One prices a risk without knowing even the exact extent of one's own promise, which adds to the blur of frequency the more embarrassing blur of coverage itself.
The matter is anything but hypothetical. In 2017, the NotPetya malware, launched from Ukraine, spread across the world in hours, paralysing giants of logistics, pharmaceuticals and industry, for a global cost estimated at some ten billion dollars. When one of the affected groups claimed more than a billion from its insurers, they invoked the act-of-war exclusion, several states having attributed the attack to a state actor. It took years of litigation to settle, an American court eventually ruling against the insurers. This episode sums up the whole problem, a single loss striking thousands of entities at once, a massive and correlated accumulation, and a battle over the very meaning of the cover, all at a scale no two-hundred-year model had seen coming. The regulatory capital computed the day before NotPetya had not the faintest idea of what awaited it.
There is something worse still than an error of measurement, there is the effect of the measurement on behaviour. A cyber capital figure that looks under control is not a neutral artefact sitting in a corner of the balance sheet, it authorises action. Reassured by a crisp number, an insurer will feel entitled to grow its cyber book, to raise its limits, to underwrite more, convinced that regulation has validated its prudence. False precision therefore does not merely mismeasure the risk, it amplifies it, by giving the green light to the very expansion an honestly uncertain figure would have restrained. The number transforms what it claims only to describe, and that may be the most perverse of all its effects, because it manufactures the confidence that swells the exposure it was meant to contain.
The meeting between Solvency II and a ransom is, at bottom, the meeting of two philosophies of the future. The first says the future resembles the past, that it is enough to measure it and hold capital against it. This is the philosophy of all prudential regulation, an institutionalised bet that tomorrow will resemble yesterday. The second philosophy is that of the ransomware author, for whom the future is precisely what they will invent next. Cyber is the first major risk shaped by an adversary whose trade is to make tomorrow different from yesterday, to deliberately break the regularity on which all forecasting rests.
The real question is therefore not whether one can compute a capital charge for cyber, one can, and one does every day. It is whether a number born of history can ever contain a risk that has declared war on history. As long as the answer stays uncertain, cyber capital will remain the most carefully calculated and least reliable figure on an insurer's balance sheet, an impeccably computed levee at the edge of a river whose next flood no one knows.
Perhaps one must then accept that cyber does not let itself be fully locked into a number, and that the role of regulatory capital, for this risk, is not to guarantee survival but to lower its probability, while knowing that a margin of the unknown will always remain. Recognising this limit would already be progress, because the real danger is not holding imperfect capital, it is believing it perfect. An insurer clear-eyed about the uncertainty of its own model is better armed than one reassured by the false crispness of its result, because it keeps the caution that overly neat figures tend to lull to sleep.
Further reading, the EIOPA reports on insurance and cyber risk, the work of the Bank of England and its prudential authority on cyber underwriting, and the Geneva Association's analyses of cyber accumulation illuminate the limits of the framework in the face of this risk.
In echo, AlgoPolis foundational article 07, Solvency II tested by cyber risk, details and quantifies how the solvency capital requirement works.
Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.
Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.
Parametric insurance promises to replace the slowness of loss adjustment with the speed of measurement. This elegance has a price often left unspoken: by substituting an index for actual damage, it trades the friction of adjustment for two new dependencies, basis risk and trust in the oracle.
A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.
A structure falls in a town you have never heard of, and a retiree's savings in Tokyo wobble that same month. A hidden wire runs between the two, and that wire is reinsurance.