← Back to tools

Tool 07 · Cyber model

How much cyber loss, how much coverage?

Frequency-severity model (Poisson x lognormal) simulated over 20,000 years: annual loss distribution, loss / return-period curve (99.5% VaR) and insurance-program sizing. 100% in the browser, all parameters and sources shown.

$4.88M
Global average cost of a data breach in 2024.
IBM Cost of a Data Breach 2024
258 days
Average time to identify and contain a breach.
IBM Cost of a Data Breach 2024
~24 days
Average downtime after a ransomware event.
Coveware
4%
GDPR fine ceiling, as a share of worldwide annual revenue.
GDPR, Article 83

Organization profileImplied revenue €90M

Sector
Size
Cyber-security maturity
Partial MFA, regular backups, EDR on key endpoints.
Sensitive personal data (health, banking, biometric)
Average annual loss
€608K
Expected cyber loss over one year, across all scenarios (the pure premium).
Probability of at least one incident this year: 31%
Most years pass with no incident: the loss is carried by rare but severe scenarios. The tail is what matters.
Loss / return-period curve
Annual loss exceeded on average once every T years.
€0€5.6M€11M€17M€22M1/11/101/1001/500Return period€1.5M€9.3M€13M

Return periodVaR

1 / 10€1.5M
1 / 20€3M
1 / 50€6M
1 / 100€9.3M
1 / 200 · VaR 99.5%€13M

Annual loss exceeded on average once every T years.

Manageable
The reinsurer's read

An absorbable risk

The 1-in-200 scenario stays a fraction of revenue: insurable at reasonable cost, the point is to optimize the retention.

Priority levers
  • Strengthen the cyber posture: up to -45% average annual loss and better underwriting terms.
  • Sensitive-data governance: encryption, data minimization and a notification plan reduce GDPR severity.

Cyber-maturity lever

HighLow

A mature posture would bring the average annual loss to €334K (about -45%). Maturity drives frequency, the primary engine of the risk.

Average annual loss
€608K
High
€334K
Retained loss at 1-in-200
€3.4M
Insurance-program sizing
Set the retention you keep and the limit transferred to the insurer.
Retention (deductible)€600K
Limit (sum insured)€10M
Split of a 1-in-100 loss (€9.3M)
Retained €600KTransferred €8.7M
Indicative premium
€606K
Rate on line (ROL)
6.1%
Ceded loss (average)
€379K
Retained loss (average)
€229K
Retained loss at 1-in-200
€3.4M
Premium = average ceded loss x 1.6 (loading for expenses, capital and margin, i.e. a target loss ratio of about 63%). Excludes tax and market conditions.

The link reopens this exact scenario: profile, assumptions and insurance program.

How it is calculated
Model parameters
Annual frequency (lambda)0.375
Median severity per event€648K
Lognormal dispersion (sigma)1.35
Severity cap (single event)€90M
Simulated years20,000
Sources & calibration
Order-of-magnitude coefficients calibrated on public studies we document:
IBM, Cost of a Data Breachsource →Verizon, DBIRsource →NetDiligence, Cyber Claims Studysource →Coveware, Ransomware Marketplacesource →Ponemon Institutesource →
Assumptions & limits
  • ·Frequency of material incidents: Poisson with parameter lambda (sector x size x maturity).
  • ·Severity per event: lognormal (median and dispersion by sector, size and data sensitivity).
  • ·Aggregate losses via a seeded, therefore reproducible, simulation over 20,000 years.
  • ·Single-event severity capped at annual revenue (an implicit bound covering the 4% GDPR maximum).
  • ·Maturity acts on frequency, not on severity once an incident occurs.
Go further
Read AlgoPolis research →

Order-of-magnitude model, for educational and framing purposes. Coefficients are calibrated on public studies (IBM, Verizon DBIR, NetDiligence, Ponemon, Coveware) and do not replace a model specific to your exposure, contracts and cover. Indicative premium, neither firm pricing nor advice.