Cyber model

How much cyber loss, how much cover?

Frequency-severity model (Poisson x lognormal) simulated over 20,000 years: annual loss distribution, loss / return-period curve (99.5% VaR) and insurance-program sizing. 100% in the browser, all parameters and sources shown.

$4.88M
Global average cost of a data breach in 2024.
IBM Cost of a Data Breach 2024
258 days
Average time to identify and contain a breach.
IBM Cost of a Data Breach 2024
~24 days
Average downtime after a ransomware event.
Coveware
4%
GDPR fine ceiling, as a share of global turnover.
GDPR, Article 83

Organisation profileImplied turnover 90 M€

Sector
Size
Cyber-security maturity
Partial MFA, regular backups, EDR on key endpoints.
Sensitive personal data (health, banking, biometric)
Average annual loss
608 k€
Expected cyber loss over one year, across all scenarios (the pure premium).
Probability of at least one incident this year : 31 %
Most years pass with no incident: the loss is carried by rare but severe scenarios. The tail is what matters.
Loss / return-period curve
Annual loss exceeded on average once every T years.
0 €5.6 M€11 M€17 M€22 M€1/11/101/1001/500Return period1.5 M€9.3 M€13 M€

Return periodVaR

1 / 101.5 M€
1 / 203 M€
1 / 506 M€
1 / 1009.3 M€
1 / 200 · VaR 99.5%13 M€

Annual loss exceeded on average once every T years.

Manageable
The reinsurer's read

An absorbable risk

The 1-in-200 scenario stays a fraction of turnover: insurable at reasonable cost, the point is to optimise the retention.

Priority levers
  • Strengthen the cyber posture: up to -45% average annual loss and better underwriting terms.
  • Sensitive-data governance: encryption, minimisation and a notification plan reduce GDPR severity.

Cyber-maturity lever

HighLow

A mature posture would bring the average annual loss to 334 k€ (about -45%). Maturity drives frequency, the primary engine of the risk.

Average annual loss
608 k€
High
334 k€
Retained loss at 1-in-200
3.4 M€
Insurance-program sizing
Set the retention you keep and the limit transferred to the insurer.
Retention (deductible)600 k€
Limit (sum insured)10 M€
Split of a 1-in-100 loss (9.3 M€)
Retained 600 k€Transferred 8.7 M€
Indicative premium
606 k€
Rate on line (ROL)
6.1 %
Ceded loss (average)
379 k€
Retained loss (average)
229 k€
Retained loss at 1-in-200
3.4 M€
Premium = average ceded loss x 1.6 (loading for expenses, capital and margin, i.e. a target loss ratio of about 63%). Excludes tax and market conditions.

The link reopens this exact scenario: profile, assumptions and insurance programme.

How it is calculated
Model parameters
Annual frequency (lambda)0.375
Median severity per event648 k€
Lognormal dispersion (sigma)1.35
Severity cap (single event)90 M€
Simulated years20,000
Sources & calibration
Order-of-magnitude coefficients calibrated on public studies we document:
IBM, Cost of a Data Breachsource →Verizon, DBIRsource →NetDiligence, Cyber Claims Studysource →Coveware, Ransomware Marketplacesource →Ponemon Institutesource →
Assumptions & limits
  • Frequency of material incidents: Poisson with parameter lambda (sector x size x maturity).
  • Severity per event: lognormal (median and dispersion by sector, size and data sensitivity).
  • Aggregate losses via a seeded, therefore reproducible, simulation over 20,000 years.
  • Single-event severity capped at turnover (an implicit bound covering the 4% GDPR maximum).
  • Maturity acts on frequency, not on severity once an incident occurs.
Go further
Read AlgoPolis research →

Order-of-magnitude model, for educational and framing purposes. Coefficients are calibrated on public studies (IBM, Verizon DBIR, NetDiligence, Ponemon, Coveware) and do not replace a model specific to your exposure, contracts and cover. Indicative premium, neither firm pricing nor advice.