Back to glossaryActuarial science

Cyber risk quantification (CRQ)

Set of actuarial and probabilistic methods aimed at expressing cyber risk exposure in financial terms, to guide pricing, reserving and coverage decisions.

Definition

Cyber risk quantification seeks to answer a simple but difficult question: what is the probable cost, in euros or dollars, of a cyber event for a given organization? Approaches divide between formal probabilistic models, among which the FAIR framework, Factor Analysis of Information Risk, is most widespread, and stochastic simulation models, which generate loss distributions from threat scenarios. A fundamental difficulty is the insufficiency of homogeneous historical data: unlike fire or life risk, cyber is a recent, non-stationary risk whose loss experience evolves with the offensive capabilities of attackers. Actuaries must therefore combine internal data, external threat intelligence, vulnerability scan results and sector benchmarks. CRQ links with reinsurance, as it enables calculation of attachment points and layer limits; with Solvency II, as it feeds internal SCR cyber models; and with red teaming, whose results can calibrate occurrence probabilities used in scenarios. A challenge specific to CRQ is systemic correlation: the same attack vector can simultaneously affect thousands of policyholders, invalidating the independence assumption underlying classical actuarial models.

Example

A cyber insurer feeds its CRQ model with an attack scenario targeting a SaaS payroll provider used by 1,200 of its SME policyholders. The FAIR model estimates a probable aggregate loss of 85 million euros, 2.3 times the available net capacity. Management decides to transfer the excess via a cyber catastrophe bond and to introduce an accumulation sub-limit per vendor in the new policy conditions.

Related terms
Also known as

CRQ, cyber risk quantification, quantification risque cyber, modélisation financière du risque cyber, cyber financial modelling