Risk that a single cyber event simultaneously affects a large number of interconnected insureds, generating an accumulation of correlated claims that cannot be modeled with traditional actuarial tools.
Systemic cyber risk refers to the possibility that a single cyber event, such as a massive cyberattack, a widely exploited zero-day vulnerability or a failure of critical digital infrastructure (cloud provider, DNS, BGP), triggers simultaneous and correlated claims from a very large number of insureds, generating an accumulation that exceeds the insurance sector's capacity. This risk is structurally different from natural perils (where geographic correlation is predictable) because the perimeter of a cyber event is difficult to define ex ante and its propagation can be near-instantaneous on a global scale. State-backed cyber operations represent a particularly concerning subcategory of systemic risk, as their firepower and ability to target critical infrastructure makes them potentially more devastating than a cybercriminal attack. This is precisely why Lloyd's imposed clarity on cyber war coverage: by excluding or capping the most systemic state-backed cyber operations (impacted state), LMA 5565 to 5567 clauses aim to make the residual risk modelable and therefore insurable.
In 2024, a global outage of the CrowdStrike platform temporarily paralyzed millions of Windows systems worldwide: hospitals, airports, banks. Although non-malicious, this outage illustrated the accumulation potential of systemic cyber risk. A state-backed cyberattack of the same scale would have triggered simultaneous claims at thousands of insureds.
accumulation cyber, risque systémique, systemic risk, cyber systemic risk, accumulation catastrophique