A shared digital component whose single failure can trigger simultaneous losses across a very large number of insureds.
In the context of cyber insurance, a Single Point of Failure refers to a shared digital component, a cloud provider, software publisher, certificate authority or security vendor, whose single failure propagates to the large number of organizations that depend on it. This concept lies at the heart of cyber accumulation analysis, as it explains how an isolated technical event can turn into a correlated mass loss for an insurance portfolio. Unlike physical risk, where geographical dispersion naturally limits accumulation, digital risk is characterized by a concentration of dependencies around a small number of critical infrastructures. The insurer must therefore map not only each insured's own vulnerabilities but also the common providers shared across the whole portfolio, which is a matter of aggregate exposure analysis rather than individual analysis. The central difficulty is that these dependencies are often invisible in underwriting submissions, since an insured frequently does not know which fourth-tier providers support its own direct suppliers.
The global outage caused by a faulty CrowdStrike update in July 2024 simultaneously paralyzed transport, healthcare and finance companies, illustrating how a single security vendor can become a systemic point of failure.
point de défaillance unique, SPOF cyber, point unique de défaillance