Infrastructure & data centers

Technology dependency vectors

Modelling variables measuring the market share of major IT providers in a cedant's portfolio, used to quantify implicit concentration on technological single points of failure.

Definition

Technology dependency vectors are modelling variables introduced into cyber catastrophe models following the 2024 CrowdStrike event to capture the implicit concentration of a cedant's portfolio on a given technology provider. Swiss Re, Munich Re, Hannover Re and leading modelling platforms (Verisk Analytics, Moody's RMS) revised their methodologies to integrate these vectors: they measure the market share of each major IT provider (security vendors, hyperscalers, critical BGP providers) within the revenues or system counts of insured companies in a portfolio. The weighted sum of exposures by these market shares allows calculation of the cyber Probable Maximum Loss (PML) for a systemic failure scenario, analogous to seismic or hurricane PML in classical CAT models. These vectors have since become a standard component of large-scale cyber underwriting.

Example

A reinsurer calculates that 34% of the insured companies in its property portfolio use CrowdStrike Falcon as their EDR. The CrowdStrike dependency vector equals 0.34. Combined with the portfolio's company size distribution, this vector produces a cyber PML estimate for a total failure scenario of that vendor, enabling calibration of sub-limits specific to technology failure events.

Related terms
Related articles
Also known as

technology dependency vectors, vecteurs de concentration IT, concentration fournisseur IT