Cyber risk poses severe challenges to the society and has become an important theme in risk management and insurance. Yet its statistical features and evolution over time are not sufficiently understood. This paper focuses on two key dimensions of cyber risk-loss severity and tail risk-using three different cyber loss databases. We first focus on the dynamics of loss severity, identifying structural shifts in distributions through a Fr & eacute;chet-based change point detection method and applying inverse probability weighting to control for selection bias. Our results indicate an increase in the severity of malicious cyber losses since 2018, whereas negligent incidents do not follow the same trend. We then propose methods that combine tail index estimation and change point detection, finding that cyber loss distributions remain heavy-tailed over time, despite heterogeneity across different risk categories. Finally, we present a numerical analysis to illustrate how losses of a simulated cyber insurance portfolio evolve over time, emphasizing the importance of incorporating the dynamic properties of cyber risk into pricing strategies for insurance companies.
Crises have profound and varied impacts on individual and societal behaviors, shaping preferences and decision-making processes. Switzerland, with its distinct language regions and shared institutional frameworks, provides a unique setting to explore how the Covid-19 pandemic influenced risk and time preferences across cultural boundaries. The results indicate that the pandemic made people more risk averse, more patient and diminished preexisting cultural differences. The authors show evidence that the shift from regional to uniform nationwide restrictions during the pandemic altered social behavior and beliefs and their interaction with individuals' cultural backgrounds drove changes in preferences. These findings underscore the importance of considering cultural and societal dimensions in policy design, especially during crises.
Open Insurance applies Open Finance principles to the insurance sector by enabling the sharing of insurance-related data with third-party providers. Despite strong policy interest, empirical evidence on Open Insurance remains very limited. This paper analyses consumer preferences for Open Insurance services using a large-scale survey from the German-speaking insurance markets combined with a choice-based conjoint analysis. The results show that consumers value transparency-enhancing services, such as consolidated overviews of insurance coverage and identification of coverage gaps. Willingness to pay exists but is limited, suggesting challenges for direct monetisation. Trust is a key determinant of acceptance: services offered by established insurers and public institutions are preferred over offerings by new private entrants such as insurtech firms. Overall, the findings indicate that Open Insurance is likely to evolve incrementally rather than disruptively, with trust and usability shaping its economic impact.
We use the dynamic inoperability input-output model-presented in this journal to analyze cyber risk scenarios-to evaluate the economic impact of seven plausible, potentially high-consequence artificial intelligence (AI) risk scenarios. The scenarios span a diverse range of AI-related disruptions, including failures of widely used business software, breakdowns in AI-enabled transport systems, or targeted AI-based attacks on critical infrastructure. Each scenario is modeled based on sectoral inoperability, recovery dynamics, and cascading effects across the economy. Estimated losses for the U.S. economy range from US$11 billion to US$85 billion. While most scenarios fall within insurable limits, some might exceed the risk-bearing capacity of private insurers and require public-private risk-sharing mechanisms, especially for AI-based attacks on critical infrastructure. This study presents a structured, scenario-based approach to assessing the insurability of emerging AI risks in the absence of historical data and thus assists decision-makers in better understanding this emerging type of risk.
This seminar series is jointly organized by [***World Salon***](https://www.world-salon.com/) and [***Risk Science***](https://www.keaipublishing.com/en/journals/risk-sciences/) Prof. Dr. Martin Eling is Full Professor of Insurance Economics and holds the Chair for Insurance Management at the University of St. Gallen, where he also serves as Director of the Institute of Insurance Economics. His empirical research spans insurance management, mathematics, and economics, focusing in recent years on cyber risk, risk measurement, regulation, digitalization, and systemic vulnerabilities in financial and insurance markets. He earned his doctorate in 2005 at the University of Münster and has held appointments in Ulm and as a visiting professor in the USA, among others. Prof. Eling is a prolific author, advisor, and speaker, widely recognized for his work on the insurability of emerging risks, regulatory frameworks like Solvency II, and the quantitative modeling of risk in interconnected systems. Dr. Petar Jevtic is an Associate Professor in the School of Mathematical and Statistical Sciences at Arizona State University, with affiliations in the Center for Biodiversity Outcomes. He holds a Ph.D. in Economics with specialization in Applied Mathematics and Statistics from the University of Turin, along with degrees in Economics and Computer Science and Engineering from Belgrade. His research spans longevity risk, property casualty insurance, cyber risk, smart contract and autonomous systems risk, and climate‑induced risk. He has published in leading journals, holds patents in cyber risk modeling and pricing, and his work is supported by grants from bodies such as the NSF, DHS, and Society of Actuaries. Amir Ansari is Chief Technology Advisor at Lenovo, where he leads advanced services strategy across EMEA, focusing on AI, Big Data, and cloud-driven transformations for enterprise and public sector clients. With deep expertise in architecting secure, data-centric solutions, Amir has spearheaded initiatives across Smart Cities, Defense, Healthcare, and Education—deploying edge and hybrid cloud strategies that reduce data latency, enforce local data residency, and integrate cybersecurity frameworks such as ISO 27001, NIST, and GDPR. As a trusted advisor to CxOs, Amir has guided organizations in navigating the intersection of innovation and risk, embedding security and compliance into AI, IoT, and edge ecosystems while enabling operational efficiency gains of up to 40%. He is passionate about helping organizations address the rising cyber risks in connected systems by designing resilient architectures that balance agility, compliance, and digital trust. Dr. Yevgeniy Vorobeychik joined Washington University in St. Louis in 2018. He was an assistant professor of computer science and biomedical informatics at Vanderbilt University from 2013 until 2018, and a principal research scientist at Sandia National Laboratories from 2010 until 2013. Between 2008 and 2010 he was a post-doctoral research associate at the University of Pennsylvania Computer and Information Science department. He received a PhD and MSE in Computer Science and Engineering from the University of Michigan and a BS degree in Computer Engineering from Northwestern University. Professor Vorobeychik received an NSF CAREER award in 2017 and was invited to give an IJCAI-16 early career spotlight talk. He was nominated for the 2008 ACM Doctoral Dissertation Award and received honorable mention for the 2008 IFAAMAS Distinguished Dissertation Award. Dr. Linfeng Zhang is an Assistant Professor in the Department of Mathematics at The Ohio State University, specializing in actuarial science and risk analytics. He earned his Ph.D. in Mathematics from the University of Illinois at Urbana–Champaign and is an Associate of the Society of Actuaries. Before joining Ohio State, he served as a Visiting Assistant Professor of Actuarial Science at Drake University and gained industry-oriented research experience at the Critical Infrastructure Resilience Institute, focusing on cyber risk and cyber insurance. His research explores cyber risk, pandemic risk, and privacy risk, with publications in leading journals such as The Geneva Papers on Risk and Insurance, IEEE Transactions on Emerging Topics in Computing, and the Connecticut Insurance Law Journal. He has led and contributed to projects funded by the Society of Actuaries, Fundación MAPFRE, and Cisco, and continues to advance interdisciplinary approaches to risk management and actuarial science.
PurposeThis study aims to develop a comprehensive framework for discussing sustainability within the insurance industry, extending the traditional Environmental, Social, and Governance (ESG) dimensions to include economic and technological considerations. This inclusion is vital, recognizing that financial stability and the adoption of innovative technologies are fundamental to meeting other sustainability targets.Design/methodology/approachWe base our findings on an extensive literature review, case studies, and interactive workshops with key stakeholders in the insurance industry. Our analytical framework employs Porter's (1985) insurance-specific value chain, complemented by Berliner's (1982) insurability criteria, to distinguish between insurable and non-insurable risks.FindingsOur results show that the insurance industry is sustainable because it actively incorporates and contributes to sustainability goals across environmental, social, economic, and technological dimensions. This is illustrated through the identification of 50 distinct contributions across the insurance value chain, showcasing the sector's unique position to significantly influence the sustainability discourse.Practical implicationsAddressing the pressing challenges of sustainability and insurability necessitates a strategic, collective response from the global insurance and risk management community. This paper proposes several policy recommendations, including enhancing risk assessment methodologies, diversifying insurance product offerings, encouraging cross-sectoral collaboration, and prioritizing investments in resilience and preventive measures.Originality/valueBy broadening the sustainability discussion to encompass economic and technological facets, this paper enriches the dialogue surrounding the insurance industry's role in sustainability. It aims to inform decision-makers across the industry, political spheres, and broader society about the necessity of sustainability, fostering pertinent political discussions and highlighting avenues for future research.
The development of new technologies and big data analytics tools has had a profound impact on the insurance industry. A new wave of insurance economics research has emerged to study the changes and challenges those big data analytics developments engendered on the insurance industry. We provide a comprehensive literature review on big data, risk classification, and privacy in insurance markets, and discuss avenues for future research. Our study is complemented by an application of the use of big data in risk classification, considering individuals' privacy preferences. We propose a framework for analyzing the trade-off between the accuracy of risk classification and the discount offered to policyholders as an incentive to share private data. Furthermore, we discuss the conditions under which using policyholders' private data to classify risks more accurately is profitable for an insurer. In particular, we find that improving the accuracy of risk classification, if achieved by requiring the use of private data, does not necessarily provide an incentive for insurers to create more granular risk classes.
This study investigates whether cyber loss events occurring in the United States are spatially correlated and if so, which socioeconomic factors are associated with the spatial correlation. We analyze 3132 counties of the 50 U.S. states from 2005 to 2020 using the largest existing dataset of cyber risks and socioeconomic data. While previous literature found no or little spatial correlation at the state level, we are the first to document that such correlation exists at the county level; positive Moran's I indicates that more exposed (i.e., a relatively large number of cyber events and losses) and less exposed counties are clustered. Spatial regressions show positive direct and negative indirect effects of county-level population and average income on loss frequency and severity. Large and wealthy counties thus tend to be more exposed to cyber risk events, but their geographically neighboring counties are less affected. We further investigate relatively exposed regions (California and the Northeast Coast) and three risk types (malicious, unintended, and privacy risks) and show consistent spatial effects for the key variables of population size and average income. Our findings can aid risk managers, cyber insurers, and policymakers to geographically differentiate cyber risk, recognize relatively more exposed regions, and develop more effective risk management strategies.
We focus on the fundamental tradeoff between performance and explainability in machine learning algorithms. This tradeoff is well established in the computer science literature but has not yet been explored in the insurance literature. We consider a market where two biased machine learning algorithms, subject to a performance-explainability tradeoff, compete on price to sell an insurance contract with homogeneous coverage to a large number of buyers, who are differentiated by their loss probabilities. Our findings reveal that the realization of the equilibrium, and thus optimal regulatory policy, is determined by the interplay of the algorithm-specific bias and explainability markdown, as well as the data access range. Policymakers face a tradeoff between premium size and the degree of algorithmic explainability, which can be alleviated by favoring algorithms with decreasing marginal explainability costs.
This study explores how optimism bias influences decision-making in cyber risk management by developing a novel model that reflects utility loss aversion, a factor previously unexplored in this context. We find that decision-makers with self-protection as reference point are less likely to invest in other cyber risk management measures, providing support for optimism bias observed in the cyber-insurance market. We also show that decision-makers with higher loss aversion tend to not invest in other cyber risk management measures. Our results help to explain the lack of demand for cyber-insurance and have important implications for corporate risk management and public policy on cyber risk. They also help better understand cyber risk events which can trigger huge systemic consequences for economies and societies.
Using representative survey data from the Swiss population, we show that pension literacy is different from financial literacy. While both literacy measures are higher among men than women, we observe that financial literacy is largely driven by education, whereas pension literacy increases with age and income. Motivated by the differences between both literacy measures, we extend past research on the effect of culture on financial and pension literacy, an area that has not been considered in a pension context. We identify a significant and robust heterogeneity in pension literacy depending on language regions. The magnitude of the language association is high compared to other control variables. A mediation analysis attributes differences in pension literacy to financial risk preferences and differences in financial literacy to time preferences across cultural groups.
Cyber risk insurance has been introduced for more than two decades in the United States, yet the insurance market for cyber risk is tiny amounting to 1% ($6.5 billion) of premiums in the U.S. property-casualty insurance market in 2021. In this paper, we analyze what constrains the insurance industry from providing larger capacity. We argue that cyber risk is special in that it is both information-intensive to underwrite and heavy-tailed. It leads to the tension between the need to raise large amounts of external capital to finance heavy-tailed risks and the high compensation demanded by capital providers due to information frictions. Hence, the suppliers are large insurance groups with a deep internal capital market, and their capacity is constrained. We start by providing empirical evidence that the cyber risk insurance market is dominated by large insurance groups and that, compared to other types of insurance, cyber insurance relies heavily on the groups' internal capital market. Then, using an exogenous shock on the tax treatment of the non-U.S. affiliated reinsurance in 2017, we establish the causal inference that insurers primarily rely on the internal capital market to supply cyber risk insurance.
We develop a model of insurance markets in the presence of globally-diversifiable and globally-undiversifiable risk. A firm seeks coverage from an insurer who, in turn, may purchase reinsurance and/or place excess risk in the capital market. Securitization through cat bonds preserves private-sector risk sharing for globally-diversifiable risk. For globally-undiversifiable risk, however, the firm's probability of default can only be curtailed through government intervention. We show that an ex-ante government backstop in the highest loss layers dominates other interventions, particularly an ex-post disaster relief program because it maximizes the risk borne by the private sector.
This is the third special issue of The Geneva Papers on Risk and Insurance-Issues and Practice devoted to cyber risk and cyber insurance (previous issues were published in April 2018 and October 2020).Interest in the topic of cyber risk and cyber risk insurance has been increasing over the last years, both in industry and academia.We document a steady growth of academic research on cyber risk and cyber risk insurance (see Fig. 1 in "Appendix 1"), not only in computer science but also increasingly in business and economics (see Fig. 2 in "Appendix 2").There have also been top publications in finance, economics and management journals focussing on market reactions to cyber risk events (Kamiya et al. 2021;Foerderer and Schuetz 2022;Florackis et al. 2023) and potential systemic risks arising from such events (August et al. 2022;Eisenbach et al. 2022;Crosignani et al. 2023).Yet, insurance is not a major component of this research.With this special issue, we contribute to this emerging field of literature with seven articles.Two of them focus on ransomware insurance, while three consider cyber loss modelling.The remaining two consider cyber risk management in general, with one paper looking at the coordination of cybersecurity management and the other at risk mitigation and optimal contract design for cyber insurance As in the two previous special issues, the articles come from different methodological backgrounds and focus on different industries.This editorial summarises the papers included in this special issue and then highlights some potential avenues for future research.The goal of the issue is to not only present new contributions on one of the timeliest topics in research and practice but also to stimulate future research on cyber risk and cyber risk insurance.The first paper by Tom Baker and Anja Shortland collects interview data from 25 insurance, legal, security and policy professionals to study how insurers address the problems of moral hazard, uncertainty and correlated losses when selling and
This paper utilizes three large databases to better understand the characteristics of cyber loss events, especially how to deal with data biases and how cyber losses evolve over time. We first deal with the problem of report delay with an extended two-stage model in combination with detailed information in our data. Then we analyze the frequency and severity of different categories of cyber events (such as malicious and negligent events) using state-of-art statistical methods for the detection of structural changes. We document that the frequency is increasing rapidly with the malicious cyber events growing exponentially in the past two decades but there is no significant change in loss severity. We also explore the tail dynamics and find that the heavy-tailedness of cyber events is persistent over time. Finally, we develop a conceptual model with the documented empirical features (delayed information and heavy-tailedness) and show that they lead to significantly lower insurance demand. This might help explain the low volume of the cyber insurance market observed today.