One market participant’s disclosed tails, as shares of shareholders’ equity. In the left panel, the horizontal axis is the disclosed figure as a percent of shareholders’ equity: the two deep blue bars are the cyber book’s probabilistic 1‑in‑250 net modeled loss – $651 million at 31 December 2023 against year-end 2023 equity of $3,882.1 million (about 17%), and $461 million at October 2024 against the same year-end 2023 equity (about 12%) – and the green bar is the natural-catastrophe risk appetite for a probabilistic 1‑in‑250 U.S. event, $438.0 million for 2022 against year-end 2022 equity of $2,955.0 million (about 15%); the appetite is a ceiling on modeled net exposure rather than a modeled loss. In the right panel, drawn on its own scale, in multiples of shareholders’ equity, the bar spans the total cyber limits deployed as inferred in the notes – $118.4 billion to $150.0 billion, or about 31 to 39 times shareholders’ equity – with the span reflecting the assumed average premium of $15,000 to $19,000. Dates and denominators differ across bars as stated; all values are disclosures or inferences from disclosures, not observed losses. Sources: the participant’s investor update of October 2024, Solvency and Financial Condition Report 2023, and Annual Reports 2022 and 2023, as cited in the notes.
Looking at the graphic, the likeness in the left panel is the point of caution. As shares of equity, the modeled cyber tail and the modeled natural-catastrophe tail sit side by side, between about one-eighth and one-sixth of equity – and on the page, the two figures carry the same precision. What stands behind them differs in kind. Behind the natural-catastrophe figure lie decades of recorded losses and models grounded in the physics of windstorm and earthquake; wildfire stands apart. Behind the cyber figure lies no comparable record: the modeled loss is what remains of limits amounting to more than 30 times equity after the model’s assumptions about how little of them one event reaches – assumptions the right panel shows to be carrying almost the entire distance. For windstorm and earthquake, the modeled 1‑in‑250 has earned the reliance placed on it; for cyber – as for war and terrorism – it has not yet; and the market’s scenario regimes do not draw the distinction: Lloyd’s realistic disaster scenarios request a modeled loss for windstorm and earthquake, and for cyber and terrorism, in the same form.8 Neither the participant nor the market presents these disclosures in the language of percolation; that reading is this post’s. The figures are model outputs, not observed losses – and for cyber, that is precisely the caution.
What Follows
Above the threshold, the exposure changes in kind, not degree: it is rare, large when it arrives, and correlated across the book. It does not behave like the diversified remainder, where the law of large numbers holds; capital standing behind it bears a risk closer to that of equity than of a pooled book.
The cyber market has built a response into the wording. Under a widespread-event endorsement, an incident is sorted into one of two kinds – a limited-impact event or a widespread event – the latter defined by a common trigger such as a severe shared vulnerability, a software-supply-chain compromise, or the failure of a system on which many policyholders depend.9 Losses from a widespread event are met by a separate, lower sub-limit, set apart from the overall policy limit, so a single event cannot reach the full book at full terms. That sub-limit is the accumulation condition written into the contract: it bounds how much of the book one event can cost – the quantity that the threshold, once crossed, leaves unbounded. Supervisors treat this accumulation as a major challenge of cyber underwriting, driven by shared dependence on cloud providers and software platforms through which a single failure can cascade across many policyholders.10
That response is still being extended, and along the same structural line. In August 2026 the Lloyd’s Market Association confirmed that it is considering a model infrastructure-failure exclusion for cyber policies, developed with its cyber business panel and, like its other model clauses, open to adaptation rather than mandated.11 What such a clause has to define is the set of dependencies whose failure carries the cluster: shared infrastructure on which many policyholders rest at once, where one event could generate claims from “thousands of insureds simultaneously.” Naming that set in the wording is the operation the sub-limit performs on the loss, moved one step earlier – it fixes in the contract what the threshold fixes in the structure. Reinsurers have meanwhile resisted broader critical-infrastructure cover through the soft market, on the account of two of them, so the threshold shows in what the market declines to write as much as in what the wording bounds.
Whether such exposure should be written, and how much of it to retain, the structure does not decide. It fixes something narrower: the point at which the maximum possible loss stops being bounded by the size of any single policyholder and comes to be set by shared dependence.
Next in the series: “Priced for the Worst” – the market for lemons and the retreat from AI cover. Missed the previous article? Read it here.