英文_guidewire_2025年美国网络行业暴露数据库和损失曲线_31页_8mb
报告摘要
2025 US Cyber Industry Exposure Database and Loss Curve Summary
Core Content
This document presents the 2025 US Cyber Industry Exposure Database and Loss Curve (IED), a collaborative effort between Guidewire Cyence and Guy Carpenter (GC). The IED is designed to provide updated and detailed cyber risk exposure metrics for the US market, including Occurrence Exceedance Probabilities (OEP) and Aggregate Exceedance Probabilities (AEP). It serves as a critical tool for financial and insurance markets to assess potential losses and adjust risk transfer strategies accordingly.
The IED reflects the evolving cyber risk landscape in 2025, influenced by federal deregulation, defunding of key cyber agencies, increased nation-state cyber activity, and ongoing foreign conflicts. These factors are expected to increase the overall risk level in the cyber industry compared to 2024.
Main Findings
- 1-in-100 Loss: Estimated at $9.94B (Occurrence) and $16.53B (Aggregate), with a loss ratio of 174%.
- 1-in-250 Loss: Estimated at $17.23B (Occurrence) and $24.42B (Aggregate), with a loss ratio of 257%.
- Expected Loss: $5.05B annually.
- Projected Annual Written Premium: $9.52B, leading to a loss ratio of 53%.
- Loss Ratio Composition: 42% attritional and 11% cat (catastrophic) losses.
- Top Sectors by Exposure:
- Manufacturing, Financial Services, and Retail Trade are the most exposed in extreme tail events.
- Top Revenue Bands by Exposure:
- SMEs (<$20M revenue) are the largest group in terms of policy count, with 98.7% of the total 4.97 million policies.
- Mega-sized businesses (> $10B revenue) are 465 in number.
- Tail Event Types:
- Mass Ransom events dominate the extreme tail, contributing to the highest loss scenarios.
- Mass Data Breach and Cloud Provider Outages are also significant contributors.
Key Metrics and Statistics
- OEP and AEP VaR Curves:
- The 1-in-50 OEP loss is $13.2B, with 1-in-100 at $16.5B.
- TVaR (Tail Value at Risk) for the 1-in-100 event is $19.25B, with Manufacturing and Financial Services contributing the most.
- TVaR by Sector:
- Manufacturing and Financial Services show the steepest increases in tail contributions due to their high interruption duration and average net income per unit time.
- TVaR by Revenue Band:
- SMEs contribute the majority of losses in the largest tail events.
- Large and Mega firms also play a significant role due to the high severity of events.
- Comparison to NotPetya:
- The NotPetya event (2017) was the largest insured cyber event with an estimated loss of $3B (equivalent to $4B in 2025 terms).
- A 1-in-100 loss ratio of 174% would require an event 2.5–3 times larger than NotPetya.
- NotPetya impacted only 2,300 businesses, primarily in Ukraine, due to the narrow scope of the vulnerability.
Methodology Overview
- IED Form and Scope:
- The IED is a bottom-up model that estimates potential extreme cyber loss scenarios.
- It includes both OEP and AEP curves, along with loss ratio and written premium estimates.
- Policy Population:
- The IED uses NAICS code categories and revenue bands to define the US business population.
- The base data is sourced from the US Census Bureau and adjusted to match Cyence's granularity.
- Take-up Rates:
- Standalone take-up rates increase with revenue band size.
- Package/endorsement rates decrease and are generally absent in mega-sized firms.
- Limitations:
- Unknown revenue for 10% of businesses is manually distributed.
- Broad revenue groupings are subdivided into more granular bands.
- Subsidiaries are excluded to avoid double-counting.
- Non-employer businesses are excluded, but their potential inclusion is considered through package policy take-up rate inflation.
Implications for the Cyber Insurance Market
- A 174% loss ratio is considered a severe but plausible event, likely to result in rapid rate hardening.
- Reinsurance appetite is expected to shift toward cat event protection, including:
- Excess of Loss (XOL)
- Hybrid XOL + Aggregate Stop Loss (ASL)
- Cyber cat bonds
- Industry Loss Warranty (ILW)
- Parametric covers
- Market Dynamics:
- Ransomware and BEC attacks have increased in frequency.
- AI advancements have made phishing more sophisticated, increasing BEC attack frequency.
- Geopolitical tensions, particularly US-Russia and US-China, may lead to increased cyber attacks.
- Commercial reliance on SaaS/PaaS providers has led to single point of failure (SPOF) events with high severity.
- Cloud service providers like AWS are still vulnerable to nation-state attacks, especially in the US.
Future Iterations
- The IED is planned for global expansion beyond the US.
- Cyence Model 8 will be the next version, incorporating additional functionality and refined granularity, especially in SME revenue band segmentation.
- Regular updates and new version releases are expected to enhance the IED's utility for the financial and insurance markets.
Conclusion
The IED provides a transparent and detailed view of the US cyber risk landscape, incorporating historical data, current market conditions, and future risk modeling. It highlights the increased risk due to regulatory changes, geopolitical tensions, and technological advancements, while also offering insights into the feasibility of extreme loss scenarios. The collaboration between Cyence and GC aims to foster trust and comfort in the model through open discussions and continuous improvements.
试读结束,高清完整版pdf/doc/ppt,请点下载