INSURTECH · CYBER ACCUMULATION · T461 cat-30

Cyber Insurance Accumulation & PML Modeler

Estimate portfolio-level cyber insurance Probable Maximum Loss (PML) at multiple return periods by scenario type, using published industry severity curves by sector and coverage trigger. Model accumulation risk, set aggregate limits, and stress-test the book against systemic cyber events: without transmitting any real policyholder data.

🔒Zero PII
📡No server calls
💻Client-side
📋Lloyd's / NAIC Cyber Framework
Cyber PML Accumulation Risk Lloyd's RDS Return Periods Tail Risk Systemic Event IBM / Ponemon 2024
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
⚠ Synthetic Aggregate Data Only All inputs are synthetic aggregates about your book of business, not individual policyholder data. Do not enter names, policy numbers, company names, or any identifying information. This tool models portfolio-level accumulation; it never needs (and must never receive) record-level data.
A: Book Composition (aggregate inputs only)
Count of cyber policies in force
Used for severity band scaling
Skews the effective severity band
Applies a published sector severity multiplier
Self-insured retention
For loss ratio stress
Maximum possible loss to the portfolio; the PML denominator
Coverage Trigger Mix: must sum to 100%
Trigger mix total100%
B: Scenario Parameters
Share of book that co-moves in a systemic event
C: Tail Risk Summary
D: PML Heat Map · Scenario × Return Period

Each cell shows combined-adjusted PML in $M (top) and % of aggregate limit (bottom). Cells are colour-coded: green <10% · amber 10–25% · red 25–40% · deep red >40% of aggregate limit.

E: Attritional Expected Loss & Loss Ratio Stress
F: Concentration Indicators
G: Stress Test Panel
H: Caveats & Model Limitations
Severity Reference Data
TriggerSMEMidEnt.
Ransomware$185K$2.1M$18.5M
Data Breach$120K$1.4M$9.4M
Business Interruption$95K$3.2M$28.0M
Funds Transfer Fraud$65K$450K$2.8M
SME <$50M rev · Mid $50M–$1B · Ent. >$1B. Indicative: industry medians, as of source year. 3rd-party liability priced from breach severity.
Sources: IBM Cost of a Data Breach 2024 · IBM/Ponemon 2024 · Lloyd's RDS · FBI IC3 2024.
Systemic PML Scalars (% of portfolio)
Scenario1:101:501:1001:250
Mass ransomware5%18%32%55%
Cloud CSP outage 24h+8%22%38%60%
Critical infra attack3%12%25%45%
Supply chain compromise4%15%28%50%
Indicative: industry medians, as of source year. Mass ransomware = NotPetya-type.
Sources: Lloyd's RDS for Cyber 2024 · CyberCube · WEF Global Cyber Outlook 2024.
About This Tool
IBM / Ponemon: Cost of a Data Breach 2024 Average loss severities by trigger and revenue band. Industry medians; actual experience varies by sector and controls. IBM Cost of a Data Breach 2024
FBI IC3 2024 Annual Report Funds-transfer-fraud / business-email-compromise loss benchmarks. FBI IC3 2024
Lloyd's RDS for Cyber 2024 Realistic Disaster Scenario systemic PML scalars by return period (mass ransomware, cloud outage, critical infrastructure, supply chain). Lloyd's RDS 2024
NAIC Cyber Insurance Supplement US cyber market framework and aggregate-monitoring expectations referenced for accumulation thresholds. NAIC Cyber Framework
WEF Global Cyber Outlook 2024 Supply-chain and systemic cyber correlation context. WEF 2024
Source Notes & Caveats
  1. Severity benchmarks from IBM / Ponemon Institute Cost of a Data Breach Report 2024; FBI Internet Crime Complaint Center (IC3) 2024 Annual Report.
  2. Systemic event scalars from Lloyd's of London Realistic Disaster Scenarios (RDS) for Cyber, 2024 version; WEF Global Cyber Outlook 2024.
  3. All severity figures are industry medians. Actual loss experience varies materially by sector, control environment, and policy form.
  4. PML estimates are scenario-based approximations. Full cyber accumulation modelling requires licensed catastrophe model platforms (CyberCube, Verisk Touchstone, AIR Cyence).
  5. This tool does not capture silent cyber exposure in non-cyber policies.