Silent cyber, unintended coverage embedded in commercial P&C policy forms, carries an industry PML estimated between $10 billion and $250 billion or more depending on the scenario modeled. Most commercial cat models carry it at zero. AI natural-language tools can now scan full wordings, classify cyber-adjacent provisions against benchmark exclusion language, and produce a portfolio-level estimate, which turns an unmeasured exposure into an input a signing actuary has to stand behind.
Key Takeaways
- An industry PML range of $10 billion to $250 billion is a risk communication figure, not a treaty input. It is driven by scenario assumptions about what counts as a covered cyber trigger.
- The July 2024 CrowdStrike update crashed roughly 8.5 million Windows systems and produced at least $10 billion of damage from a faulty update rather than an attack, which is exactly the coverage-determination case forms were silent on.
- Affirmative cyber runs 20 to 30 percent of portfolio premium, with silent exposure surfacing in another 40 to 50 percent of the book that never entered any cyber cat model input.
- The high-confidence classification stratum covers about 85 to 90 percent of a 50,000-account portfolio. The remainder needs manual adjudication, so the output is a range and not a point.
- Non-proportional affirmative cyber reinsurance rates fell 32% risk-adjusted at the April 2026 renewal, which prices the option to convert silent exposure into something a treaty can cover.
The Accumulation Sitting in the Back Book
Silent cyber is not a gap. It is coverage that exists inside property forms, general liability, marine cargo, workers compensation, and D&O programs without either party having agreed that cyber events are included. A commercial property policy written before the mid-2010s says nothing about whether ransomware triggering a business interruption loss is covered, and courts, adjusters, and coverage counsel have answered differently across jurisdictions.
The July 2024 CrowdStrike software update failure showed the shape of it. Roughly 8.5 million Windows systems crashed at once, triggering business interruption claims at airlines, hospitals, financial institutions, and logistics providers, with total estimated damage of at least $10 billion. It was not an attack. Many policies cover software-caused operational failures, many exclude them, and many say nothing, and carriers in the third group faced one coverage question multiplied across thousands of accounts simultaneously.
That is why the actuarial frame is wrong by default. This is an accumulation problem, not a frequency problem, and its loss distribution resembles a cat peril rather than a liability development pattern. PML modeling is the right tool, and PML modeling requires knowing which policies carry the exposure.
Lloyd's addressed the forward book in July 2019 with Market Bulletin Y5258, requiring every policy to affirm or exclude cyber, phased from January 1, 2020 for first-party property damage through to marine, aviation, liability, and specialty by mid-2021. ISO followed with two mandatory commercial property endorsements: CP 10 75 12 20, excluding all loss caused by a cyber incident, and CP 10 76 12 20, excluding cyber-caused loss but preserving coverage for specified ensuing physical causes. Neither mandate reached in-force portfolios, and both left the choice at the account level with underwriters rather than aggregated for actuaries.
What Scanning Produces, and What It Costs to Rely On
Across mixed commercial P&C portfolios, affirmative cyber accounts for 20 to 30 percent of premium while silent exposure appears in another 40 to 50 percent of the book. That residual is what the tools are built to surface.
The method runs natural-language processing across the full document rather than the declarations page, because a commercial property or GL policy runs 40 to 80 pages with endorsements, schedules, and riders. Each provision is scored against a taxonomy built from the ISO model forms, the LMA clause library, and market-standard manuscript wordings, and returns one of three classifications: explicitly excluded, explicitly affirmed, or ambiguous. Ambiguous provisions are flagged for human review rather than auto-classified.
Accuracy is the binding constraint. Classifiers do well on standard ISO language and known manuscript variants, and residual error on novel or heavily customized wordings is a documented concern. The practical output is therefore two-tiered: for a 50,000-account portfolio, a high-confidence stratum covering perhaps 85 to 90 percent of policies, and a remainder requiring underwriter or counsel adjudication. A PML built on an assumption of 100 percent classification accuracy is a point estimate resting on the one input that is known to be imperfect.
The pricing consequence lands at the endorsement fork. CP 10 75 excludes cyber-caused loss regardless of other contributing causes, so silent cyber PML on those accounts is zero subject to residual interpretive risk. CP 10 76 restores coverage where a cyber incident triggers a specified physical cause, so a ransomware attack that fails an industrial control system and starts a fire produces a covered fire loss. That path needs an actuarially credible loss cost.
The loss cost in turn needs an exposure denominator: which policies carry the exception, what property values sit behind them, and how technology-dependent those operations are. Scanning supplies the denominator; without it the rate is set against an unknown base.
Timing makes the choice tractable. Non-proportional affirmative cyber reinsurance rates fell 32% on a risk-adjusted basis at the April 2026 renewal, so a carrier that has converted exposure into explicitly affirmative form can reinsure it at soft-market pricing. A carrier that has not run the scan does not know what it holds and cannot structure the program.
What the Signing Actuary Has to Attest To
The certification question is one of scope. For hurricane and earthquake the scope of an aggregate cat model is usually clear. For cyber it has not been, because silent cyber has never been measured, and measuring it creates the obligation rather than removing it.
Where a carrier has scanned and the silent PML is material but the cat model excludes it, the certification needs a scope limitation disclosure stating what the model covers and what it does not. That is a factual statement about scope rather than a deficiency finding, and it requires the actuary to hold the scanning results.
Where the scan feeds the model, the exercise changes character. Attesting to reasonableness now means assessing whether the classifier's accuracy is sufficient for the purpose, which means understanding the benchmark taxonomy and whether it reflects current ISO and LMA language, the validated error rate in the high-confidence stratum, the adjudication protocol for ambiguous wordings and the volume routed through it, and version control on the engine, since an update can change prior classifications retroactively. None of that is standard cat model validation practice.
The reinsurer has the mirror-image problem, which is why submission quality has started to matter. A reinsurer writing aggregate excess across a cedant's commercial book carries basis risk if the cedant's model excludes silent cyber: a systemic event can exhaust the retention and reach the treaty on losses the treaty was never priced against. Cedants who can document methodology, scope, and accuracy validation are negotiating with something; the rest are not.
The scale gap explains why this stayed invisible. Global cyber insurance gross written premiums reached roughly $15.3 billion in 2024, a market that is priced, rated, and monitored. The silent book sits inside a US commercial P&C premium base well above $300 billion a year, and it has been outside cat accumulation management entirely.
Further Reading
- Mythos Forces Cyber Insurers to Rethink Aggregation Risk and Underwriting Models – How correlated cyber loss scenarios require cat-style modeling approaches rather than frequency-severity frameworks.
- Cyber and AI Liability Converge Into One Digital Risk Line – How CGL AI exclusions and cyber coverage evolution are merging into a single digital risk framework with pricing implications.
- US Cyber Reinsurance Rates Drop 32% at April 2026 Renewals – The soft reinsurance market context that makes converting silent exposure to affirmative coverage economically attractive right now.
- Chubb Cyber Report Shows Large-Account Severity Doubled and Supply Chain Losses Multiplied – The severity and accumulation data that illustrates what silent cyber losses look like when they materialize.
- One Ransomware Gang Drove 40% of Cyber Claims, Skewing Loss Models – Concentration risk in affirmative cyber that parallels the silent cyber accumulation problem in non-cyber books.
Sources
- Kovrr: Announces First Fully Integrated Silent Cyber Risk Solution (Business Wire, October 2018)
- Lloyd's Market Bulletin Y5258 and Y5277: Providing Clarity for Lloyd's Customers on Coverage for Cyber Exposures (Lloyd's, 2019-2020)
- Gen Re: ISO's Cyber Incident Exclusion Endorsements (CP 10 75, CP 10 76) for Commercial Property Forms (October 2020)
- Gen Re: The CrowdStrike Incident: A Wake-Up Call for Insurers? (February 2025)
- Munich Re: Cyber Insurance Risks and Trends 2026
- Google Cloud Blog: Cytora Uses Generative AI to Assess Underwriting Risk (2024)
- Kovrr: Silent Cyber Risk Exposure and Visibility Case Study (2024)
- Reinsurance News: US Cyber Rates Drop 32% at April 1, 2026 (Gallagher Re)
- American Academy of Actuaries Cyber Risk Task Force: Global Cyber Risk Toolkit (2025)
- Guy Carpenter: Silent Cyber: No Longer Silent (July 2020)