Cyber risk has evolved from a niche operational hazard into one of the most consequential and least tractable classes of insurable risk. Insurers continue to rely largely on heuristic and experience-rated underwriting, while the academic literature has produced a rapidly expanding but fragmented body of quantitative models. This review synthesises the peer-reviewed literature on cyber risk quantification and cyber insurance pricing, drawing on a structured search of scholarly databases that returned 199 records, from which 102 studies are critically reviewed. The literature is organised into eight themes: the statistical properties of cyber losses; actuarial and mathematical pricing models; dependence modelling and systemic risk; machine-learning approaches to incident prediction and underwriting; technical risk-assessment frameworks and control-based premium adjustment; the economics of cyber insurance markets; sectoral heterogeneity in cyber exposure; and methods for modelling under data scarcity. Across themes, four persistent findings emerge: cyber losses are heavy-tailed and dynamically non-stationary; dependence among losses undermines classical portfolio diversification and is systematically under-modelled in practice; technical vulnerability metrics and financial loss models remain poorly integrated; and virtually all empirical evidence derives from United States loss databases, leaving emerging markets and firm-level primary data almost unexamined. These gaps motivate an integrated, industry-specific research agenda that couples asset-centric technical assessment (CVSS, FAIR, ISO/NIST alignment) with neural-network incident probability estimation, copula-based dependence modelling and explicit actuarial premium construction. The review concludes by positioning such a framework against the state of the art and identifying the contribution it would make to actuarial science, underwriting practice and regulation.
| Published in | International Journal of Accounting, Finance and Risk Management (Volume 11, Issue 3) |
| DOI | 10.11648/j.ijafrm.20261103.13 |
| Page(s) | 138-147 |
| Creative Commons |
This is an Open Access article, distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution and reproduction in any medium or format, provided the original work is properly cited. |
| Copyright |
Copyright © The Author(s), 2026. Published by Science Publishing Group |
Cyber Risk, Cyber Insurance, Risk-based Pricing, Heavy Tails, Copula Models, Neural Networks, Systemic Risk
NIST | National Institute of Standards and Technology |
FAIR | Factor Analysis of Information Risk |
CVSS | Common Vulnarability Scoring System |
SCADA | Supervisory Control and Data Acquisition |
OCTAVE | Operationally Critical Threat, Asset and Vulnerability Evaluation |
| [1] | Acquisti, A., Friedman, A. and Telang, R. (2006). Is there a cost to privacy breaches? An event study. Proceedings of the International Conference on Information Systems / Workshop on the Economics of Information Security. |
| [2] | Aksu, M. U., et al. (2017). A quantitative CVSS-based cyber security risk assessment methodology for IT systems. Proceedings of the International Carnahan Conference on Security Technology (ICCST). |
| [3] | Antonio, Y., et al. (2021a). Pricing of cyber insurance premiums using a Markov-based dynamic model with clustering structure. PLoS ONE, 16. |
| [4] | Antonio, Y., et al. (2021b). Cyber insurance ratemaking: A graph mining approach. Risks, 9. |
| [5] | Argaw, S. T., et al. (2020). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 20. |
| [6] | Awiszus, K., et al. (2023). Modeling and pricing cyber insurance: Idiosyncratic, systematic, and systemic risks. European Actuarial Journal, 13. |
| [7] | Baker, T. and Shortland, A. (2022). Insurance and enterprise: Cyber insurance for ransomware. The Geneva Papers on Risk and Insurance - Issues and Practice, 48. |
| [8] | Bardopoulos, J. (2025). Cyber-insurance pricing models. British Actuarial Journal, 30. |
| [9] | Barons, M. J., et al. (2021). Balancing the elicitation burden and the richness of expert input when quantifying discrete Bayesian networks. Risk Analysis, 42. |
| [10] | Benz, M. and Chatterjee, D. (2020). Calculated risk? A cybersecurity evaluation tool for SMEs. Business Horizons, 63. |
| [11] | Biener, C., Eling, M. and Wirfs, J. H. (2014). Insurability of cyber risk: An empirical analysis. The Geneva Papers on Risk and Insurance - Issues and Practice, 40. |
| [12] | Bilen, A. and Ozer, A. B. (2021). Cyber-attack method and perpetrator prediction using machine learning algorithms. PeerJ Computer Science, 7. |
| [13] | Bohme, R. (2005). Cyber-insurance revisited. Proceedings of the Workshop on the Economics of Information Security (WEIS). |
| [14] | Bolot, J. and Lelarge, M. (2008). Cyber insurance as an incentive for IT security. Proceedings of the Workshop on the Economics of Information Security (WEIS). |
| [15] | Bouveret, A. (2019). Estimation of losses due to cyber risk for financial institutions. Journal of Operational Risk, 14. |
| [16] | Braun, A., et al. (2023). Cyber insurance-linked securities. ASTIN Bulletin, 53. |
| [17] | Campbell, K., et al. (2003). The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security, 11. |
| [18] | Carannante, M., et al. (2023). Vine copula modelling dependence among cyber risks: A dangerous regulatory paradox. SSRN Working Paper. |
| [19] | Carannante, M., et al. (2025). An analytical review of cyber risk management by insurance companies: A mathematical perspective. Risks, 13. |
| [20] | Cavusoglu, H., Mishra, B. and Raghunathan, S. (2004). The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers. International Journal of Electronic Commerce, 9. |
| [21] | Celeny, D., et al. (2024). Prioritizing investments in cybersecurity: Empirical evidence from an event study on the determinants of cyberattack costs. SSRN Working Paper. |
| [22] | Choi, S. J., et al. (2021). The relationship between cybersecurity ratings and the risk of hospital data breaches. Journal of the American Medical Informatics Association, 28. |
| [23] | Chong, W. F., et al. (2023). Incident-specific cyber insurance. ASTIN Bulletin, 53. |
| [24] | Constantinou, A., Fenton, N. and Neil, M. (2016). Integrating expert knowledge with data in Bayesian networks: Preserving data-driven expectations when the expert variables remain unobserved. Expert Systems with Applications, 56. |
| [25] | Coventry, L. and Branley, D. (2018). Cybersecurity in healthcare: A narrative review of trends, threats and ways forward. Maturitas, 113. |
| [26] | Cremer, F., et al. (2024a). Enhancing cyber insurance strategies: Exploring reinsurance and alternative risk transfer approaches. Journal of Cybersecurity, 10. |
| [27] | Cremer, F., et al. (2024b). Bridging the cyber protection gap: An investigation into the efficacy of the German cyber insurance market. Risk Management and Insurance Review, 27. |
| [28] | Dacorogna, M., et al. (2022). Building up cyber resilience by better grasping cyber risk via a new algorithm for modelling heavy-tailed data. European Journal of Operational Research, 311. |
| [29] | Doss, S., et al. (2026). Development of an aggregate model for cyber risk assessment using deep neural network and structural equation modelling. International Journal of Finance and Economics. |
| [30] | Dou, W., et al. (2020). An insurance theory based optimal cyber-insurance contract against moral hazard. Information Sciences, 527. |
| [31] | Dusane, H. N., et al. (2025). Evaluating cyber risk insurance frameworks: Bridging cybersecurity threats with financial risk strategies through actuarial modeling and adaptive resilience. Proceedings of the IEEE International Conference on Blockchain and Distributed Systems Security (ICBDS). |
| [32] | Edwards, B., Hofmeyr, S. and Forrest, S. (2016). Hype and heavy tails: A closer look at data breaches. Journal of Cybersecurity, 2. |
| [33] | Eling, M. and Jung, K. (2018). Copula approaches for modeling cross-sectional dependence of data breach losses. Insurance: Mathematics and Economics, 82. |
| [34] | Eling, M. and Jung, K. (2022). Unraveling heterogeneity in cyber risks using quantile regressions. Insurance: Mathematics and Economics, 104. |
| [35] | Eling, M., et al. (2023a). The supply of cyber risk insurance. SSRN Working Paper. |
| [36] | Eling, M., et al. (2023b). Time dynamics of cyber risk. SSRN Working Paper. |
| [37] | Eling, M., et al. (2025). The changing landscape of cyber risk: An empirical analysis of loss severity and tail dynamics. Insurance: Mathematics and Economics. |
| [38] | Fahrenwaldt, M., Weber, S. and Weske, K. (2018). Pricing of cyber insurance contracts in a network model. ASTIN Bulletin, 48. |
| [39] | Fang, X., et al. (2019). A deep learning framework for predicting cyber attacks rates. EURASIP Journal on Information Security, 2019. |
| [40] | Ganin, A., et al. (2020). Multicriteria decision framework for cybersecurity risk assessment and management. Risk Analysis, 40. |
| [41] | Gatzlaff, K. M. and McCullough, K. A. (2010). The effect of data breaches on shareholder wealth. Risk Management and Insurance Review, 13. |
| [42] | Goel, S. and Shawky, H. A. (2009). Estimating the market impact of security breach announcements on firm values. Information and Management, 46. |
| [43] | Guo, J., et al. (2025). Entity-specific cyber risk assessment using InsurTech empowered risk factors. arXiv preprint. |
| [44] | Hanea, A., et al. (2022). Bayesian networks for risk analysis and decision support. Risk Analysis, 42. |
| [45] | Herath, H. S. B. and Herath, T. C. (2011). Copula-based actuarial model for pricing cyber-insurance policies. Insurance Markets and Companies: Analyses and Actuarial Computations, 2. |
| [46] | Hillairet, C., et al. (2021a). An expansion formula for Hawkes processes and application to cyber-insurance derivatives. Stochastic Processes and their Applications, 143. |
| [47] | Hillairet, C. and Lopez, O. (2021). Propagation of cyber incidents in an insurance portfolio: Counting processes combined with compartmental epidemiological models. Scandinavian Actuarial Journal, 2021. |
| [48] | Howland, H. (2021). CVSS: Ubiquitous and broken. Digital Threats: Research and Practice, 4. |
| [49] | Humayun, M., et al. (2020). Internet of things and ransomware: Evolution, mitigation and prevention. Egyptian Informatics Journal, 22. |
| [50] | Ismail, S. M., et al. (2025). Cyber insurance pricing through Monte Carlo simulation: A case study of the Egyptian insurance market. Journal of Administrative, Financial and Quantitative Research. |
| [51] | Jalali, M. S. and Kaiser, J. P. (2018). Cybersecurity in hospitals: A systematic, organizational perspective. Journal of Medical Internet Research, 20. |
| [52] | Jeamaon, A., et al. (2026). Aggregate cyber loss modeling with TVaR-constrained premium optimization: A Monte Carlo framework with spliced severity and systemic dependence. Proceedings of the IEEE International Conference on Cybernetics and Innovations (ICCI). |
| [53] | Jung, K. (2021). Extreme data breach losses: An alternative approach to estimating probable maximum loss for data breach risk. North American Actuarial Journal, 25. |
| [54] | Keskin, O., et al. (2021). Scoring cyber vulnerabilities based on their impact on organizational goals. Proceedings of the Systems and Information Engineering Design Symposium (SIEDS). |
| [55] | Khalili, M. M., Naghizadeh, P. and Liu, M. (2017). Designing cyber insurance policies: Mitigating moral hazard through security pre-screening. Proceedings of GameNets / International Conference on Game Theory for Networks. |
| [56] | Koley, J. (2025). Emerging trends and challenges in India's cyber insurance sector: A multifaceted examination. International Journal of Financial Management and Economics, 8. |
| [57] | Lelarge, M. and Bolot, J. (2009). Economic incentives to increase security in the internet: The case for insurance. Proceedings of IEEE INFOCOM 2009. |
| [58] | Lu, Y., et al. (2024). Cyber risk modeling: A discrete multivariate count process approach. Scandinavian Actuarial Journal, 2024. |
| [59] | Maillart, T. and Sornette, D. (2008). Heavy-tailed distribution of cyber-risks. The European Physical Journal B, 75. |
| [60] | Marotta, A., et al. (2017). Cyber-insurance survey. Computer Science Review, 24. |
| [61] | Mell, P., Scarfone, K. and Romanosky, S. (2006). Common Vulnerability Scoring System. IEEE Security and Privacy, 4. |
| [62] | Mott, G., et al. (2023). Between a rock and a hard (ening) place: Cyber insurance in the ransomware era. Computers and Security, 128. |
| [63] | Muktadir-Al-Mukit, D., et al. (2025). The dynamics of stock market responses following the cyber-attacks news: Evidence from event study. Information Systems Frontiers. |
| [64] | Mukhopadhyay, A., et al. (2024). A framework for cyber-risk insurance against ransomware: A mixed-method approach. International Journal of Information Management, 74. |
| [65] | Nankya, M., et al. (2023). Securing industrial control systems: Components, cyber threats, and machine learning-driven defense strategies. Sensors, 23. |
| [66] | Ning, D. (2026). Selection and screening in cyber insurance markets. SSRN Working Paper. |
| [67] | Nwafor, C., et al. (2025). A hybrid FAIR and XGBoost framework for cyber-risk intelligence and expected loss prediction. Expert Systems with Applications. |
| [68] | Pal, R., et al. (2021a). Will catastrophic cyber-risk aggregation thrive in the IoT age? A cautionary economics tale for (re-) insurers and likes. ACM Transactions on Management Information Systems, 12. |
| [69] | Pal, R., et al. (2021b). Aggregate cyber-risk management in the IoT age: Cautionary statistics for (re) insurers and likes. IEEE Internet of Things Journal, 8. |
| [70] | Peng, C., et al. (2018). Modeling multivariate cybersecurity risks. Journal of Applied Statistics, 45. |
| [71] | Peters, G. W., et al. (2022). Cyber loss model risk translates to premium mispricing and risk sensitivity. The Geneva Papers on Risk and Insurance - Issues and Practice, 48. |
| [72] | Podofillini, L., et al. (2022). A traceable process to develop Bayesian networks from scarce data and expert judgment: A human reliability analysis application. Reliability Engineering and System Safety, 230. |
| [73] | Portela, D., et al. (2022). Economic impact of a hospital cyberattack in a national health system: Descriptive case study. JMIR Formative Research, 7. |
| [74] | Radanliev, P., et al. (2018). Economic impact of IoT cyber risk: Analysing past and present to predict the future developments in IoT risk analysis and IoT cyber insurance. arXiv preprint. |
| [75] | Ren, N., et al. (2025). The modeling of cyber risk insurance by Hawkes processes with loss covariate. Applied Stochastic Models in Business and Industry, 41. |
| [76] | Sahai, R., et al. (2023). Insurance risk prediction using machine learning. Proceedings of the International Conference on Data Science and Applications. |
| [77] | Salzberger, A. (2025). An empirical analysis of the behavioral influences and information sources affecting the cyber insurance decisions of German SMEs. The Journal of Risk Finance, 26. |
| [78] | Samia, N., et al. (2024). Predicting and mitigating cyber threats through data mining and machine learning. Computer Communications, 216. |
| [79] | Shetty, N., et al. (2010). Competitive cyber-insurance and internet security. In: Moore, T., Pym, D. and Ioannidis, C. (eds.) Economics of Information Security and Privacy. Springer. |
| [80] | Shevchenko, P. V., et al. (2021). Quantification of cyber risk: Risk categories and business sectors. SSRN Working Paper. |
| [81] | Shevchenko, P. V., et al. (2022). The nature of losses from cyber-related events: Risk categories and business sectors. Journal of Cybersecurity, 9. |
| [82] | Shin, J., Son, H. and Heo, G. (2015). Development of a cyber security risk model using Bayesian networks. Reliability Engineering and System Safety, 134. |
| [83] | Skeoch, H. (2021). Expanding the Gordon-Loeb model to cyber-insurance. Computers and Security, 112. |
| [84] | Skeoch, H. and Bohme, R. (2023). The barriers to sustainable risk transfer in the cyber-insurance market. Journal of Cybersecurity, 9. |
| [85] | Skeoch, H., et al. (2023). Pricing cyber-insurance for systems via maturity models. arXiv preprint. |
| [86] | Spring, J. M., et al. (2021). Time to change the CVSS? IEEE Security and Privacy, 19. |
| [87] | Strupczewski, G. (2019). What is the worst scenario? Modeling extreme cyber losses. In: Multiple Perspectives in Risk and Risk Management. Springer Proceedings in Business and Economics. |
| [88] | Subramaniam, B., et al. (2023). What ails cyber insurance? An analysis of barriers and drivers using fuzzy TOPSIS method. SN Computer Science, 4. |
| [89] | Sun, H., Xu, M. and Zhao, P. (2020). Modeling malicious hacking data breach risks. North American Actuarial Journal, 25. |
| [90] | Tripathi, M. and Mukhopadhyay, A. (2020). Financial loss due to a data privacy breach: An empirical analysis. Journal of Organizational Computing and Electronic Commerce, 30. |
| [91] | Uflaz, E., et al. (2023). Quantifying potential cyber-attack risks in maritime transportation under Dempster-Shafer theory FMECA and rule-based Bayesian network modelling. Reliability Engineering and System Safety, 243. |
| [92] | von Skarczinski, B. S., et al. (2023). Modelling maximum cyber incident losses of German organisations: An empirical study and modified extreme value distribution approach. The Geneva Papers on Risk and Insurance - Issues and Practice, 48. |
| [93] | Wang, J., Neil, M. and Fenton, N. (2020). A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model. Computers and Security, 89. |
| [94] | Wang, S. S. (2019). Integrated framework for information security investment and cyber insurance. Pacific-Basin Finance Journal, 57. |
| [95] | Wasserman, L. and Wasserman, Y. (2022). Hospital cybersecurity risks and gaps: Review (for the non-cyber professional). Frontiers in Digital Health, 4. |
| [96] | Welburn, J. W. and Strong, A. M. (2021). Systemic cyber risk and aggregate impacts. Risk Analysis, 42. |
| [97] | Wheatley, S., Hofmann, A. and Sornette, D. (2020). Addressing insurance of data breach cyber risks in the catastrophe framework. The Geneva Papers on Risk and Insurance - Issues and Practice, 46. |
| [98] | Woods, D. W., Bohme, R. and Moore, T. (2021). The county fair cyber loss distribution: Drawing inferences from insurance prices. Digital Threats: Research and Practice, 2. |
| [99] | Wu, M. Z., et al. (2021). Modeling multivariate cyber risks: Deep learning dating extreme value theory. Journal of Applied Statistics, 50. |
| [100] | Xu, M. and Hua, L. (2019). Cybersecurity insurance: Modeling and pricing. North American Actuarial Journal, 23. |
| [101] | Yang, Z., et al. (2020). Premium calculation for insurance businesses based on cyber risks in IP-based power substations. IEEE Access, 8. |
| [102] | Zeller, G. and Scherer, M. (2021). A comprehensive model for cyber risk based on marked point processes and its application to insurance. European Actuarial Journal, 12. |
| [103] | Zeller, G. and Scherer, M. (2024). Is accumulation risk in cyber methodically underestimated? European Actuarial Journal, 14. |
| [104] | Zhang, Q., et al. (2018). A fuzzy probability Bayesian network approach for dynamic cybersecurity risk assessment in industrial control systems. IEEE Transactions on Industrial Informatics, 14. |
APA Style
Narasimhan, R. (2026). Quantifying Cyber Risk Exposure and Risk-Based Pricing of Cyber Insurance: A Thematic Review of Actuarial, Statistical and Machine-Learning Approaches. International Journal of Accounting, Finance and Risk Management, 11(3), 138-147. https://doi.org/10.11648/j.ijafrm.20261103.13
ACS Style
Narasimhan, R. Quantifying Cyber Risk Exposure and Risk-Based Pricing of Cyber Insurance: A Thematic Review of Actuarial, Statistical and Machine-Learning Approaches. Int. J. Account. Finance Risk Manag. 2026, 11(3), 138-147. doi: 10.11648/j.ijafrm.20261103.13
@article{10.11648/j.ijafrm.20261103.13,
author = {Raveendran Narasimhan},
title = {Quantifying Cyber Risk Exposure and Risk-Based Pricing of Cyber Insurance: A Thematic Review of Actuarial, Statistical and Machine-Learning Approaches},
journal = {International Journal of Accounting, Finance and Risk Management},
volume = {11},
number = {3},
pages = {138-147},
doi = {10.11648/j.ijafrm.20261103.13},
url = {https://doi.org/10.11648/j.ijafrm.20261103.13},
eprint = {https://article.sciencepublishinggroup.com/pdf/10.11648.j.ijafrm.20261103.13},
abstract = {Cyber risk has evolved from a niche operational hazard into one of the most consequential and least tractable classes of insurable risk. Insurers continue to rely largely on heuristic and experience-rated underwriting, while the academic literature has produced a rapidly expanding but fragmented body of quantitative models. This review synthesises the peer-reviewed literature on cyber risk quantification and cyber insurance pricing, drawing on a structured search of scholarly databases that returned 199 records, from which 102 studies are critically reviewed. The literature is organised into eight themes: the statistical properties of cyber losses; actuarial and mathematical pricing models; dependence modelling and systemic risk; machine-learning approaches to incident prediction and underwriting; technical risk-assessment frameworks and control-based premium adjustment; the economics of cyber insurance markets; sectoral heterogeneity in cyber exposure; and methods for modelling under data scarcity. Across themes, four persistent findings emerge: cyber losses are heavy-tailed and dynamically non-stationary; dependence among losses undermines classical portfolio diversification and is systematically under-modelled in practice; technical vulnerability metrics and financial loss models remain poorly integrated; and virtually all empirical evidence derives from United States loss databases, leaving emerging markets and firm-level primary data almost unexamined. These gaps motivate an integrated, industry-specific research agenda that couples asset-centric technical assessment (CVSS, FAIR, ISO/NIST alignment) with neural-network incident probability estimation, copula-based dependence modelling and explicit actuarial premium construction. The review concludes by positioning such a framework against the state of the art and identifying the contribution it would make to actuarial science, underwriting practice and regulation.},
year = {2026}
}
TY - JOUR T1 - Quantifying Cyber Risk Exposure and Risk-Based Pricing of Cyber Insurance: A Thematic Review of Actuarial, Statistical and Machine-Learning Approaches AU - Raveendran Narasimhan Y1 - 2026/09/18 PY - 2026 N1 - https://doi.org/10.11648/j.ijafrm.20261103.13 DO - 10.11648/j.ijafrm.20261103.13 T2 - International Journal of Accounting, Finance and Risk Management JF - International Journal of Accounting, Finance and Risk Management JO - International Journal of Accounting, Finance and Risk Management SP - 138 EP - 147 PB - Science Publishing Group SN - 2578-9376 UR - https://doi.org/10.11648/j.ijafrm.20261103.13 AB - Cyber risk has evolved from a niche operational hazard into one of the most consequential and least tractable classes of insurable risk. Insurers continue to rely largely on heuristic and experience-rated underwriting, while the academic literature has produced a rapidly expanding but fragmented body of quantitative models. This review synthesises the peer-reviewed literature on cyber risk quantification and cyber insurance pricing, drawing on a structured search of scholarly databases that returned 199 records, from which 102 studies are critically reviewed. The literature is organised into eight themes: the statistical properties of cyber losses; actuarial and mathematical pricing models; dependence modelling and systemic risk; machine-learning approaches to incident prediction and underwriting; technical risk-assessment frameworks and control-based premium adjustment; the economics of cyber insurance markets; sectoral heterogeneity in cyber exposure; and methods for modelling under data scarcity. Across themes, four persistent findings emerge: cyber losses are heavy-tailed and dynamically non-stationary; dependence among losses undermines classical portfolio diversification and is systematically under-modelled in practice; technical vulnerability metrics and financial loss models remain poorly integrated; and virtually all empirical evidence derives from United States loss databases, leaving emerging markets and firm-level primary data almost unexamined. These gaps motivate an integrated, industry-specific research agenda that couples asset-centric technical assessment (CVSS, FAIR, ISO/NIST alignment) with neural-network incident probability estimation, copula-based dependence modelling and explicit actuarial premium construction. The review concludes by positioning such a framework against the state of the art and identifying the contribution it would make to actuarial science, underwriting practice and regulation. VL - 11 IS - 3 ER -