Systemic cyber risks and insurance regulatory capital
摘要
Systemic cyber risk can cascade across interconnected networks, generating substantial Incurred But Not Reported (IBNR) losses that threaten insurers’ capital adequacy. We present a tractable scenario-based framework for assessing how systemic cyber contagion, reporting delays, and operational resilience can affect cyber IBNR losses and solvency capital requirements under stylized assumptions. This framework employs a stochastic epidemic method (susceptible-infected-recovered model) with the parameters of firms’ operational resilience and sectoral network structure and is intended as a diagnostic device and a stress-testing tool that links contagion timing to capital adequacy. Our analysis shows that firms with more resilient operations may be able to recognize losses more quickly, leading to shorter reporting delays and consequently higher IBNR in the early stages, whereas less resilient firms have longer reporting delays, causing their claims to increase over time. We also find that sectoral comparison reveals more severe systemic impacts in the financial industry than in the information industry, and that large insurers can maintain adequate solvency buffers, whereas smaller insurers may face solvency pressures. These findings highlight the need to incorporate IBNR, operational resilience, and network topology in insurance regulatory models to capture systemic cyber losses.