This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. To find out more about the cookies we use, see our Privacy policy and Cookie Policy.

Choices about cookies

You can choose which analytical, functionality and targeting cookies we can set by clicking on the button(s):

You can also choose to "Reject All" non-essential cookies by clicking the button below. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our website.
Except for essential cookies, all cookies will expire after 12 months.
If you have any questions or concerns about our use of cookies, please send us an email at info@dynarisk.com.


Why Cyber Loss Ratios Are Hard to Predict

Why Cyber Loss Ratios Are So Hard to Predict (and What Pre-Bind Data Changes)

Two risks can look identical at quotation and produce completely different losses. The difference is often visible before binding, if you know where to look.

Most cyber underwriters have seen it happen. Two submissions arrive looking almost the same: same sector, similar revenue, the same limit and the same reassuring answers on the application. Both are bound on comparable terms. A year later, one has been a quiet risk and the other has produced a ransomware claim that wipes out the premium from several others.

Cyber insurers don't expect to avoid every claim. What they need is a book where losses stay within a range that can be understood, priced and managed. That gets difficult when much of the information used to assess a risk is incomplete, self-reported or out of date by the time the policy is bound. The result isn't just imperfect underwriting on individual risks. It's uncertainty that builds across the whole portfolio.

What is a cyber loss ratio?

A cyber loss ratio is the proportion of premium on a book of cyber business that is paid out in claims over a given period. A low, stable ratio suggests that pricing and risk selection are working as intended. A volatile one suggests losses aren't tracking with expectations, even where risks were priced on the best information available at the time. In cyber, that volatility is rarely about claims frequency alone. More often, it reflects the gap between the risk an insurer believed it was writing and the risk it was actually exposed to.

The loss often starts before the policy does

Cyber claims tend to look sudden. A ransomware attack, an exploited service, or compromised credentials that give an attacker access to a critical system. But the conditions behind the loss were often there long before it. Internet-facing systems were misconfigured, credentials were already circulating in criminal marketplaces, and known vulnerabilities sat unpatched. The exposure existed. It just wasn't visible when the risk was written. When that happens, the insurer accepts two things: the underlying cyber risk, and uncertainty about what that risk actually looks like.

The limits of a narrow pre-bind view

Traditional underwriting draws on application data, broker submissions, financials and selected security controls. Each is useful, but none gives a complete or current picture. Applications depend on the accuracy of whoever completes them. Controls are often described at policy level without evidence they're applied consistently. And the external attack surface, which is the part an attacker actually sees, is frequently missing altogether.

Timing makes this worse. A questionnaire completed weeks or months before inception can't reflect a newly exposed service, a fresh credential leak or a vulnerability that has since become exploitable. Pricing models are only as reliable as the data going into them, and when that data is stale, even a sophisticated model can give a false sense of precision.

Why similar risks behave so differently

Go back to those two near-identical submissions. On paper, they're comparable. In reality, one has a well-maintained external environment and no compromised credentials, while the other is running outdated internet-facing software with employee logins already in the hands of threat actors. If underwriting can't see that difference, both risks are treated the same way, and the gap only becomes visible when one of them claims. Repeat that across a book and the portfolio is far less consistent than the underwriting data suggests.

Claims data explains the past, not the present

Historical claims data remains essential. It shows loss frequency, severity, attack methods and sector trends. But it reflects incidents that have already happened, patterns take time to emerge, and it rarely explains why two similar insureds had very different outcomes. Exposure also moves faster than the data used to model it. New vulnerabilities appear, attack techniques become commoditised, and a portfolio can deteriorate well before the loss ratio shows it. By the time claims confirm the trend, the exposure is already embedded in the book.

What better pre-bind data changes

Better data won't make cyber losses perfectly predictable, but it does reduce the amount of risk accepted without proper visibility. That has a practical effect across the underwriting process.

It sharpens risk selection, helping underwriters distinguish between risks that would otherwise look alike and focus investigation where it matters, rather than simply declining anything with a weakness. It supports fairer pricing, because when one organisation has a materially weaker external posture than another, the insurer can respond through premium, terms, deductibles, sublimits or required fixes. Without that, stronger risks end up subsidising weaker ones.

It also creates the chance to fix problems before cover begins. Exposed services, compromised credentials and known vulnerabilities can be flagged and remediated as a condition of binding, improving the risk before it ever enters the portfolio. It brings consistency too, giving teams, brokers and delegated authorities a shared evidence base and clear escalation criteria, so similar exposures are treated in similar ways. And when that data is structured consistently, individual underwriting observations become portfolio insight, showing concentrations of exposed technology, recurring weaknesses and segments where risk quality is slipping.

More data isn't automatically better data

The goal isn't to bury underwriters in alerts. A long list of vulnerabilities and configuration findings can make decisions harder, not easier. Useful risk intelligence needs context: which indicators matter most, how serious they are, whether they're likely to be exploited and what should happen next. It needs to be timely, since a detailed assessment from several months ago may be less useful than a focused view close to binding. And it needs to fit the workflow. If it needs heavy manual interpretation, lives in a separate system or arrives too late to influence the decision, its value drops. Visibility only improves loss performance when it leads to a different action.

Reducing avoidable uncertainty

No insurer can remove volatility from cyber entirely. Novel attacks, systemic events and previously unknown vulnerabilities will always exist. The realistic aim is to reduce avoidable uncertainty by spotting observable exposures before they become claims, and by separating risks that look the same on paper but differ materially in practice. Loss ratios become hard to predict when a portfolio holds more hidden variation than the insurer realises. Better pre-bind visibility doesn't remove that variation, but it makes more of it measurable, and what can be measured can be priced, remediated or declined.

How DynaRisk helps

DynaRisk's Breach Check helps insurers and MGAs assess cyber exposure before binding by surfacing externally observable risks that traditional application data often misses. Underwriting teams get a clear view of exposed services, compromised credentials and known security weaknesses, so they can make better decisions on selection, pricing and remediation.

The result is fewer risks accepted blind, more consistent underwriting across teams and brokers, and earlier sight of the exposures most likely to drive next year's loss ratio. Cyber loss ratios don't need to be predicted perfectly. They need to be understood, and much of what drives volatility is visible before binding if you're looking in the right place.

Request a Breach Check portfolio scan to see what's hiding in your current book before it shows up in next year's loss ratio.