Brought to you by:

Digital footprint 'provides cyber claim frequency signal'

Cyber risk underwriting can be further enhanced using digital footprint data, according to a Gallagher Re report. 

Insurers typically rely on firmographic information such as company revenue and employee size as well as external security indicators to assess an entity’s cyber exposure. 

“While these factors remain important, Gallagher Re’s analysis suggests they do not fully describe the scale, complexity, and structure of an organisation’s external technology footprint,” the reinsurance broker said. 

“Rather than relying solely on lengthy questionnaires or traditional firmographics, insurers can incorporate observable indicators of internet-facing complexity into underwriting and portfolio management decisions.” 

The joint report with cyber risk intelligence firm KYND found “positive relationship” between distinct Internet Service Provider count and claim likelihood, with risk increasing as the number of ISPs rises. 

“This suggests that ISP diversity is capturing an important aspect of the organisation’s external footprint, all of which may contribute to greater cyber exposure,” the report said. 

“Importantly, this pattern appears broadly consistent across companies of different revenue bands, indicating that the predictive value of ISP count is not simply a reflection of economic size. 

“Rather, distinct ISPs appear to provide a meaningful technographic signal in their own right, perhaps providing a valuable view of the geographic spread of an organisation.” 

Other digital footprint data that can enhance cyber risk pricing include email provider diversity, externally exposed services and Internet protocol address locations. 

“This work with KYND suggests that understanding an organisation’s digital footprint carries its own signal for claim frequency, beyond those established factors,” Gallagher Re global head of cyber security Ed Pocock said. 

“We’re only scratching the surface of what this data can tell us, but it gives us a useful, evidence-led starting point for understanding cyber exposure better.”