Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
EXTREME VALUE COPULASCyber Risk Underwriting

Extreme Value Copula Distributions for Correlated Kinetic-Cyber Catastrophic Solvency

100% Complete & Untruncated 32 min read
Return to Research Tracks

J. McKenney

This is the solvency paper of the underwriting working group, WG-01-UI, and it stands alone rather than in a numbered series. It sits downstream of the group's asset register work, which derives single and annualized loss expectancy for one facility, and upstream of nothing: it is where the group's loss figures become a capital requirement and a security to sell. It absorbs a second paper, Actuarial Solvency and Dynamic Catastrophe Bonds for Renewable Microgrids, which is now retired, and it carries that paper's coupon pricing formula, its cryptographic oracle construction, its offshore wind case study and its treatment of the war exclusion.

Licence: CC BY 4.0. 16 September 2026.

Executive Abstract#

An insurer covering an industrial plant makes two bets. One is how bad a single loss can be. The other is how many plants can be destroyed on the same afternoon, and that is the one that ends insurers.

Industrial accidents used to be local and independent, so that second bet was safe. A cyber attack on control equipment is not. One defect in a widely deployed controller, once an exploit exists, sits at every site that bought it and can fire at all of them within minutes. The Gaussian model under most capital work treats simultaneous extreme losses as approaching impossible, backwards for this peril.

This paper replaces it. Single-loss size follows the distribution extreme value theory requires for the largest losses, and joint behavior follows a copula that keeps positive probability of simultaneous catastrophe however deep into the tail you look. On a modeled portfolio of twenty sites the required capital runs several times the Gaussian figure.

That number cannot sit on a balance sheet, so the tail is sold to capital markets as a catastrophe bond. It pays not on a forensic investigation, which arrives too late for an operator whose covenants fail meanwhile, but on two machine-checkable conditions: a measurement crossing a certified damage threshold, and a signed attestation that a known exploit was involved. Both are checked by cryptography, and money moves in hours. Two cases follow, with a note on two inherited figures that do not reconcile.

Abstract#

Industrial cyber losses that cross into physical destruction are heavy-tailed and asymmetrically dependent. Marginals are fitted by peaks over threshold under the Pickands-Balkema-de Haan theorem, giving the generalized Pareto distribution as the limiting excess law. Shapes run from 0.39 to 0.58, placing losses in the Frechet domain; above 0.5 the variance does not exist, invalidating any standard-deviation premium principle. Dependence uses nested asymmetric Gumbel-Hougaard copulas, whose upper tail dependence has the closed form two minus two to the power one over theta. Solvency capital and expected shortfall are computed across five dependence structures at identical rank correlation, the gap being the central result. The tail transfers through a collateralized catastrophe bond with a dual-key parametric trigger, a physical key on a certified kinetic damage integral and a cyber key on a signed exploitability attestation, settled by threshold signature aggregation in one pairing check. Every parameter is calibrated against the working group's own models, since no public loss database exists. The single-peril case prices residual basis risk at 6.8 percent against 4.2 percent for indemnity; section 7.3 records two inherited figures that do not reconcile.

1. Why conventional underwriting fails on this peril#

1.1 The two failure modes an underwriter meets#

Commercial cyber insurance was designed around informational loss: privacy breach liability, exfiltration of personal data, extortion of a business that cannot reach its files. Those losses are transactional, legal and reputational. They have bounded variance, they are mostly independent across policyholders, and the standard aggregate loss machinery handles them.

Operational technology in energy generation, chemical synthesis, water distribution and logistics is now networked to supervisory systems that reach outside the plant, and an attack on it does not stop at information. Manipulating a protective relay, forcing over-pressurization of a distillation column, or decoupling synchronous frequency across a grid destroys capital equipment. A penetration of supervisory controls does not merely exfiltrate data; it alters inverter frequency-droop coefficients, changes maximum power point tracking parameters, or suppresses blade pitch feathering during gale-force winds. What follows is shaft shearing, transformer dielectric breakdown or thermal runaway in a battery container, at a capital cost orders of magnitude above a data breach payout.

An underwriter pricing that exposure meets two structural failures, and they are different in kind.

The first is a timing failure. A standard indemnity policy requires physical forensic investigation, loss adjustment and legal attribution of fault. For an operator whose cash flow depends on continuous delivery under a power purchase agreement, an adjustment cycle running from six months to two years does not delay recovery, it causes insolvency before recovery. The policy pays the estate.

The second is a distributional failure, and it is the subject of the next two subsections. Aggregating cyber losses under lognormal or Weibull assumptions understates the probability of simultaneous multi-facility failure. A malicious firmware update distributed to thousands of grid-edge inverters produces correlated failures that breach conventional reinsurance stop-loss limits, and the model that set those limits did not contain the possibility.

1.2 The linear correlation fallacy#

Pearson's correlation measures linear co-movement and is a complete description of dependence only within the elliptical family, of which the multivariate normal is the familiar member [1]. Outside that family it is a summary statistic that can be identical for two joint distributions with entirely different extreme behavior.

Applied to industrial sites, it produces a specific and dangerous reading. Two utility plants show near-zero loss correlation across the overwhelming majority of operating hours, because their local disturbances genuinely are independent. Then an automated payload exploiting a widely deployed controller firmware defect is released, and both fail within the same minute, along with dozens of others. The historical correlation was not wrong about the ordinary hours. It was measuring the wrong thing, because the dependence in this peril lives entirely in a region the ordinary hours never visit.

1.3 Vanishing and symmetric tail dependence#

The deeper problem is in the dependence model rather than the summary statistic. A Gaussian copula has zero upper tail dependence in the asymptotic limit for any correlation short of one:

λUGauss=lim⁡t→1−P(U2>t∣U1>t)=0,∀∣ρ∣<1\lambda_U^{\text{Gauss}} = \lim_{t \to 1^-} \mathbb{P}\left( U_2 > t \mid U_1 > t \right) = 0, \quad \forall |\rho| < 1

Using a Gaussian copula to model multi-plant physical damage therefore forces the model to assert that as loss severity approaches catastrophic levels, joint extreme occurrence becomes impossible. That is not a conservative simplification. It is the opposite of the phenomenon being modeled.

The Student-t copula is often offered as the repair, and it does admit tail dependence, but symmetrically: it imposes the same dependence in the lower tail, meaning joint quiet days, as in the upper tail, meaning joint destruction. Industrial cyber losses are right-skewed and asymmetric. Calm periods show localized independent noise and catastrophic periods show maximal clustering, and a model that ties the two together will be calibrated by the quiet data it has and applied to the extreme data it does not [2], [3].

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

2. Marginals: peaks over threshold#

2.1 The Pickands-Balkema-de Haan theorem#

Let XX be a loss variable representing physical asset destruction or business interruption at one facility, with distribution function F(x)=P(X≤x)F(x) = \mathbb{P}(X \le x). For a high threshold uu, the conditional excess distribution is

Fu(y)=P(X−u≤y∣X>u)=F(u+y)−F(u)1−F(u),y≥0F_u(y) = \mathbb{P}(X - u \le y \mid X > u) = \frac{F(u + y) - F(u)}{1 - F(u)}, \quad y \ge 0

The theorem, established independently by Pickands and by Balkema and de Haan, states that for a broad class of underlying FF, as uu approaches the right endpoint xFx_F the excess distribution converges uniformly to the generalized Pareto distribution [4], [5]:

lim⁡u→xFsup⁡0≤y<xF−u∣Fu(y)−Gξ,σ(y)∣=0\lim_{u \to x_F} \sup_{0 \le y < x_F - u} \left| F_u(y) - G_{\xi, \sigma}(y) \right| = 0

with

Gξ,σ(y)={1−(1+ξyσ)−1/ξ,ξ≠01−exp⁡(−yσ),ξ=0G_{\xi, \sigma}(y) = \begin{cases} 1 - \left( 1 + \frac{\xi y}{\sigma} \right)^{-1/\xi}, & \xi \neq 0 \\ 1 - \exp\left( -\frac{y}{\sigma} \right), & \xi = 0 \end{cases}

where y≥0y \ge 0 when ξ≥0\xi \ge 0 and 0≤y≤−σ/ξ0 \le y \le -\sigma/\xi when ξ<0\xi < 0. The shape parameter ξ\xi is the tail index and σ>0\sigma > 0 the scale.

The reason to use this rather than to fit a familiar loss distribution is that the theorem is about the tail specifically. It says that whatever the body of the loss distribution looks like, the excesses over a high enough threshold have a known parametric form. The underwriter's question is entirely about the tail, so the tail is what gets fitted.

For industrial kinetic cyber losses the fitted shape is positive, which places the loss in the Fréchet domain of attraction. Under a positive shape, the kk-th moment E[Xk]\mathbb{E}[X^k] exists if and only if ξ<1/k\xi < 1/k. At ξ≥0.5\xi \ge 0.5 the variance does not exist, and every premium principle that adds a multiple of a standard deviation to an expected loss is arithmetic on a quantity that is not there.

The calibrations in the table below are the working group's own, fitted against its own modeled loss ensembles rather than against a public database of industrial cyber losses, because no such database exists at the size this fitting needs. They are offered as the numbers used in the simulations reported later and not as an industry estimate.

Risk classificationShapeScale, USD millionTail regime
Level 0 and 1 kinetic damage0.58214.2Fréchet, variance does not exist
Level 2 and 3 supervisory outage0.3948.6Fréchet, variance exists
Level 4 business interruption0.44121.5Fréchet, variance exists

2.2 Semi-parametric reconstruction and the choice of threshold#

Fitting only the tail leaves the body of the distribution undescribed, and a simulation needs both. The complete marginal for facility ii joins the empirical distribution function below the threshold to the fitted generalized Pareto tail above it:

Fi(x)={F~n,i(x),x≤ui1−(1−F~n,i(ui))[1+ξi(x−ui)σi]−1/ξi,x>uiF_i(x) = \begin{cases} \tilde{F}_{n, i}(x), & x \le u_i \\ 1 - \left( 1 - \tilde{F}_{n, i}(u_i) \right) \left[ 1 + \frac{\xi_i (x - u_i)}{\sigma_i} \right]^{-1/\xi_i}, & x > u_i \end{cases}

The threshold itself is a choice and it is the most consequential one in the whole fitting procedure, because too low a threshold biases the shape estimate toward the body and too high a threshold leaves too few exceedances to estimate anything. It is selected from the mean excess function, whose form under the generalized Pareto is linear in uu:

e(u)=E[X−u∣X>u]=σ+ξu1−ξ,ξ<1e(u) = \mathbb{E}[X - u \mid X > u] = \frac{\sigma + \xi u}{1 - \xi}, \quad \xi < 1

A plot of the empirical mean excess against uu that becomes and stays linear with positive slope above some point is evidence both that the tail is heavy and that the threshold can be set there. The Hill estimator plotted across order statistics gives a second reading, and the two are used together rather than either alone.

2.3 High-quantile metrics for a single exposure#

With NuN_u exceedances out of nn observations, the unconditional tail estimator above the threshold is

F^(x)=1−Nun(1+ξ^(x−u)σ^)−1/ξ^\hat{F}(x) = 1 - \frac{N_u}{n} \left( 1 + \frac{\hat{\xi}(x - u)}{\hat{\sigma}} \right)^{-1/\hat{\xi}}

Inverting it gives value at risk at confidence pp:

VaRp(X)=u+σ^ξ^[(nNu(1−p))−ξ^−1]\text{VaR}_p(X) = u + \frac{\hat{\sigma}}{\hat{\xi}} \left[ \left( \frac{n}{N_u} (1 - p) \right)^{-\hat{\xi}} - 1 \right]

Value at risk is not subadditive in the heavy-tailed regime, which means that splitting a portfolio into two can appear to reduce total risk, so capital adequacy is assessed on expected shortfall, which is coherent:

ESp(X)=E[X∣X>VaRp(X)]=VaRp(X)1−ξ^+σ^−ξ^u1−ξ^\text{ES}_p(X) = \mathbb{E}[X \mid X > \text{VaR}_p(X)] = \frac{\text{VaR}_p(X)}{1 - \hat{\xi}} + \frac{\hat{\sigma} - \hat{\xi} u}{1 - \hat{\xi}}

At the 99.5 percent level and a shape of 0.58, the modeled expected shortfall runs 2.38 times the Gaussian approximation on the same data. That ratio is for one exposure. Sections 3 and 4 are about what happens when there are twenty.

3. Dependence: extreme value copulas#

3.1 Sklar's theorem and the extreme value property#

Once the marginals F1,…,FdF_1, \dots, F_d are fixed, Sklar's theorem guarantees a unique copula CC on the unit cube coupling them into a joint distribution [6]:

F(x1,…,xd)=C(F1(x1),…,Fd(xd))F(x_1, \dots, x_d) = C\left( F_1(x_1), \dots, F_d(x_d) \right)

That separation is what makes the whole approach work: severity and dependence are estimated from different features of the data and can be wrong independently, which means they can also be checked independently.

Not every copula is admissible here. A copula appropriate to extremes must satisfy the extreme value property, meaning it is max-stable:

C(u1t,…,udt)=Ct(u1,…,ud),∀t>0C\left( u_1^t, \dots, u_d^t \right) = C^t(u_1, \dots, u_d), \quad \forall t > 0

which says that the dependence structure of the maxima is the dependence structure itself, at every scale.

3.2 The Gumbel-Hougaard copula#

The Archimedean family generated by a continuous, strictly decreasing, convex generator ψ\psi with ψ(1)=0\psi(1) = 0 takes the form

C(u1,…,ud)=ψ[−1](∑i=1dψ(ui))C(u_1, \dots, u_d) = \psi^{[-1]}\left( \sum_{i=1}^d \psi(u_i) \right)

and the member of it that satisfies the extreme value property is the Gumbel-Hougaard copula, with parameter θ∈[1,∞)\theta \in [1, \infty) [7]:

ψθ(t)=(−ln⁡t)θ,ψθ−1(s)=exp⁡(−s1/θ)\psi_\theta(t) = (-\ln t)^\theta, \quad \psi_\theta^{-1}(s) = \exp\left( -s^{1/\theta} \right)

giving

Cθ(u1,…,ud)=exp⁡(−[∑i=1d(−ln⁡ui)θ]1/θ)C_\theta(u_1, \dots, u_d) = \exp\left( - \left[ \sum_{i=1}^d (-\ln u_i)^\theta \right]^{1/\theta} \right)

At θ=1\theta = 1 this is the independence copula. As θ\theta grows without bound it converges to the upper Fréchet-Hoeffding bound, which is complete comonotonicity. The single parameter therefore sweeps the whole range from independent plants to plants that fail together by construction.

3.3 The upper tail dependence coefficient#

The quantity an underwriter actually needs is the conditional probability that a second asset suffers an extreme loss given that the first has, evaluated in the limit:

λU=lim⁡t→1−P(U2>t∣U1>t)=lim⁡t→1−1−2t+C(t,t)1−t\lambda_U = \lim_{t \to 1^-} \mathbb{P}\left( U_2 > t \mid U_1 > t \right) = \lim_{t \to 1^-} \frac{1 - 2t + C(t, t)}{1 - t}

For the Gumbel-Hougaard copula the diagonal section evaluates in closed form:

Cθ(t,t)=exp⁡(−[2(−ln⁡t)θ]1/θ)=exp⁡(−21/θ(−ln⁡t))=t21/θC_\theta(t, t) = \exp\left( - \left[ 2(-\ln t)^\theta \right]^{1/\theta} \right) = \exp\left( - 2^{1/\theta} (-\ln t) \right) = t^{2^{1/\theta}}

Substituting and applying L'Hôpital's rule to the resulting indeterminate form:

λU=lim⁡t→1−−2+21/θt21/θ−1−1=2−21/θ\lambda_U = \lim_{t \to 1^-} \frac{-2 + 2^{1/\theta} t^{2^{1/\theta} - 1}}{-1} = 2 - 2^{1/\theta}

Because θ≥1\theta \ge 1 gives 21/θ∈(1,2]2^{1/\theta} \in (1, 2], the coefficient satisfies

λU∈(0,1]∀θ>1\lambda_U \in (0, 1] \quad \forall \theta > 1

Any positive coupling at all leaves a strictly positive probability of simultaneous catastrophe arbitrarily deep in the tail. That is the property the Gaussian copula does not have and the reason for choosing this family. For a fleet sharing standardized firmware at θ=2.45\theta = 2.45:

λU=2−21/2.45=2−20.4082≈2−1.327=0.673\lambda_U = 2 - 2^{1/2.45} = 2 - 2^{0.4082} \approx 2 - 1.327 = 0.673

Given that one facility is destroyed, the model assigns a 67.3 percent conditional probability that an interconnected neighbour is destroyed in the same event.

3.4 Asymmetric nested copulas#

A single θ\theta across a whole portfolio asserts that every pair of exposures is coupled equally, which is false in a way that matters. Dependence inside one site, between turbine vibration and boiler pressure on the same process, is far stronger than dependence between two sites on different continents. Forcing one parameter to describe both either overstates the cross-site coupling or understates the within-site coupling, and which of the two happens depends on which data dominated the fit.

The repair is to nest:

C(u1,u2,u3)=Cθ1(u1,Cθ2(u2,u3))C(u_1, u_2, u_3) = C_{\theta_1}\left( u_1, C_{\theta_2}(u_2, u_3) \right)

subject to the nesting condition that makes the result a valid copula:

1≤θ1≤θ21 \le \theta_1 \le \theta_2

The inner copula couples the tightly bound local components, the actuators and controllers at the lower Purdue levels. The outer copula couples that local aggregate to the enterprise-level exposure, the planning systems and supply chain disruption at Level 4. The condition θ1≤θ2\theta_1 \le \theta_2 is not a modeling preference; a nested Archimedean construction that violates it is not a distribution function.

4. Regulatory capital under Solvency II#

4.1 The requirement and the measure#

Under Article 101 of the Solvency II directive, an insurer's solvency capital requirement must absorb all quantifiable risks at a 99.5 percent confidence level over one year [8]:

SCR=VaR0.995(L−E[L])\text{SCR} = \text{VaR}_{0.995}(L - \mathbb{E}[L])

where L=∑k=1dXkL = \sum_{k=1}^d X_k is the aggregate portfolio loss. The directive permits value at risk, and sound practice computes expected shortfall alongside it, because expected shortfall is coherent and reports the severity of the breaches rather than only their frequency:

ESα(L)=11−α∫α1VaRu(L) du=E[L∣L>VaRα(L)]\text{ES}_\alpha(L) = \frac{1}{1 - \alpha} \int_\alpha^1 \text{VaR}_u(L) \, du = \mathbb{E}\left[ L \mid L > \text{VaR}_\alpha(L) \right]

Reporting only the first of these is the commonest way a capital calculation comes to be believed more than it should be. The quantile says where the loss sits that is exceeded once in two hundred years. It says nothing about how far beyond it the exceedance goes, and in a Fréchet regime that distance is the whole exposure.

4.2 What the choice of copula costs#

The following simulation isolates the effect of dependence structure alone. A portfolio of twenty industrial energy facilities is modeled, each with baseline assets of USD 500 million and identical marginal generalized Pareto parameters, shape 0.52, scale USD 18 million, threshold USD 10 million. One hundred thousand joint loss realizations are drawn under each of five dependence structures, all calibrated to the same Kendall rank correlation of 0.50, so that any difference between the rows comes from the tail behavior of the copula rather than from a different amount of dependence.

CopulaUpper tail dependenceCapital requirement at 99.5 percent, USD millionExpected shortfall at 99.5 percent, USD million
Independent, as a baseline0.00084.2102.5
Gaussian0.000168.4214.1
Student-t, four degrees of freedom0.284312.8438.7
Gumbel-Hougaard0.586584.6892.4
Nested asymmetric, as fitted here0.642641.21048.6

Each comparison below names the row it is against, because the two comparisons in the absorbed material did not use the same row and the discrepancy is recorded in section 7.3.

Against the Gumbel-Hougaard row, the Gaussian copula understates the capital requirement by 71.2 percent, 168.4 against 584.6, and understates expected shortfall by 76.0 percent, 214.1 against 892.4. Against the nested row actually fitted here, the Gaussian understates capital by 73.7 percent and expected shortfall by 79.6 percent.

The reading is the same whichever row is chosen. An underwriter using Gaussian dependence to cover twenty interconnected industrial sites holds something between a quarter and a third of the liquidity the extreme value model says is required, and discovers the shortfall on the day every policyholder claims at once.

The Student-t row is worth a separate remark because it is the usual remedy. It does improve on the Gaussian, roughly doubling the capital figure, and it still lands at about half the extreme value number. Symmetric tail dependence fitted to a data set dominated by ordinary periods produces a tail coefficient governed by the ordinary periods, which is the failure described in section 1.3 showing up as a number.

5. Transferring the tail: parametric catastrophe bonds#

5.1 Why an indemnity trigger cannot work here#

A capital requirement above a billion dollars against a portfolio of this size cannot be held on a commercial balance sheet, so it has to be transferred. Insurance-linked securities are the established route, and catastrophe bonds issued into the institutional private placement market provide multi-year fully collateralized capacity [9].

The obstacle is not capacity but the trigger. A traditional catastrophe bond pays on an indemnity trigger, requiring months of forensic audit, or on a modeled loss trigger, which is vulnerable to disagreement about the model. Section 1.1 gave the reason neither works here: the operator's problem is a liquidity problem measured in weeks, and a payout arriving after the adjustment cycle arrives after the covenant breach.

The construction below removes the adjustment cycle rather than shortening it, by defining the payout over quantities that are measured rather than argued.

5.2 The physical parameter key#

The physical key asserts when measured plant telemetry crosses a certified damage threshold. For a rotating machine the canonical destruction vector is overspeed under load, and the excursion is expressed as an integral over the exposure window rather than as an instantaneous reading, because damage accumulates:

Ikinetic=∫t0t0+ΔTmax⁡(0,ω(t)−ωtrip)2⋅∣τ(t)∣ dt\mathcal{I}_{\text{kinetic}} = \int_{t_0}^{t_0 + \Delta T} \max\left(0, \omega(t) - \omega_{\text{trip}}\right)^2 \cdot |\tau(t)| \, dt

where ω\omega is the angular velocity of the high-speed shaft, ωtrip\omega_{\text{trip}} the certified trip speed and τ\tau the mechanical torque. Squaring the overspeed and weighting by torque is a modeling choice, made so that the integral tracks the fatigue mechanism rather than the duration of the excursion.

Generalized across a fleet, the key asserts when enough assets exceed their own thresholds:

Kphys=1(∑i=1d1(∫t0t0+Δtmax⁡(0,ϕi(t)−ϕcrit)dt>Γi)≥M)\mathcal{K}_{\text{phys}} = \mathbf{1}\left( \sum_{i=1}^d \mathbf{1}\left( \int_{t_0}^{t_0 + \Delta t} \max\left(0, \phi_i(t) - \phi_{\text{crit}}\right) dt > \Gamma_i \right) \ge M \right)

where ϕi\phi_i is the physical metric for asset ii, which may be bearing vibration velocity, busbar frequency deviation or transformer winding hotspot temperature, Γi\Gamma_i its critical damage integral, and MM the minimum number of affected assets. The thresholds Γi\Gamma_i come from the equipment certification, not from the insurer, which is what makes them arguable in advance and not arguable afterwards.

5.3 The cyber provenance key#

The physical key alone would pay on a hurricane. The cyber key establishes that the excursion was caused by unauthorized manipulation rather than by weather or wear, and it asserts on a cryptographically validated exploitability attestation carried in a CycloneDX vulnerability exchange document, signed by a national incident response team or an independent audit consortium [10]:

Kcyber=1(∃c∈VEX:c.status=affected∧c.state=exploitable∧VerifySig(c,PKauditor)=1)\mathcal{K}_{\text{cyber}} = \mathbf{1}\left( \exists c \in \text{VEX} : c.\text{status} = \text{affected} \land c.\text{state} = \text{exploitable} \land \text{VerifySig}(c, \text{PK}_{\text{auditor}}) = 1 \right)

The signing party matters more than the format. An attestation signed by the operator who is about to be paid is not evidence, and the protocol is built so that the party asserting the cyber key has no interest in the payout.

5.4 The settlement condition#

The bond principal PP sits in a special purpose vehicle invested in short-duration government paper. Release is governed by the conjunction of the two keys:

Disbursement=P×(Kphys∧Kcyber)\text{Disbursement} = P \times \left( \mathcal{K}_{\text{phys}} \land \mathcal{K}_{\text{cyber}} \right)

Because both conditions are objective and machine-verifiable, settlement requires no forensic litigation and the liquidity reaches the affected operator inside the same working day.

The cost of that speed is basis risk, and it is real. The bond pays a contracted amount on a measured condition, not the loss actually suffered, and the difference between the two is retained by the insured. Section 7.1 prices that difference in the single-peril case.

5.5 Coupon pricing#

Investors require a coupon compensating them for the expected loss and for the shape of the tail beyond it. The expected loss rate on the tranche is the probability mass of the excursion integral above the attachment point:

EL=E[Θpayout]=∫Γcrit∞gI(z) dz\text{EL} = \mathbb{E}[\Theta_{\text{payout}}] = \int_{\Gamma_{\text{crit}}}^\infty g_{\mathcal{I}}(z) \, dz

where gIg_{\mathcal{I}} is the density of the excursion integral induced by the fitted marginal model of section 2. The spread over the risk-free benchmark decomposes into four terms:

S=μloss+κ1⋅VaRα(I)+κ2⋅ESα(I)EL+λmodelS = \mu_{\text{loss}} + \kappa_1 \cdot \text{VaR}_\alpha(\mathcal{I}) + \kappa_2 \cdot \frac{\text{ES}_\alpha(\mathcal{I})}{\text{EL}} + \lambda_{\text{model}}

with μloss\mu_{\text{loss}} the expected loss itself, κ1\kappa_1 a capital reserve coefficient reflecting the solvency margin the investor's own regulator imposes, κ2\kappa_2 a conditional tail expectation multiplier compensating for downside in the Fréchet regime, and λmodel\lambda_{\text{model}} an explicit uncertainty load for misspecification of adversary attack frequency. The last term is the honest one: nobody knows the arrival rate of coordinated firmware attacks, and a pricing function that does not carry a line for that ignorance is pricing it at zero.

Calibrated against observed market spreads for energy and cyber catastrophe bonds, the working group uses the operational form

Cbond=rf+1.45⋅EL+0.082⋅Var(Loss)+0.0150C_{\text{bond}} = r_f + 1.45 \cdot \text{EL} + 0.082 \cdot \sqrt{\text{Var}(\text{Loss})} + 0.0150

The three coefficients are the group's own calibration and are reproduced here as they were calibrated in the absorbed paper. They are not drawn from a published pricing study, and the square root term inherits the difficulty noted in section 2.1, that at a shape above one half the variance it refers to does not exist; in practice the term is evaluated on the truncated distribution used in the simulation, which is a choice and is recorded here as one.

6. The oracle and the settlement path#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

6.1 Tamper-evident physical attestation#

The physical key is only as good as the sensor that asserts it, so each protective relay and measurement unit is provisioned with a hardware root of trust. Telemetry frames carrying frequency, rotor speed and phase angle are sampled at the process bus rate defined for sampled values in the relevant part of IEC 61850 [11], and at a fixed interval the relay hashes the telemetry buffer and signs it with its hardware-bound private key:

σi=Signski(H(Timestamp∥AssetID∥Ikinetic∥GridFreq))\sigma_i = \text{Sign}_{sk_i}\left( H\left( \text{Timestamp} \parallel \text{AssetID} \parallel \mathcal{I}_{\text{kinetic}} \parallel \text{GridFreq} \right) \right)

Binding the key to hardware is what distinguishes this from a logging arrangement. A signature the operator could produce on a workstation would put the operator in the position of certifying its own claim, which is the position the whole construction exists to remove.

6.2 Threshold aggregation and the pairing check#

A network of MM independent oracle validators subscribes to the signed streams. A node that observes the excursion integral exceeding the certified threshold broadcasts an approval. Once KK of MM agree, with K≥⌊2M/3⌋+1K \ge \lfloor 2M/3 \rfloor + 1, the individual signatures are aggregated into one compact signature [12]:

σagg=∑k=1Kσk\sigma_{\text{agg}} = \sum_{k=1}^K \sigma_k

and the settlement contract verifies the whole set with a single pairing evaluation rather than one verification per signer:

e(σagg,g2)=∏k=1Ke(H1(m),pkk)e\left( \sigma_{\text{agg}}, g_2 \right) = \prod_{k=1}^K e\left( H_1(m), pk_k \right)

The reason to use an aggregatable scheme rather than a list of ordinary signatures is cost and constancy. Verification is a fixed amount of work regardless of how many oracles participated, so the protocol can add validators to raise the difficulty of collusion without making settlement more expensive.

7. Case studies#

The two cases below exercise different halves of the model. The first is a single-peril case in which one operator's fleet is attacked, and it tests the trigger and the liquidity path. The second is a correlated-peril case across a portfolio, and it tests the copula and the capital relief. They were run on different modeled portfolios and no figure from one carries to the other.

7.1 A 250 MW offshore wind farm#

A coordinated persistent threat is modeled against the supervisory and pitch-control systems of an offshore wind farm of thirty 12 MW direct-drive turbines. Malware forces eighteen turbines into high-wind overspeed while falsifying vibration telemetry to the operator's own displays. Independent measurement units detect the kinetic overspeed integral exceeding its certified threshold at 38.4 seconds, and the oracle network reaches agreement at 42.1 seconds. Within 1.85 hours of the physical damage, the vehicle disburses EUR 84,000,000 to the operator's reserve account against a capitalized limit of EUR 120,000,000.

ParameterTraditional indemnity policyParametric catastrophe bond
Capitalized limitEUR 120,000,000EUR 120,000,000
Claim triggerForensic loss adjustmentCryptographic telemetry excursion
Disbursement latency412 days1.85 hours
Adjustment and litigation costEUR 8,450,000EUR 42,000
Residual basis risk4.2 percent6.8 percent
Operator insolvency probability68.4 percent0.8 percent
Underwriter solvency ratioreserve call breaches the capvehicle collateral ring-fenced

The row that decides the question is not the latency, it is the second to last. The liquidity arriving inside two hours lets the operator service senior debt, mobilize repair vessels and procure replacement nacelle components without filing for protection, and the modeled insolvency probability falls accordingly. The row that costs something is the basis risk, which rises from 4.2 to 6.8 percent because the bond pays a contracted amount against a measured condition and the unmodeled auxiliary costs are retained. That is the trade, stated in the two numbers rather than in an adjective.

7.2 A continental transmission fleet#

The second case is a portfolio of fifty high-voltage substations and generation hubs exposed to a single threat actor deploying an undocumented firmware implant against protective relays. Five hundred thousand synthetic catastrophe years are simulated. Marginals are fitted by peaks over threshold at a USD 5 million threshold, giving shapes in the range 0.48 to 0.62 and scales from USD 12 million to USD 22 million. Dependence is the asymmetric nested Gumbel construction of section 3.4, with a regional clustering parameter of 3.12 and an inter-regional backbone parameter of 1.84. The transferred tranche is USD 750 million over three years, attaching when at least four substations trip on vibration or overcurrent interlocks with a confirmed exploitability record.

ParameterValue
Annual attachment probability1.14 percent, a 1-in-88 year return period
Annual exhaustion probability0.42 percent, a 1-in-238 year return period
Expected loss0.82 percent, USD 6.15 million a year
Investor coupon spreadbenchmark rate plus 575 basis points
Capital reliefUSD 512.4 million of reserve released
Benefit to cost ratio4.38 times return on allocated capital

Ceding the tail beyond the 1-in-88 year point reduces the operator's capital requirement from USD 786 million to USD 273.6 million, and the cost of carrying the spread is smaller than the return on the released capital. That arithmetic is what makes the structure sustainable rather than merely available, and it depends entirely on the capital requirement being computed under the extreme value copula. Under the Gaussian assumption the requirement would be small enough that the bond would look like an unnecessary expense, which is how an insurer talks itself out of the cover it needs.

7.3 Two figures that do not reconcile#

Two inherited numbers do not survive checking, and both are recorded here rather than quietly corrected.

The first is the tail dependence of the inter-regional parameter in section 7.2. The absorbed and surviving material both give the closed form derived in section 3.3, that λU=2−21/θ\lambda_U = 2 - 2^{1/\theta}. At the regional clustering parameter of 3.12 that form gives 0.751, against a printed 0.748, which is ordinary rounding of the parameter. At the inter-regional parameter of 1.84 it gives

λU=2−21/1.84=2−20.5435≈2−1.457=0.543\lambda_U = 2 - 2^{1/1.84} = 2 - 2^{0.5435} \approx 2 - 1.457 = 0.543

against a printed 0.446. To obtain 0.446 the parameter would have to be about 1.57 rather than 1.84. One of the two values is wrong and the source material does not say which, so neither is used anywhere else in this paper: the two parameters are quoted in section 7.2 as the parameters of the fitted copula, and no tail dependence is claimed for the inter-regional level.

The second is the comparison percentage in section 4.2. The absorbed and surviving material stated that the Gaussian copula understates the capital requirement by 73.7 percent while printing the comparison as 168.4 against 584.6, which is the Gumbel-Hougaard row and gives 71.2 percent. The 73.7 percent figure is the comparison against the nested row at 641.2. The expected shortfall percentage in the same sentence, 76.0 percent, is against the Gumbel-Hougaard row. So the sentence combined two comparisons against two different rows. Section 4.2 now names the row for each comparison and prints both pairs, which resolves the inconsistency from the table's own numbers and introduces nothing new.

Neither correction changes the conclusion either passage was drawn for. The Gaussian understatement is large under every pairing in the table, and the nested copula's tail dependence at the regional level is high under either reading of the parameter.

8. Regulatory governance and the war exclusion#

The formulation meets the internal model requirements of the Solvency II directive, whose Article 101 requires capital sufficient for a one-in-two-hundred-year event [8]. Fitting the tail to physical boundary limits rather than to historical regression has a specific regulatory merit: a turbine component cannot exceed its yield strength without destruction, which bounds the support of the extreme loss distribution by an engineering fact rather than by a modeling assumption.

The structure also addresses the market's cyber war exclusion, which is the clause that most often makes cover on this peril worthless at the moment it is needed [13]. The exclusion turns on attribution of an attack to a state actor, and attribution is slow, contested and frequently never settled. A parametric catastrophe bond is structured as a capital markets risk transfer rather than as an indemnity contract, and its payout is contingent on physical sensor metrics and a signed exploitability attestation rather than on who was responsible. The geopolitical question does not enter the settlement path.

I want to be careful about how far that goes. It removes the attribution question from the payout mechanism. It does not remove it from the surrounding contractual arrangements, and an insurer retaining any part of this exposure on an indemnity basis still meets the exclusion on that part.

9. Implementing this inside a regulated carrier#

Four stages, in order, because each depends on the one before it.

Telemetry and attestation ingestion comes first. Edge collectors sit in the substation demilitarized zone, connected to the process bus sampled values and to an authenticated feed of machine-readable bills of materials and exploitability documents. Nothing downstream is meaningful until the physical and cyber inputs are both attested at source.

Marginal calibration is automated second. Goodness-of-fit testing recalibrates the threshold and shape parameters as assets are energized and retired, because a portfolio whose composition changes and whose fitted tail does not is being modeled as the portfolio it used to be.

Copula stress testing enters the carrier's own risk and solvency assessment third. This is the stage that has to survive a supervisor, and the deliverable is the replacement of Gaussian dependence assumptions in the filings rather than a new model sitting beside the old one.

Settlement infrastructure comes last, deliberately. The oracle network and the collateral vehicle are the part that looks most novel and matters least until the three stages above produce a number worth transferring. Building it first produces a settlement path for a capital requirement nobody has computed.

10. Conclusion#

Indemnity cyber insurance does not scale to cover industrial plant against heavy-tailed adversarial loss, and the reason is not pricing. It is that the two things the peril requires, a dependence model that survives the tail and a payout that arrives before the operator fails, are both absent from the standard product.

The first is supplied by fitting marginals where the theory says the tail lives and coupling them with a copula that does not assert independence in the limit. The size of that correction is the paper's main quantitative result and it is a factor of three to four on required capital, at identical rank correlation, which means it is entirely an artifact of the dependence structure and not of the amount of dependence assumed.

The second is supplied by moving the trigger off the loss and onto two measured conditions, one physical and one cyber, each attested by a party with no interest in the payout. That removes the adjustment cycle rather than compressing it, and the price of removing it is a few points of basis risk, which section 7.1 states as a number rather than as a caveat.

What this does not settle is the input that matters most. The arrival rate of coordinated firmware attacks against industrial fleets is unknown, there is no public loss database at the size these fits require, and every shape parameter, dependence parameter and pricing coefficient in this paper is the working group's own calibration against its own models. The pricing function carries an explicit model uncertainty load for that reason. An underwriter adopting this framework inherits a better-shaped model and the same ignorance about frequency, and should say so in the filing [14], [15].

11. References#

[1] A. J. McNeil, R. Frey and P. Embrechts, Quantitative Risk Management: Concepts, Techniques and Tools. Princeton, NJ: Princeton University Press, 2015. Cited for the result that linear correlation is a complete description of dependence only within the elliptical family, which is the basis of section 1.2, and for the copula and risk measure apparatus used in sections 3 and 4.

[2] P. Embrechts, C. Klüppelberg and T. Mikosch, Modelling Extremal Events for Insurance and Finance. Berlin: Springer, 1997. Cited for the extreme value framework as a whole and specifically for the domain of attraction argument that places positive-shape losses in the Fréchet class.

[3] N. N. Taleb, Statistical Consequences of Fat Tails: Real World Preasymptotics, Epistemology, and Applications. STEM Academic Press, 2020. Cited for the consequences of infinite variance for estimation and for premium principles built on a standard deviation, and not for any specific estimate reproduced here.

[4] A. A. Balkema and L. de Haan, "Residual life time at great age", The Annals of Probability, vol. 2, no. 5, pp. 792 to 804, 1974. Cited jointly with [5] for the limit theorem that gives the generalised Pareto distribution as the limiting excess law in section 2.1.

[5] J. Pickands, "Statistical inference using extreme order statistics", The Annals of Statistics, vol. 3, no. 1, pp. 119 to 131, 1975. Cited jointly with [4] for the same theorem, independently obtained.

[6] A. Sklar, "Fonctions de répartition à n dimensions et leurs marges", Publications de l'Institut de Statistique de l'Université de Paris, vol. 8, pp. 229 to 231, 1959. Cited for the representation theorem that separates marginals from dependence, which is what licenses the two-stage fitting procedure of sections 2 and 3.

[7] E. J. Gumbel, "Bivariate exponential distributions", Journal of the American Statistical Association, vol. 55, no. 292, pp. 698 to 707, 1960. Cited for the copula family carrying his name, used here in its Archimedean generator form.

[8] European Parliament and Council, Directive 2009/138/EC on the taking-up and pursuit of the business of Insurance and Reinsurance, Solvency II. Official Journal of the European Union, L 335, pp. 1 to 155, 2009. Cited for Article 101, the 99.5 per cent one-year capital standard that sections 4.1 and 8 are written against.

[9] J. D. Cummins and M. A. Weiss, "Convergence of insurance and financial markets: hybrid and securitized risk-transfer solutions", Journal of Risk and Insurance, vol. 76, no. 3, pp. 493 to 545, 2009. Cited for insurance-linked securities as an established transfer route and for the collateralised structure assumed in section 5.1, and not for anything about cyber peril, which postdates it.

[10] OWASP Foundation, CycloneDX v1.6 Specification, including the Vulnerability Exploitability eXchange. OWASP, 2024. Cited for the signed exploitability document that the cyber provenance key in section 5.3 asserts on.

[11] International Electrotechnical Commission, IEC 61850-9-2, Communication networks and systems for power utility automation, Specific communication service mapping, Sampled values. Geneva: IEC, 2020. Cited for the sampled-value process bus that carries the attested telemetry in section 6.1.

[12] D. Boneh, B. Lynn and H. Shacham, "Short signatures from the Weil pairing", Journal of Cryptology, vol. 17, no. 4, pp. 297 to 319, 2004. Cited for the aggregatable signature scheme and the single pairing verification used in section 6.2.

[13] Lloyd's, Market Bulletin Y5381: Cyber-attack exclusions, Corporation of Lloyd's, London, 16 August 2022. The model wordings drafted to meet it are the Lloyd's Market Association's clauses LMA5564 to LMA5567, November 2021. Cited for the state-backed attack exclusion discussed in section 8, and as the clause the parametric structure is designed to route around rather than to challenge.

[14] J. McKenney, Physics-Grounded Cyber Underwriting: Deriving Single Loss Expectancy and Annualised Loss Expectancy from Unified BIM and BOM Asset Registers. Eigenia Research Working Group WG-01-UI. Cited for the per-facility loss derivation this paper takes as its input and does not restate.

[15] J. McKenney, Mathematical Foundations of Sovereign OT Cyber-Physical Underwriting. Eigenia Monograph Series, Working Group WG-01-UI. Cited for the wider underwriting programme this paper sits inside, and not as evidence for any claim made here.

Note on this bibliography#

Every parameter fitted in this paper is the author's own calibration against the working group's own modelled loss ensembles, and those ensembles are held in the working corpus rather than published. The simulations in sections 4.2, 7.1 and 7.2 are the author's own and no published source records them; they are offered as modelled results and are labelled as modelled wherever they appear. Entries [14] and [15] name Eigenia working group treatises, which are internal to the programme and are cited for what they establish rather than as independently fetchable sources. Section 7.3 records two inherited figures that do not reconcile, and no source supports either of the withdrawn readings.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 48,210 chars