Cyber Insurance Risk Exposure Estimator

This estimator converts a cyber incident scenario into an annualized financial exposure after insurance. It combines incident probability, modeled loss, policy coverage, the deductible, the policy limit, and costs that remain outside the policy. Use the result to compare retained risk across policy options or to identify where prevention and recovery controls may have more value than additional insurance. The estimate is a planning model, not a prediction of a specific claim outcome.

Risk and policy assumptions

%
USD
%
USD
USD
USD
Result
annual retained cyber risk exposure
Gross expected loss
Expected insurer payment
Retained loss per incident

1. Set incident probability
Enter the estimated chance of at least one modeled cyber incident during a year.

2. Enter the modeled loss
Use the total financial loss before insurance for one representative incident.

3. Describe the policy
Enter the eligible coverage share, deductible, and maximum policy payout.

4. Add excluded costs
Include losses expected to remain uninsured, such as exclusions or uncovered response work.

5. Review retained exposure
Compare the annual retained amount with the gross expected loss and expected insurer payment.

Annual retained exposure = Incident probability × (Gross loss − Insurer payment + Uninsured cost) Insurer payment = min(Policy limit, max(0, Gross loss × Coverage rate − Deductible))

Where:

  • Incident probability: annual probability expressed as a decimal
  • Gross loss: modeled loss for one incident in USD
  • Coverage rate: eligible share of gross loss
  • Deductible: amount retained before insurer payment
  • Policy limit: maximum insurer payment
  • Uninsured cost: additional loss outside modeled coverage

Assumptions: The model treats one representative incident scenario and annualizes it by probability. Actual wording, exclusions, sublimits, claim adjustment, and multiple incidents can materially change recovery.

What the result means

The main result is the expected annual loss the organization still carries after the modeled insurance recovery.

Use comparable loss scenarios when testing different policy structures. This estimate is not legal, insurance, or actuarial advice.

Given: 20% annual incident probability, $500,000 gross loss, 80% covered share, $50,000 deductible, $300,000 limit, and $40,000 uninsured cost.

Calculation: Eligible amount = $500,000 × 80% = $400,000. After deductible = $350,000. Insurer payment is capped at $300,000. Retained loss per incident = $500,000 − $300,000 + $40,000 = $240,000. Annual retained exposure = 20% × $240,000 = $48,000.

Result: The modeled annual retained cyber risk exposure is $48,000.

Why is the policy limit applied after the deductible?

The estimator first calculates the covered portion and subtracts the deductible, then caps the insurer payment at the policy limit. Policy wording can differ, so match the inputs to the structure being evaluated.

Should incident probability exceed 100% when several events are possible?

No. This version uses the probability of one representative annual loss scenario. For multiple event frequencies, model scenarios separately or use an expected event count model.

What belongs in uninsured cost?

Use costs that are expected to remain outside the modeled insurer payment, such as exclusions, sublimit gaps, or internal labor not reimbursed. Do not add costs already included in gross loss unless they are intentionally separated.

Can the result be negative?

No. The calculator prevents insurer payment from exceeding the modeled covered amount and floors retained loss at zero before adding uninsured costs.

How is this different from expected loss?

Gross expected loss ignores insurance recovery. Retained exposure estimates the portion the organization expects to carry after the modeled policy response.