Aggregation Risk
Aggregation risk is the danger that many separate losses turn out to be connected and happen at the same time from a single underlying cause, rather than staying independent of one another. In cyber insurance, this matters because one event, such as a widely used software failure or a shared cloud service outage, could trigger claims across many policyholders simultaneously. The term is used in two related but distinct ways: as a risk-management technique for combining individual risks into an overall picture, and as an insurer concern about correlated losses building up across a portfolio.
In enterprise risk management, risk aggregation refers to the process of combining several individual risks into a more comprehensive, single measure to develop a fuller understanding of overall exposure, for example by evaluating and summing risks across an organization's risk register. In the cyber (re)insurance context, aggregation risk (also termed accumulation risk) refers to the potential for a single triggering event or common dependency to generate correlated, simultaneous losses across many insureds within a portfolio, undermining the assumption of loss independence on which diversification relies. Cyber aggregation risk is widely regarded as dynamic and subject to substantial modeling uncertainty; it concerns portfolio-level loss correlation and is distinct from any single policy's coverage terms, sublimits, or retentions. Whether losses arising from a common event are ultimately covered depends on the specific policy wording, endorsements, and exclusions (such as war or widespread-infrastructure-outage exclusions) rather than on the aggregation concept itself.
Why it matters
Aggregation risk challenges one of the foundational assumptions of insurance: that individual losses are largely independent of one another, so that only a fraction of policyholders will suffer a loss at any given time. When losses are independent, an insurer can pool premiums across many insureds and rely on diversification to remain solvent. Cyber exposures strain this assumption because many organizations depend on the same widely used software, cloud platforms, managed service providers, and authentication systems. A single compromise or failure in one of these shared dependencies could, in principle, trigger correlated claims across a large share of a portfolio at once, concentrating losses rather than spreading them.
This correlation is what makes cyber aggregation risk difficult to price, reserve for, and reinsure. Because a common triggering event can affect both first-party exposures (such as business interruption or data restoration for each affected insured) and third-party exposures (such as liability claims flowing from a shared vendor's breach), an insurer's total exposure to a single scenario may be far larger than the sum of any one policy would suggest. As the industry sources note, cyber aggregation is widely regarded as a dynamic topic surrounded by substantial modeling uncertainty, which is why leading cyber (re)insurers and risk modelers continue to seek greater cooperation and better tools to understand it.
It is important to keep aggregation risk distinct from the coverage question. Aggregation is a portfolio-level concern about how losses correlate; it does not by itself determine whether any individual loss is paid. Whether losses from a common event are ultimately covered depends on the specific policy wording, endorsements, and exclusions, such as war or widespread-infrastructure-outage provisions, rather than on the aggregation concept itself.
Who it's relevant to
Inside Aggregation Risk
Common questions
Answers to the questions practitioners most commonly ask about Aggregation Risk.
