Cyber Reinsurance Capacity
Cyber reinsurance capacity refers to the amount of coverage that reinsurers are willing and able to provide to primary cyber insurers, allowing those insurers to offload part of the cyber risk they take on from policyholders. It effectively determines how much cyber risk the broader market can absorb, which in turn influences how much cyber insurance primary insurers can offer. It is a form of risk transfer between an insurer and a reinsurer, not a direct security or resilience measure.
Cyber reinsurance capacity is the aggregate limit of reinsurance protection made available by risk-bearing reinsurers to cedents (primary cyber insurers), enabling those insurers to transfer a portion of their cyber portfolio exposure. It is supplied by reinsurers such as Munich Re and Swiss Re, which provide capacity alongside underwriting expertise, actuarial support, and accumulation/exposure management. Capacity may be deployed through various structures; for example, Swiss Re has described aggregate excess-of-loss cyber reinsurance placements (excluding retrocession) increasing from USD 1,500m to USD 2,000m from 2019 to 2020. Capacity should be distinguished from the role of reinsurance brokers or intermediaries (such as Aon), which arrange and place reinsurance and hold market exposure data but do not themselves bear the underwritten risk. Available capacity is subject to prevailing market conditions, treaty wording, retentions, and the specific terms negotiated between cedent and reinsurer, and reinsurance capacity affects risk transfer within the sector rather than reducing the likelihood of cyber incidents.
Why it matters
Cyber reinsurance capacity effectively sets the ceiling on how much cyber risk the broader insurance market can absorb. When primary cyber insurers write policies, they retain some risk and transfer a portion to reinsurers; the amount of reinsurance capacity available influences how much cyber cover primary insurers are willing and able to offer to policyholders. When capacity expands, primary insurers generally have more room to grow their portfolios; when it contracts or hardens, primary insurers may reduce limits, tighten terms, or raise prices. This makes reinsurance capacity a structural factor behind the availability and cost of cyber insurance for end buyers, even though buyers rarely interact with reinsurers directly.
Reinsurers such as Munich Re and Swiss Re supply this capacity alongside underwriting expertise, actuarial support, and accumulation and exposure management. Swiss Re has publicly described total aggregate excess-of-loss cyber reinsurance placed (excluding retrocession) increasing from USD 1,500m to USD 2,000m from 2019 to 2020, an indication of how capacity levels can be tracked and how they shift year over year. According to research on cyber reinsurance, this capacity is regarded as crucial to fostering sustainable growth and enhancing risk transfer strategies within the cyber insurance sector.
It is important to keep the boundary of this concept clear: reinsurance capacity is a form of risk transfer between insurers and reinsurers. It affects how cyber risk is distributed across the sector, but it does not reduce the likelihood of cyber incidents and is not itself a security or resilience measure. Organizations relying on cyber insurance should understand that the availability of coverage upstream depends on reinsurance market conditions they do not control, and that transferring risk through insurance does not substitute for mitigation, incident response, or business continuity planning.
Who it's relevant to
Inside Cyber Reinsurance Capacity
Common questions
Answers to the questions practitioners most commonly ask about Cyber Reinsurance Capacity.