Skip to main content
Category: Loss Modeling & Aggregation

Frequency-Severity Model

Also known as: Frequency-Severity Method, Frequency and Severity Model, Frequency-Severity Modeling
Simply put

A frequency-severity model is an actuarial tool insurers use to estimate the expected cost of claims by looking at two separate factors: how many claims are likely to occur (frequency) and how much each claim is likely to cost on average (severity). Combining these estimates helps an insurer project the total expected losses over a given period. It is a modeling and pricing technique, not a coverage term, and it does not by itself determine whether any individual loss is covered under a policy.

Formal definition

The frequency-severity model is an actuarial approach that decomposes expected claims cost into two components estimated separately: claim frequency (the number of claims expected over a defined exposure period) and claim severity (the average cost per claim). Expected losses are derived by combining these components, and the method is applied in insurance pricing and reserving because of the features of contracts, policyholder behavior, and the claims databases insurers maintain. Practitioners may model the two components independently or account for dependence between frequency and severity, and modern implementations range from generalized linear and Poisson-based formulations to neural network-based approaches. As a modeling framework it informs how premiums and expected costs are estimated; it is distinct from policy wording, coverage triggers, sublimits, retentions, and exclusions, which govern whether and to what extent a specific loss is indemnified.

Why it matters

The frequency-severity model sits at the foundation of how insurers price cyber and other lines of coverage, because it separates two questions that behave very differently: how often losses occur and how large they are when they do. In cyber insurance specifically, this separation matters because the drivers of frequency (for example, the volume of attacks or the rate of policyholder incidents) are not the same as the drivers of severity (for example, the cost to restore data, respond to an incident, or defend a regulatory claim). Estimating them independently, or accounting for the dependence between them, gives underwriters a more structured way to project expected losses across a portfolio.

For buyers and brokers, understanding this model clarifies why premiums are set the way they are and why insurers pay close attention to the claims databases they maintain and to policyholder behavior. It also underscores an important boundary: the model informs pricing and reserving, but it does not determine whether any individual loss is indemnified. Whether a specific incident is covered depends on the policy wording, coverage triggers, sublimits, retentions, and exclusions, not on the actuarial technique used to estimate expected costs.

The distinction is also a reminder that risk transfer through insurance is not the same as risk mitigation. A frequency-severity model helps an insurer price the risk it assumes; it does nothing to reduce the likelihood or size of an actual loss for the insured. Organizations that treat a favorable premium as a substitute for controls and resilience planning misread what the model is doing.

Who it's relevant to

Underwriters and Actuaries
This is a core pricing and reserving tool. Underwriters and actuaries use frequency-severity modeling to translate claims data and exposure information into expected losses, deciding whether to model frequency and severity independently or to capture the dependence between them. The choice of formulation, from Poisson-based generalized linear models to neural network approaches, affects how expected costs are estimated but does not change the policy terms that govern coverage.
Insurance Brokers
Brokers benefit from understanding the model when explaining to clients why premiums are structured as they are and why insurers request detailed exposure and loss history. It also helps brokers reinforce a key point for buyers: the model shapes pricing, but coverage of any given loss depends on wording, triggers, sublimits, retentions, and exclusions, not on the actuarial method.
Risk Managers
Risk managers should recognize that a frequency-severity model reflects how an insurer prices the risk it assumes, not how likely or costly an incident is for their own organization after controls are applied. Insurance is risk transfer, not risk mitigation, and a favorable premium derived from such a model is not a substitute for reducing the frequency or severity of actual incidents through resilience and security measures.

Inside Frequency-Severity Model

Frequency Component
The modeled count of loss events expected over a defined period, typically a policy year. In cyber insurance contexts this captures how often incidents such as ransomware, data breaches, or business interruption events are expected to occur across a portfolio or for an individual insured. It is usually estimated with count distributions and reflects exposure factors such as industry, revenue, and control maturity.
Severity Component
The modeled monetary size of a loss given that an event has occurred. It is typically represented by a distribution that can produce a wide range of outcomes, including large tail losses. In cyber, severity may blend first-party elements (such as business interruption, data restoration, and cyber extortion payments) and third-party elements (such as privacy liability and regulatory defense), which behave differently and are often modeled separately.
Compound Loss Distribution
The combined output produced by convolving the frequency and severity components, representing aggregate expected losses over the period. This is commonly used to estimate metrics such as expected loss, and points along the loss curve used for pricing, capital allocation, and reinsurance decisions.
Exposure and Rating Variables
The characteristics fed into the model to differentiate risks, such as sector, size, data volume, and observed security controls. In cyber these variables are used qualitatively and quantitatively to modify frequency and severity assumptions, though the predictive strength of individual control indicators remains a subject of genuine debate among underwriters.
Correlation and Accumulation Assumptions
Assumptions about how losses depend on one another across insureds. Cyber events can be systemic (for example, a widely used software vulnerability or a common cloud provider outage), which can break the independence assumption underlying simple frequency-severity models and drive correlated accumulation across a portfolio.
Policy Structure Interaction
The layer of the model that applies retentions, sublimits, waiting periods, and aggregate limits to gross modeled losses to derive the insurer's net exposure. Whether a modeled loss translates into a paid claim depends on the specific policy wording, endorsements, exclusions, and conditions, so ground-up modeled loss is not the same as covered loss.

Common questions

Answers to the questions practitioners most commonly ask about Frequency-Severity Model.

Does a frequency-severity model predict whether my specific organization will suffer a cyber loss next year?
No. A frequency-severity model is an actuarial and portfolio-level construct that estimates the expected number of loss events (frequency) and the size of those events (severity) across a population of risks. It describes distributions and expected outcomes, not a deterministic forecast for any single insured. An individual organization may experience zero losses in a year the model deems high-frequency, or a severe loss in an otherwise quiet period. The model informs pricing and capital decisions; it does not tell you what will happen to you specifically.
Is a frequency-severity model a measure of my organization's resilience or security posture?
No. Frequency and severity are underwriting and risk-quantification concepts, not resilience metrics. They estimate how often losses occur and how large they are in monetary terms, whereas resilience concepts such as RTO, RPO, business continuity, and disaster recovery describe an organization's ability to maintain and restore operations. Controls and security posture may be inputs that influence an insurer's view of expected frequency or severity, but the model itself does not measure preparedness, and improving a modeled score is not the same as reducing the likelihood or impact of an actual incident.
What data is typically needed to parameterize a frequency-severity model for cyber risk?
Modelers generally seek historical loss and event counts to inform the frequency component and loss amounts (including first-party costs such as business interruption and data restoration, and third-party amounts such as liability and defense) to inform the severity component. Exposure information such as revenue, industry, data volumes, and control attributes is often used to normalize and segment the data. Because cyber loss history is comparatively short and rapidly evolving, practitioners frequently supplement internal data with external sources and expert judgment, and should treat resulting parameters as uncertain rather than settled.
How do policy features like sublimits, retentions, and waiting periods interact with a frequency-severity model?
These features reshape the modeled loss distribution before it reaches the insurer. Retentions and deductibles remove or reduce smaller losses, effectively truncating the lower end of the severity distribution and lowering apparent frequency of covered claims. Sublimits cap recovery for specified perils, censoring the upper tail for those categories. Waiting periods for business interruption exclude losses below a duration threshold. Modelers should apply these terms to ground-up losses to derive the ceded or retained distribution, and results are only meaningful when tied to the specific policy wording being analyzed.
Should frequency and severity be modeled separately or together, and why?
They are commonly modeled as separate distributions and then combined, because the drivers often differ: the factors influencing how often events occur may not be the same as those influencing how costly each event is. Separating them allows each component to be fitted, stressed, and adjusted independently, and supports a compound aggregate loss distribution. However, practitioners should consider whether frequency and severity are genuinely independent in cyber contexts, since systemic events can drive both simultaneously; where dependence exists, treating them as independent can understate tail risk.
What are the main limitations to communicate when presenting frequency-severity model output to decision-makers?
Key caveats include the scarcity and non-stationarity of cyber loss data, which makes parameters uncertain and historical experience an imperfect guide to a shifting threat landscape; the risk of correlated or systemic events that break independence assumptions and inflate the tail; sensitivity to the assumed severity distribution, particularly in the tail where data is thinnest; and the dependence of results on the specific coverage terms modeled. Decision-makers should understand that the output is a conditional estimate reflecting stated assumptions, not a precise prediction, and that genuine disagreement exists among practitioners about appropriate distributions and dependency structures for cyber risk.

Common misconceptions

A frequency-severity model tells you whether a given loss will be covered.
The model estimates the size and likelihood of losses; it does not determine coverage. Whether a modeled loss becomes a paid claim depends on policy wording, endorsements, exclusions (such as war, infrastructure, or failure-to-maintain-standards exclusions), conditions precedent, retentions, sublimits, waiting periods, and jurisdiction. Coverage determination is a separate, conditional exercise from actuarial modeling.
Because frequency and severity are modeled separately, they can be treated as independent, and cyber losses can be aggregated the way many traditional lines are.
Cyber losses can be strongly correlated through common dependencies such as shared software, cloud providers, or widespread vulnerabilities. Systemic events can cause many insureds to suffer losses simultaneously, undermining independence assumptions and producing accumulation that a naive frequency-severity model may understate.
Modeling loss frequency and severity accurately reduces the insured's actual risk of a cyber incident.
The model quantifies expected losses to support pricing and capital decisions; it is a risk-transfer and measurement tool, not a mitigation control. It does not lower the likelihood or impact of an incident. Reducing actual risk requires security controls, resilience planning, and response capability, which are distinct from insurance.

Best practices

Model first-party and third-party exposures separately where practical, since their frequency patterns, severity distributions, and drivers differ, and combining them can obscure the true shape of the loss curve.
Explicitly account for correlation and accumulation from systemic cyber events rather than assuming independence across insureds, and stress test the portfolio against common single points of failure such as shared software or cloud providers.
Apply policy structure (retentions, sublimits, waiting periods, and aggregate limits) to gross modeled losses to distinguish ground-up modeled loss from the insurer's net covered exposure, and document these adjustments clearly.
Pay close attention to the tail of the severity distribution, since cyber losses can produce large, low-frequency outcomes that dominate capital and reinsurance needs and are poorly captured by focusing on expected loss alone.
Treat exposure and control variables with appropriate humility, using qualified language about their predictive value and acknowledging the genuine disagreement among practitioners about which indicators reliably differentiate risk.
Revisit assumptions frequently, as cyber frequency and severity evolve with the threat landscape, and avoid presenting model outputs as coverage determinations or as substitutes for security and resilience measures.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.