Frequency-Severity Modeling
Frequency-severity modeling is an actuarial approach insurers use to estimate the expected cost of claims by separately examining two factors: how often claims are likely to occur (frequency) and how much each claim is likely to cost (severity). Combining these two estimates helps an insurer predict the total claims cost it may face over a given period. This is a pricing and forecasting tool, not a measure of an organization's resilience or its ability to prevent incidents.
Frequency-severity modeling decomposes expected claims cost into two components estimated separately: claim frequency (the number of claims expected over a defined exposure period) and claim severity (the average cost per claim). The expected aggregate loss is typically derived by combining these components, and each may be modeled using distributional and regression techniques, including approaches that account for dependence between frequency and severity rather than assuming independence. The method underpins pricing, reserving, and loss forecasting; it estimates expected costs conditional on the modeling assumptions and data used, and does not itself determine whether any particular loss is covered under a policy, which depends on the specific policy wording, endorsements, exclusions, and conditions.
Why it matters
Frequency-severity modeling sits at the heart of how cyber insurers price policies, set reserves, and forecast expected losses. Because cyber risk is dynamic and data on losses remains comparatively immature relative to established lines such as property or auto, the discipline of separating how often claims occur from how costly each one is gives underwriters a structured way to reason about an otherwise volatile exposure. For risk managers and brokers, understanding this decomposition clarifies why premiums move the way they do: a rise in the frequency of ransomware claims and a rise in the severity of individual events push pricing in the same direction but through different levers.
The method also carries an important limitation that professionals should keep front of mind. Frequency-severity modeling estimates expected claims cost conditional on the data and assumptions feeding the model; it is a pricing and forecasting instrument, not a measure of any single organization's resilience or its ability to prevent an incident. A well-modeled portfolio price says nothing definitive about whether a particular insured will suffer a loss, and it does not determine whether a given loss will be covered. Coverage always turns on the specific policy wording, endorsements, exclusions, and conditions rather than on the actuarial model that priced the policy.
Because cyber losses can exhibit dependence between how frequently events occur and how severe they become, modelers increasingly avoid assuming that frequency and severity are independent. Recognizing that dependence matters for accurate forecasting, since events that cluster or correlate can produce aggregate outcomes that a naive independent-component model would understate.
Who it's relevant to
Inside Frequency-Severity Modeling
Common questions
Answers to the questions practitioners most commonly ask about Frequency-Severity Modeling.
