Skip to main content
Category: Premium & Actuarial Pricing

Frequency-Severity Modeling

Also known as: Frequency-Severity Method, Frequency and Severity Models
Simply put

Frequency-severity modeling is an actuarial approach insurers use to estimate the expected cost of claims by separately examining two factors: how often claims are likely to occur (frequency) and how much each claim is likely to cost (severity). Combining these two estimates helps an insurer predict the total claims cost it may face over a given period. This is a pricing and forecasting tool, not a measure of an organization's resilience or its ability to prevent incidents.

Formal definition

Frequency-severity modeling decomposes expected claims cost into two components estimated separately: claim frequency (the number of claims expected over a defined exposure period) and claim severity (the average cost per claim). The expected aggregate loss is typically derived by combining these components, and each may be modeled using distributional and regression techniques, including approaches that account for dependence between frequency and severity rather than assuming independence. The method underpins pricing, reserving, and loss forecasting; it estimates expected costs conditional on the modeling assumptions and data used, and does not itself determine whether any particular loss is covered under a policy, which depends on the specific policy wording, endorsements, exclusions, and conditions.

Why it matters

Frequency-severity modeling sits at the heart of how cyber insurers price policies, set reserves, and forecast expected losses. Because cyber risk is dynamic and data on losses remains comparatively immature relative to established lines such as property or auto, the discipline of separating how often claims occur from how costly each one is gives underwriters a structured way to reason about an otherwise volatile exposure. For risk managers and brokers, understanding this decomposition clarifies why premiums move the way they do: a rise in the frequency of ransomware claims and a rise in the severity of individual events push pricing in the same direction but through different levers.

The method also carries an important limitation that professionals should keep front of mind. Frequency-severity modeling estimates expected claims cost conditional on the data and assumptions feeding the model; it is a pricing and forecasting instrument, not a measure of any single organization's resilience or its ability to prevent an incident. A well-modeled portfolio price says nothing definitive about whether a particular insured will suffer a loss, and it does not determine whether a given loss will be covered. Coverage always turns on the specific policy wording, endorsements, exclusions, and conditions rather than on the actuarial model that priced the policy.

Because cyber losses can exhibit dependence between how frequently events occur and how severe they become, modelers increasingly avoid assuming that frequency and severity are independent. Recognizing that dependence matters for accurate forecasting, since events that cluster or correlate can produce aggregate outcomes that a naive independent-component model would understate.

Who it's relevant to

Underwriters and Actuaries
For those pricing and reserving cyber portfolios, frequency-severity modeling is a core technique for translating loss experience into expected cost. It informs premium setting and reserve adequacy, but its outputs are only as reliable as the data and distributional assumptions behind them, and modelers must decide whether to treat frequency and severity as independent or dependent.
Insurance Brokers
Brokers benefit from understanding the mechanics behind premium movements so they can explain to clients why pricing shifts as claim frequency or severity trends change. This understanding also helps brokers distinguish actuarial pricing from coverage scope, reminding clients that a competitively priced policy is not a guarantee that a given loss will be covered.
Risk Managers
Risk managers can use knowledge of frequency-severity modeling to interpret how insurers view their exposure and to frame internal conversations about risk transfer. It is important to recognize that this model prices risk; it does not reduce the likelihood of an incident or substitute for resilience measures, which remain the organization's own responsibility.
Compliance and Finance Professionals
Those responsible for financial forecasting and reserve reporting rely on the aggregate loss estimates that frequency-severity modeling produces. They should treat these figures as conditional estimates dependent on modeling assumptions rather than as precise predictions of actual future losses.

Inside Frequency-Severity Modeling

Frequency Component
The modeled estimate of how often loss events are expected to occur over a defined period, typically expressed as an annual count or rate. In cyber risk, frequency reflects the likelihood of events such as ransomware attacks, data breaches, or business interruption triggers, and is distinct from the size of any individual loss.
Severity Component
The modeled estimate of the financial magnitude of a loss given that an event occurs, often represented as a probability distribution rather than a single figure. Severity in cyber contexts may combine first-party losses (such as business interruption and data restoration) and third-party losses (such as privacy liability and regulatory defense), which should be modeled with awareness of their differing drivers.
Loss Distribution
The combined output produced by convolving the frequency and severity components, describing the range of possible aggregate losses and their associated probabilities. This distribution supports metrics such as expected loss and tail estimates used in pricing and capital decisions.
Aggregation and Correlation Assumptions
Assumptions about how individual events or exposures relate to one another, including the potential for a single cause (such as a widely used software vulnerability or a shared cloud provider) to trigger many correlated losses simultaneously. These assumptions materially affect tail severity estimates.
Policy Structure Overlay
The application of retentions, sublimits, waiting periods, and aggregate limits to the modeled gross losses to derive the insured or retained portion. This overlay translates raw loss distributions into figures relevant to a specific policy, and its effect depends on the specific wording, endorsements, and exclusions.

Common questions

Answers to the questions practitioners most commonly ask about Frequency-Severity Modeling.

Does frequency-severity modeling predict whether my organization will suffer a cyber incident?
No. Frequency-severity modeling is an actuarial and risk-quantification technique that estimates the expected number of loss events (frequency) and the size of losses when they occur (severity) across a portfolio or over time. It describes probability distributions and expected values; it does not forecast a specific incident for a specific insured on a specific date. It is a tool for pricing, capital allocation, and risk-appetite decisions rather than a predictive alarm. Its outputs are also only as sound as the underlying data and assumptions, which for cyber risk are often sparse, non-stationary, and subject to correlated or systemic events that can undermine independence assumptions.
Is running a frequency-severity model a form of resilience or risk mitigation?
No. Frequency-severity modeling is an analytical and measurement activity, not a control. It does not reduce the likelihood of an incident (mitigation), remove an exposure (avoidance), or transfer financial consequences (insurance). It can inform those decisions by quantifying exposure and helping compare the cost of retention against the cost of transfer, but the modeling itself changes nothing about the organization's actual security posture or recovery capability. Treating the existence of a model as evidence of preparedness confuses measuring a risk with managing it.
What data inputs are typically needed to build a frequency-severity model for cyber risk?
Frequency-severity models generally draw on historical loss and claims data, exposure characteristics (such as revenue, industry, records held, and technology dependencies), and assumptions about how those characteristics relate to loss potential. Because internal cyber loss histories are often limited, practitioners frequently supplement them with external or industry datasets and expert judgment, subject to the specific methodology chosen. Users should document data sources, note gaps and biases, and recognize that reliance on scarce or non-representative data increases uncertainty in the outputs. The quality and comparability of the data materially affect how much weight the results can bear.
How should frequency and severity be treated when they are not independent?
Independence between frequency and severity, and between individual loss events, is a simplifying assumption that may not hold for cyber risk. Systemic events, common software dependencies, and shared service providers can cause many losses to occur together and at correlated magnitudes. Where dependence is material, practitioners typically address it through correlation or dependency structures, scenario-based or accumulation analysis, and stress testing rather than relying on a naive convolution of independent distributions. Making these assumptions explicit is important, because understated correlation can significantly understate tail exposure.
How does frequency-severity modeling relate to setting retentions, sublimits, and limits?
Modeled loss distributions can inform structuring decisions by illustrating how expected and tail losses fall across different attachment points. Higher-frequency, lower-severity outcomes tend to inform expectations around retentions and working layers, while lower-frequency, higher-severity outcomes inform limit and sublimit adequacy for catastrophic scenarios. However, the model output is an input to judgment, not a determinant of coverage. What is ultimately paid depends on the policy wording, applicable retentions, sublimits, exclusions, and conditions, which the model does not itself dictate. Structuring decisions also reflect risk appetite, capital constraints, and market conditions beyond the model.
How should the uncertainty in a frequency-severity model be communicated to decision-makers?
Because cyber frequency-severity estimates rest on limited and shifting data and on contestable assumptions, results are best presented as ranges or distributions with clearly stated assumptions, rather than as single point figures. Sensitivity analysis showing how outputs move as key assumptions change, disclosure of data limitations, and scenario or stress views of tail outcomes help decision-makers understand the confidence they can place in the numbers. Practitioners generally disagree on aspects of cyber modeling methodology, so documenting choices and their rationale supports transparent, defensible use of the results.

Common misconceptions

Frequency-severity modeling predicts whether and when a specific organization will suffer a loss.
The approach produces probabilistic estimates across a distribution of possible outcomes, not deterministic forecasts for an individual insured. It informs pricing, capital, and portfolio decisions but does not tell you if or when any particular event will occur.
A robust model reduces the likelihood or impact of a cyber incident.
Modeling is an analytical and risk-quantification exercise, not a control or resilience measure. It does not mitigate risk; reducing likelihood requires security controls, and reducing impact requires resilience measures such as business continuity and disaster recovery planning. Modeling only characterizes risk that is transferred or retained.
Modeled frequency and severity can be estimated independently and simply multiplied together.
While the components are conceptually distinct, treating them as fully independent can understate tail risk. Correlation and aggregation effects, where one cause drives many simultaneous or larger losses, mean the combined distribution requires explicit assumptions rather than a naive product of averages.

Best practices

Model frequency and severity as distributions with explicit uncertainty rather than relying on single point estimates, and document the assumptions behind each component.
Separate first-party and third-party loss drivers within the severity component, since their triggers, timing, and applicable policy terms differ and should not be conflated.
Make aggregation and correlation assumptions explicit, particularly for common causes such as shared software or infrastructure dependencies that can convert many exposures into a correlated tail event.
Apply policy structure, retentions, sublimits, waiting periods, and aggregate limits, as a distinct overlay on gross modeled losses, recognizing that whether a loss is covered depends on the specific wording, endorsements, and exclusions.
Communicate model outputs as probabilistic risk quantification, and pair them with information on controls and resilience measures so stakeholders understand that modeling characterizes risk but does not reduce it.
Periodically revisit and stress-test assumptions against emerging exposures and areas of genuine disagreement among underwriters and resilience professionals, and flag where data is sparse rather than overstating precision.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps