Skip to main content
Category: Loss Modeling & Aggregation

Susceptibility

Simply put

Susceptibility is the quality or state of being susceptible, that is, the lack of ability to resist some external agent or influence. In everyday and general usage it describes how readily something can be affected, harmed, or changed by an outside force. The precise meaning varies considerably depending on the field in which the term is used.

Formal definition

In general usage, susceptibility denotes the quality or state of being susceptible, especially a lack of ability to resist some extraneous agent. The concept is applied differently across specialized domains: in physics it is a quantification of the change in an extensive property under variation of an intensive property (for example, magnetic susceptibility measures the extent to which a substance becomes magnetized when placed in an external magnetic field); in genetics it refers to the state of being predisposed or sensitive to developing a certain disease; and in microbiology it is assessed through antimicrobial susceptibility testing. The evidence provided does not include a cyber insurance or organizational resilience definition of this term, so any application to those domains is out of scope for this entry.

Why it matters

Susceptibility is a general-purpose term that appears across many disciplines to describe how readily something can be affected, harmed, or changed by an external force. Because its precise meaning shifts with context, professionals should be careful not to assume a single fixed definition. In everyday usage it captures a lack of ability to resist some extraneous agent, while specialized fields assign it more rigorous and quantitative meanings.

The importance of the term therefore lies chiefly in disambiguation. In physics it is a measurable quantity, for example, magnetic susceptibility measures the extent to which a substance becomes magnetized when placed in an external magnetic field. In genetics it describes a predisposition or sensitivity to developing a certain disease, and in microbiology it is evaluated through antimicrobial susceptibility testing. These are distinct technical concepts that happen to share a word.

The evidence provided does not establish a cyber insurance or organizational resilience definition of susceptibility. Any application of the term to those domains is out of scope for this entry, and readers should not infer a coverage, underwriting, or resilience meaning from the general-usage definition presented here.

Who it's relevant to

Readers seeking terminology clarity
Professionals who encounter the word susceptibility in cross-disciplinary material can use this entry to confirm that its meaning is context-dependent and that no established cyber insurance or organizational resilience definition is supported by the evidence here.
Physical scientists and engineers
In physics the term is a quantitative measure, such as magnetic susceptibility, the extent to which a substance becomes magnetized in an external magnetic field, rather than a general descriptor of vulnerability.
Genetics and healthcare professionals
In genetics, susceptibility refers to being predisposed or sensitive to developing a certain disease, and in microbiology it is assessed through antimicrobial susceptibility testing. These are distinct clinical and laboratory concepts.

Inside Susceptibility

Threat Exposure
The degree to which an organization's assets, systems, or processes are reachable by relevant threat actors and attack vectors. Susceptibility reflects how exposed an entity is before considering the effectiveness of controls, and it varies by industry, technology stack, and connectivity.
Vulnerability Presence
Known or latent weaknesses in software, configurations, dependencies, or human processes that could be exploited. Susceptibility is heightened where unpatched systems, misconfigurations, or unaddressed known vulnerabilities exist.
Control Weakness or Absence
Gaps in preventive and detective safeguards (for example, access management, segmentation, or monitoring). Susceptibility increases where controls are missing, immature, or inconsistently applied, distinct from the resilience question of how quickly the organization recovers after an event.
Attack Surface Characteristics
The scope and composition of assets that could be targeted, including internet-facing systems, third-party and supply-chain connections, and identity infrastructure. A larger or more complex attack surface generally raises susceptibility.
Human and Organizational Factors
Susceptibility to social engineering, phishing, and insider actions driven by awareness levels, process discipline, and governance. These factors are often decisive and are not addressed by technical controls alone.
Underwriting Relevance
In cyber insurance, susceptibility informs an insurer's assessment of the likelihood of a loss event during risk selection and pricing. It is an input to underwriting judgment and is distinct from coverage terms such as triggers, sublimits, retentions, and waiting periods, which govern how a loss is treated once it occurs.

Common questions

Answers to the questions practitioners most commonly ask about Susceptibility.

Does buying cyber insurance reduce our susceptibility to an attack?
No. Susceptibility describes the degree to which an organization is exposed or vulnerable to a threat materializing, and insurance is a risk transfer mechanism that addresses the financial consequences of a loss after it occurs. It does not reduce the likelihood that an incident happens, nor does it by itself constitute resilience. Lowering susceptibility requires risk mitigation activities such as controls, patching, and configuration hardening. Insurance and susceptibility reduction operate on different parts of the risk equation and should not be treated as substitutes.
Is susceptibility just another word for vulnerability?
Not exactly, and the distinction matters. A vulnerability typically refers to a specific weakness that could be exploited, whereas susceptibility describes the broader condition or degree of exposure to a threat, which can be influenced by many factors including the presence of vulnerabilities, the effectiveness of controls, the threat environment, and organizational practices. Treating the two as interchangeable can lead to underestimating exposure that arises from factors beyond individually cataloged vulnerabilities. Usage can vary across security frameworks and standards bodies, so it is worth confirming how a given source defines each term.
How does an underwriter assess an applicant's susceptibility?
Underwriting practices vary by insurer and are not standardized, but assessment commonly draws on application questionnaires, evidence of security controls, external scanning or ratings data, and interviews. The goal is to gauge exposure to loss and inform pricing, retentions, sublimits, and conditions. Some insurers may condition coverage or apply endorsements based on the presence or absence of specified controls. Because approaches differ among underwriters and there is genuine disagreement about which indicators best predict loss, applicants should not assume any single assessment method or outcome.
Can reducing susceptibility affect our policy terms or premium?
In many cases demonstrating stronger controls and lower exposure can influence underwriting outcomes, potentially affecting premium, retention levels, available limits, or the willingness of an insurer to offer certain coverages. However, this depends on the insurer's methodology and the specific wording of the policy. Note that some policies contain conditions precedent or failure-to-maintain-standards exclusions, so representations made about susceptibility-reducing controls during underwriting may carry contractual significance later. Confirm how any control commitments are reflected in the policy wording before relying on them.
How should we prioritize which susceptibilities to address first?
Prioritization typically combines an estimate of likelihood with the potential impact of a threat materializing, though methodologies differ across risk management frameworks. Organizations often focus first on exposures that combine high likelihood with severe consequences, and consider which mitigation options are feasible relative to risk acceptance or avoidance. This is a risk mitigation exercise distinct from the risk transfer decision about what to insure. Coordinating the two can help ensure that residual exposure retained after mitigation aligns with the coverage, retentions, and limits carried.
Does lowering susceptibility improve our recovery capability?
Not directly. Reducing susceptibility lowers the likelihood or degree of exposure to an incident, while recovery capability concerns how quickly and completely operations and data are restored after an incident, measured through concepts such as recovery time objective and recovery point objective within business continuity and disaster recovery planning. Both are components of resilience but address different phases. An organization should treat susceptibility reduction and recovery planning as complementary rather than assume that improving one strengthens the other.

Common misconceptions

Buying cyber insurance reduces an organization's susceptibility to an incident.
Insurance is a risk transfer mechanism that addresses the financial consequences of a loss; it does not reduce the likelihood of an incident occurring. Susceptibility is lowered through risk mitigation (controls, patching, awareness) or risk avoidance, not through the purchase of a policy.
Low susceptibility means an organization is resilient.
Susceptibility concerns the likelihood of being successfully attacked, while resilience concerns the ability to continue operating and recover afterward, measured through concepts such as RTO and RPO and supported by business continuity and disaster recovery planning. An organization can have reduced susceptibility yet still recover poorly, or be highly susceptible yet recover quickly.
Susceptibility is a fixed property of an organization.
Susceptibility is dynamic. It changes as the attack surface, threat landscape, control maturity, and third-party relationships evolve. It should be reassessed periodically rather than treated as a one-time determination.

Best practices

Assess susceptibility separately from resilience: evaluate the likelihood of successful compromise (exposure, vulnerabilities, control gaps) independently from recovery capability metrics such as RTO and RPO, and document each on its own terms.
Maintain an accurate inventory of internet-facing assets, identity infrastructure, and third-party or supply-chain connections to understand the attack surface that drives susceptibility.
Prioritize remediation of known vulnerabilities and misconfigurations, and track control maturity over time so that susceptibility assessments reflect current rather than historical conditions.
Address human and organizational factors through awareness, process discipline, and governance, recognizing that technical controls alone do not eliminate social-engineering susceptibility.
Treat insurance as a complement to, not a substitute for, mitigation: use risk transfer to address residual financial exposure while continuing to reduce susceptibility through controls, and be mindful that failure-to-maintain-standards exclusions and conditions precedent may affect coverage depending on the specific policy wording.
Reassess susceptibility on a recurring basis and after significant changes to technology, vendors, or the threat landscape, and align these findings with underwriting discussions rather than assuming they map directly onto coverage terms.
Promotional banner for the Penetration Report Template Kit