Simplifying Cyber Cat(astrophe)s with Cyber Kittens: Power Law Plausibility for Cyber Insurance Risks

Max Henderson, Anton Solomko, Henry Simmons, Nick Jin, Maximilian Kloucek, John Wingate

Abstract

Cyber insurance requires accurate modeling of worst-case catastrophic (cat) events, but the field lacks robust quantitative approaches for estimating upper-bound losses. Building on a recent dataset of 24 cyber cat events over 30 years, this work tests whether cyber economic losses follow a power law distribution. We analyze "cyber kittens" - sub-1B USD events distinguished from cat events (1B+ USD) only by magnitude - extracted via LLM from cyber insurance claims data (2020-2024). Using victim count (weighted by claim year) as a proxy for economic loss, we link kitten-sized events to known cat events to estimate losses. The kitten distribution proved consistent with the cat dataset, and power laws were statistically plausible: each order-of-magnitude increase in event size corresponds to a 5-7x drop in probability. Extrapolating, an event 100x the largest 2020-2024 cat event is expected roughly every 206 years, translating to 100-250B USD in losses - catastrophic, but not extraordinary relative to other insurance lines.

Source: arxiv · PDF

Read the AI summary, key takeaways and discussion on WOBR Quant Research.


Open in the WOBR AI app → · WOBR.AI home