Decoding the world of cybersecurity

Digital footprints improve cyber claim prediction

Gallagher Re and KYND research suggests the complexity of an organisation’s internet-facing technology estate can improve cyber-claim prediction when combined with traditional underwriting data.

Digital footprints improve cyber claim prediction
Summary
  • The study analysed technographic and claims data covering more than 63,000 insured organisations.
  • ISP diversity, email-provider diversity, exposed services, and IP footprint were among the predictive external indicators.
  • The strongest model combined technical footprint data with traditional factors such as revenue, industry, and geography.

Cyber insurers can improve their prediction of claim frequency by measuring the size and complexity of an organisation’s external technology footprint alongside conventional underwriting data, according to research from Gallagher Re and security-data company KYND.

The study combines Gallagher Re claims and firmographic information with KYND technographic observations covering more than 63,000 insured organisations. It examined whether externally visible characteristics of an organisation’s digital estate could add predictive value beyond revenue, industry, and geography.

The analysis found that technographic information carried a useful signal on its own, but the strongest results came from combining it with traditional firmographic factors.

Among the most predictive indicators were the number of distinct internet service providers associated with an organisation, diversity of email providers, externally exposed services, and the size of its IP footprint.

The result challenges a relatively simple assumption in cyber underwriting: that organisations of similar size and sector present roughly comparable technical exposure. Two companies with equivalent revenue may operate very different external environments, from a relatively concentrated SaaS estate to hundreds of internet-facing systems distributed across providers and countries.

That difference creates more than additional assets to secure. Complexity affects inventory, ownership, patching, configuration management, identity, mergers and acquisitions, forgotten infrastructure, and the number of dependencies through which weaknesses can appear.

Gallagher Re’s analysis found that distinct ISP count was the strongest technographic contributor studied. The relationship remained visible across revenue bands, suggesting the signal was not simply acting as a proxy for company size.

The research does not establish that having more ISPs directly causes claims. A large external footprint may reflect organisational complexity, decentralised technology ownership, acquisitions, international operations, or other conditions associated with security risk.

That distinction is important if insurers use the findings in underwriting. Observable technical characteristics can improve segmentation without necessarily identifying the underlying cause of loss.

Cyber insurance has already become more data-driven as insurers seek evidence about controls such as multi-factor authentication, backups, endpoint security, privileged access, and vulnerability management. External scanning provides another source of information because it can be gathered without relying entirely on questionnaires completed by the insured.

That has an operational advantage for brokers and customers. Lengthy security questionnaires create friction and can become stale quickly, while external measurements can be refreshed more frequently.

They also have limitations. Internet scanning sees only part of an organisation’s environment and can misattribute infrastructure, miss compensating controls, or interpret deliberately exposed services as weaknesses without sufficient context.

Gallagher Re’s findings support using technographic data as an additional input rather than an automated underwriting verdict. Its combined model performed better than either technical or traditional information alone.

That approach reflects the broader maturity of the cyber insurance market. Early underwriting often depended heavily on organisation size and broad control questions. Claims history is now allowing insurers to test which measurable conditions actually correlate with losses and which security signals add little predictive value.

For insured organisations, the research could influence how cyber risk is priced and discussed. External estate complexity is often treated as an IT-management problem, but if insurers can demonstrate a reliable relationship with claims, reducing unnecessary exposure or consolidating poorly governed infrastructure may also affect insurance terms over time.

The study stops short of providing a deterministic risk score, and cyber losses remain influenced by threat activity, controls, human behaviour, and chance. Its more useful contribution is narrower: the visible size and structure of an organisation’s digital presence contains information about claim likelihood that revenue and sector alone cannot capture.

×