Cyber Risk Frequency Modelling Using Hawkes Processes: Calibration on Attack and Vulnerability Data

  • 1 views

  • 0 comments

  • 0 favorites

  • AAE AAE
  • 249 media
  • uploaded July 31, 2026

With the growing digitalization of the economy, cyber risk has emerged as a systemic threat, capable of triggering severe financial losses and challenging traditional insurance mechanisms. To quantify this risk from an insurance perspective, there is a growing need for mathematical models that reflect key features of cyber risk: attacks contagion, heterogeneity in propagation, exploitation of software vulnerabilities, and the adaptive response of defenders. In this paper, we propose a model for the frequency of cyber attacks that incorporates the latter structural features : a Hawkes process with external excitation, stochastic marks, and a reaction phase. This model is calibrated on real-world data combining cyber incidents from the Hackmageddon database and software vulnerabilities from the National Vulnerability Database (NVD). Our results show that disregarding vulnerability-driven excitation leads to a significant overestimation of endogenous contagion. We further simulate cyber-pandemic scenarios, where an insurer faces a surge in attacks with a limited response capacity. By exploring different mitigation and response strategies, we identify conditions under which the insurer remains not overwhelmed and quantify the effectiveness of the proposed reaction measures.

Tags:
Categories: AFIR / ERM / RISK

Additional files

More Media in "AFIR / ERM / RISK"

0 Comments

There are no comments yet. Add a comment.