The Earnings-Volatility Effect of Technology Supply-Chain Risk
On this page
- How Shared Technology Dependencies Move Reinsurance Earnings
- How much can one vendor outage move industry losses?
- Why did loss estimates for the same event vary so widely?
- How does correlated tech failure show up in quarterly earnings?
- What is the malicious-versus-accidental loss delta and why does it matter?
- How should actuaries price for shared-dependency correlation?
- What does this mean for combined ratio volatility?
- How does capital markets pricing already reflect this risk?
- How does this risk compare to traditional catastrophe volatility on the income statement?
- What signal should investors and analysts actually be watching for?
- How should this be reflected in multi-year reinsurance contract pricing?
- How should reinsurers communicate this risk in investor and analyst calls?
- What would tightening dependency visibility do for earnings stability?
- Sources
- Frequently Asked Questions
How Shared Technology Dependencies Move Reinsurance Earnings
A single vendor outage rarely shows up as a small, gradual drag on results. It tends to arrive as a lump, concentrated in one reporting period, and that pattern is what makes technology supply-chain dependency an earnings-volatility problem, not just an underwriting one.
How much can one vendor outage move industry losses?
Enough to register as a market-moving event on its own, even without a single traditional catastrophe involved.
Guy Carpenter's analysis of the July 2024 CrowdStrike outage estimated insured losses "between $300 million and $1 billion" for the actual, non-malicious event. That range came from a software configuration error, not a natural catastrophe or a targeted attack. Fewer than 1% of globally insured companies were directly affected, yet the aggregate number still reached into the hundreds of millions of dollars. That is the defining feature of technology supply-chain risk: low individual frequency, high aggregate severity when it hits.
Why did loss estimates for the same event vary so widely?
Because different modelers made different assumptions about scope, duration, and which policies would actually respond.
A Reinsurance News poll found 62% of respondents expected total industry losses to exceed $1 billion, while other named estimates ranged from Parametrix's $540 million to $1.5 billion, to CyberCube's $400 million to $1.5 billion for the standalone cyber market alone. Coalition estimated $960 million for US cyber writers specifically, while PCS designated the event a formal Cyber Catastrophe Loss Event above $250 million in industry insured losses. That spread, across credible modelers analyzing the same underlying event, shows how much measurement uncertainty still exists in this risk category. Why reinsurance leaders misdiagnose technology supply-chain dependencies explains part of why the estimates diverge so much: portfolios were not consistently tagged for this exposure beforehand.
How does correlated tech failure show up in quarterly earnings?
As a sudden, concentrated hit in a single reporting period, rather than a smooth trend line.
Most underwriting risk categories build up gradually, giving actuarial time to adjust reserves incrementally as experience develops. A correlated technology event does the opposite, converting many small, previously invisible exposures into one large loss recognized all at once. Analysts and rating agencies tend to react more strongly to that kind of surprise than to a comparable loss spread predictably across several quarters. Earnings volatility from this source is less about the total dollar amount and more about how suddenly it appears.
What is the malicious-versus-accidental loss delta and why does it matter?
It shows that intent alone, applied to the same technical failure, can roughly double the financial impact.
Guy Carpenter's analysis found that a hypothetical malicious version of the CrowdStrike outage "could have reached between $600 million and $2 billion," compared to $300 million to $1 billion for the accidental version. That delta matters because it means the earnings tail risk from shared technology dependency is not fixed; it depends on factors reinsurers cannot control or predict, like whether a future failure is deliberate. Planning only around historical accidental outages likely understates the true tail risk sitting in the book. This is a case where the worst plausible scenario deserves as much planning attention as the most likely one.
How should actuaries price for shared-dependency correlation?
By explicitly modeling technology-stack overlap, instead of assuming policyholders in different sectors are independent of each other.
Moody's RMS has noted that losses can propagate "through shared technology dependencies that traditional portfolio views struggle to make visible," which is exactly the assumption actuarial pricing needs to stop making by default. The Exposure Concentration Risk AI Agent can incorporate technology and supply-chain concentration data directly into pricing inputs, rather than treating it as an afterthought. Pricing that ignores this correlation will look adequate for years, right up until a correlated event proves otherwise. Building the correlation into pricing now is cheaper than re-pricing after a loss forces the correction.
What does this mean for combined ratio volatility?
A wider tail on the combined ratio distribution, even when the average loss ratio looks perfectly stable.
| Metric | Effect of unmanaged tech dependency risk |
|---|---|
| Average annual loss ratio | Often looks stable in normal years |
| Combined ratio tail risk | Materially wider due to rare, correlated events |
| Reserve volatility | Concentrated in the quarter an event occurs |
| Rating agency perception | More sensitive to surprise than to average performance |
Executives focused only on the average metric in the top row are missing where the real volatility risk actually sits.
How does capital markets pricing already reflect this risk?
Through an uncertainty premium already embedded in cyber and technology-related ILS and retro pricing.
The market has, in effect, already priced in some of this correlation risk, even where individual reinsurers have not yet modeled it internally. That gap between market pricing and internal modeling is itself useful information, since it suggests the capital markets see more correlation risk here than many internal models currently capture. Closing that gap internally, through better data capture, gives a reinsurer a more accurate view of its own true cost of capital for this risk. Ignoring it means paying the market's uncertainty premium without ever quantifying what it is actually being charged for.
How does this risk compare to traditional catastrophe volatility on the income statement?
Catastrophe losses follow a recognizable season and geography, while technology dependency losses can strike in any quarter with no comparable pattern to plan around.
Actuarial teams have decades of experience budgeting for hurricane or wildfire season, building that seasonality directly into reserving and capital planning. A shared technology dependency failure carries no equivalent calendar; a major outage is as likely in a quiet first quarter as in a historically loss-heavy one. That unpredictability is a distinct planning challenge, separate from the severity of the loss itself, because it removes a variable actuarial teams have long relied on. Building technology dependency into planning means accepting that this particular risk cannot be smoothed using the same seasonal logic applied to weather-driven catastrophe.
What signal should investors and analysts actually be watching for?
Disclosed technology and vendor concentration metrics, not just the headline combined ratio, are the more useful leading indicator of true earnings risk.
A stable combined ratio in an average year says little about how concentrated a reinsurer's book actually is around a handful of shared vendors. A reinsurer willing to disclose vendor concentration data gives analysts a genuine leading indicator, rather than waiting for a correlated event to reveal the concentration after the fact. As more reinsurers begin capturing and reporting this data, comparing peers on concentration discipline, not just historical loss ratios, is likely to become a more standard part of analyst coverage. Reinsurers ahead of that shift will have a clearer, more credible story to tell than those still describing this risk only in general terms.
How should this be reflected in multi-year reinsurance contract pricing?
Multi-year contracts need a built-in mechanism to reassess technology concentration as it shifts within the contract term, rather than locking in a single point-in-time assumption.
A three-year treaty priced on a snapshot of vendor exposure at inception can be materially out of date by its final year, given how quickly technology adoption patterns shift. Without a reopener or review clause, that pricing gap sits unaddressed until the next renewal, even if concentration has grown well beyond what was originally priced. Building in a scheduled mid-term review, tied specifically to technology concentration data, protects both sides from a multi-year mismatch neither one intended.
How should reinsurers communicate this risk in investor and analyst calls?
Naming specific mitigation steps already taken, rather than only acknowledging the risk exists, gives analysts more confidence in future earnings stability.
An acknowledgment that "technology concentration risk is being monitored" reassures nobody, since it provides no way to judge whether that monitoring is meaningful. Naming concrete steps, such as a completed vendor concentration mapping exercise or a specific retro purchase targeted at a known concentration point, gives analysts something they can actually evaluate. This kind of specificity tends to reduce, rather than invite, follow-up questions on earnings calls, since it demonstrates the risk is being actively managed rather than passively watched. Reinsurers that get ahead of this disclosure trend are likely to face an easier set of questions than those still speaking about the risk only in general terms.
What would tightening dependency visibility do for earnings stability?
It would narrow the range of plausible outcomes heading into every reporting period, reducing the odds of a large single-quarter surprise.
That narrower range is the practical payoff of the diagnostic work covered in why reinsurance leaders misdiagnose technology supply-chain dependencies, and it feeds directly into the executive questions raised in what the executive committee must ask about technology supply-chain risk. A parallel earnings-stability argument applies to the treaty-wording side of the cyber book, discussed in the capital drag created by cyber event definitions across treaties. Neither fix requires new capital, only better visibility into a correlation that already exists in the book today.
Technology supply-chain dependency does not create new risk out of nothing. It reveals correlation that was always present in the portfolio, and the reinsurers who measure it first will be the ones least surprised by their own next quarter.
Sources
- Insurance Business Magazine, "CrowdStrike outage - how much did it cost the re/insurance industry?"
- Reinsurance News, "Poll predicts CrowdStrike IT outage losses could exceed $1bn for re/insurance industry"
- Moody's RMS, "Introducing Moody's RMS Cyber Solutions Version 10.0"
Frequently Asked Questions
How much can one vendor outage actually move industry losses?
A single software outage has been estimated to cost the reinsurance industry between $300 million and $1 billion, based on modeled analysis of the July 2024 CrowdStrike event.
Why did loss estimates for the same event vary so widely across modelers?
Different modelers used different assumptions about affected sectors, business interruption periods, and policy trigger conditions, producing a wide dispersion of loss ranges.
How does correlated tech failure show up in quarterly earnings?
It arrives as a sudden reserve strengthening or loss recognition in a single quarter, rather than smoothing gradually across periods like more predictable risks.
What is the malicious-versus-accidental loss delta and why does it matter?
Guy Carpenter's analysis found a hypothetical malicious version of the CrowdStrike outage could have cost twice as much, showing intent alone can double the earnings impact of the same technical failure.
How should actuaries price for shared-dependency correlation?
By explicitly modeling technology-stack overlap across the book, rather than assuming independence between policyholders in different industries or regions.
What does this mean for combined ratio volatility specifically?
It raises the tail risk on the combined ratio even when the average loss ratio looks stable, because the volatility is concentrated in rare, correlated events.
How does capital markets pricing already reflect this risk?
ILS and retro pricing already carries an uncertainty premium for cyber and technology risk, reflecting the market's own recognition of this correlation.
What would tightening dependency visibility do for earnings stability?
It would narrow the range of plausible loss outcomes going into each reporting period, reducing the size of any single-quarter earnings surprise.

Hitul Mistry
CEO, Insurnest
An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.
View LinkedIn profile →