Cyber Risk Segmentation and Automated Accumulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to accurately capture and manage diverging cyber risks, particularly those related to non-tangible assets and business interruptions, as they are not designed to handle the complexity of cyber-related incidents, leading to incomplete risk coverage and operational instability.

Innovation Solution

A dynamic cyber risk insurance system with an automated resource-pooling mechanism that segments cyber risks into parameterizable exposure segments, using a searchable trigger table and trigger module to detect and accumulate measuring values, allowing for weighted accumulation and adaptive risk management across various industries and geographic regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional insurance systems are used to cover cyber risks, then tangible assets can be covered, but non-tangible assets and business interruptions cannot be adequately covered

Engineering Contradiction:
Improvecoverage scopeVSAvoidrisk coverage completeness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments cyber risks into distinct categories (data breaches, network damage, business interruption, etc.) and creates separate measurement and accumulation mechanisms for each segment, allowing comprehensive coverage of both tangible and non-tangible assets through structured division of risk types

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal measurement framework that can handle multiple types of cyber risks (data, network, operations, business interruption) through a single integrated platform, enabling one system to serve multiple coverage functions that traditional separate insurance products could not provide

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If manual risk assessment methods are used, then simple risks can be evaluated, but complex diverging cyber risks cannot be accurately measured

Engineering Contradiction:
Improverisk assessment efficiencyVSAvoidrisk measurement accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent replaces manual mechanical risk assessment processes with an automated electronic measurement system that uses computers to automatically measure, calculate, and accumulate cyber risk values, maintaining high efficiency while achieving precise measurement of complex diverging risks through algorithmic computation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an intermediary measurement and accumulation device that acts as a mediator between diverse cyber risk sources and the final risk assessment output, standardizing and precision-measuring various risk types before aggregation through this intermediate layer

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If comprehensive cyber risk coverage is pursued, then all risk types can be covered, but system complexity increases

Engineering Contradiction:
Improverisk coverage comprehensivenessVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides comprehensive cyber risk coverage into structured segments (different risk types, measurement parameters, and accumulation categories), allowing the system to handle complexity through organized segmentation rather than monolithic structure, making comprehensive coverage manageable and implementable

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses parameter-based measurement and weighting mechanisms that can be adjusted to reflect different risk scenarios, allowing comprehensive coverage through parameter variation rather than structural complexity, enabling flexible adaptation to various cyber risk conditions

Inventive Principle:
Principle #35Parameter changes

4Reliability

If static risk measurement systems are used, then current risks can be assessed, but dynamic new risks cannot be adapted to

Engineering Contradiction:
Improverisk assessment stabilityVSAvoiddynamic risk adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a dynamic measurement and accumulation system that can adapt to new cyber risk types and conditions while maintaining stable core measurement principles, allowing the system to evolve with changing threat landscapes through flexible parameter adjustment and expanded measurement capabilities

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3123389B1System for the measurement and automated accumulation of diverging cyber risks, and corresponding method thereof
Publication Date: 2022.09.21 SWISS REINSURANCE CO LTD
  • EP3123389B1 patent drawingFigure 1
  • EP3123389B1 patent drawingFigure 2

AI summary

Proposed are a system and a method for the automated measurement, accumulation and monitoring of diverging cyber risks, wherein risk components (21, 22, 23,...) are exposed by electronic means (213, 223, 233) of the risk components (21, 22, 23,...) to a plurality of cyber risks (51, 52, 53, 54). An accumulation device (5) is used for the segmentation of the total cyber risk (50) of a risk component (21, 22, 23,...) by means of parametrizable risk exposure segments, and wherein, in a searchable trigger table (7), retrievably stored segmentation parameters (721, 722, 723, 724) are associated with corresponding measuring parameters (71 1, 712, 713, 714) for capturing the risk exposure of a specific risk exposure segment. The system comprises a trigger module (3) that is connected to the risk components (21, 22, 23,...) by means of capturing devices (31, 32, 33) in order to dynamically detect and capture measuring values for the measuring parameters (71 1, 712, 713, 714) related to the occurrence of cyber risk events within the data pathway of said electronic means (213, 223, 233). By means of the accumulation device (5), the total risk (50) is accumulated, segmentation by segmentation, by sequentially selecting the segmentation parameters (721, 722, 723, 724) from the trigger table (7) and retrieving the associated measuring parameters (71 1, 712, 713, 714) for each of the segmentation parameters (721, 722, 723, 724), and then triggering the trigger module (3) based on the retrieved measuring parameters to capture measuring values for the retrieved measuring parameters (71 1, 712, 713, 714) from the risk components (21, 22, 23,...) by means of the capturing devices (31, 32, 33).