Blog Post

When a Cyber Loss Becomes a Recall

September 11, 2026

Table of Contents

Cyber loss models are built around information leaving an organization. Records exposed, notification costs, regulatory penalty, litigation from affected individuals. Every category assumes the harm is informational.

A compromise affecting vehicles in the field produces something the model has no term for. The vehicle can behave differently, the manufacturer may have to recall it, and the recall cost is frequently larger than anything the cyber categories would have produced.

Which Loss Categories Are Missing?

Three, and they are borrowed from product safety rather than from information security.

Recall and remediation is the first. A vulnerability in the field can require a fix distributed to every affected vehicle, and where the code sits deep in a control unit the update may not be deliverable remotely. A physical recall means workshop time per vehicle multiplied by the fleet, which is an order of magnitude no notification cost reaches.

Product liability is the second, fragmented across the supply chain in a way information loss rarely is. Casualty exposure is the third, since a compromise affecting braking, steering or powertrain behavior creates the possibility of injury, which sits outside cyber policies and inside a different insurance tower entirely.

Why Does the Recall Term Dominate?

Because it scales with the fleet rather than with the incident, which is a different multiplier from anything in a data loss model.

Breakdown of extreme annual loss by damage type showing which categories contribute most at the one-in-hundred level
Where a sector carries a loss category most models omit, the breakdown by damage type is what reveals it dominating.

A data breach costs per record and a recall costs per unit, and the second multiplier applies to every vehicle carrying the affected component whether or not any of them was attacked. One vulnerability in one widely shared control unit reaches a population defined by production volume, so the exposure is a function of how many were built rather than of how many were compromised.

Which Makes Deliverability the Critical Variable

Whether the fix can be distributed remotely decides the order of magnitude. A software update pushed to vehicles costs bandwidth and engineering. The same fix requiring a workshop visit costs labor per vehicle plus customer inconvenience plus the logistics of scheduling a fleet, and the ratio between those two is the single largest sensitivity in the model.

What Does the Regulatory Position Add?

A mechanism that converts a security failure into a commercial one directly, without any incident occurring.

Vehicle type approval in several markets now depends on the manufacturer operating a certified cybersecurity management system across the vehicle lifecycle. Where that certification is withdrawn or a non-conformity is found, approval can be suspended, which stops sales of affected models. The result is a revenue interruption caused by a governance finding rather than by an attack.

Which Is a Category Most Models Lack

A loss arising from losing permission to sell has no analogue in an information security model. It resembles a regulatory suspension more than a breach, and its severity depends on production volume and model mix rather than on what an attacker did, and resilience as a regulatory requirement is the general form of that mechanism.

Where Does Liability Sit?

Fragmented, with the manufacturer holding governance accountability regardless of where the defect originated, which changes how supply chain exposure should be modeled.

Per-vendor exposure table showing each supplier with its category, failure frequency band and modeled annual loss
Pricing suppliers individually understates a sector where one shared component reaches a whole production run.

A vulnerability originating in a supplier component can be pursued down the chain contractually, and the obligation to have validated that component before production stays with the manufacturer. So the exposure is not reduced by the defect being somebody else's, it is potentially recoverable afterward, which is a different thing with different timing and different certainty.

How Should That Be Modeled?

Gross, with recovery treated as a separate and uncertain offset. A model netting off expected supplier recovery produces a figure that understates what the manufacturer funds in the period the recall happens, since recovery arrives later if at all. The same asymmetry applies wherever a loss is borne first and recovered second, and modeling gross and subtracting is the general treatment.

Which Exposures Fall Outside Cyber Cover?

Most of the large ones, which is the finding that matters commercially and is frequently discovered during a claim.

Recall expense is typically a product recall policy rather than a cyber one. Bodily injury sits with casualty. Product liability sits with product liability. A cyber policy responds to the investigation, the response costs and the data-related consequences, which in this sector may be the smallest component of the event.

What Does That Mean for the Analysis?

The exposure has to be modeled before the coverage question rather than within it. Producing a single figure and asking whether cyber insurance covers it produces a misleading answer, since the figure spans several towers. Modeling by damage type and mapping each to the policy that would respond is the sequence that reveals what is genuinely uninsured, and the exclusions that surface at claim is where the surprises live.

Who Holds the Inputs?

Engineering and manufacturing rather than security, which is the same pattern as any sector where the loss is physical.

Production volume per platform, component commonality across models, whether a given control unit accepts remote updates, and the labor time for a workshop procedure are all known inside the organization and none sits with the security function. A model assembled without them will carry an accurate frequency estimate and a severity figure that misses the dominant term.

What Are the Four Questions to Ask?

How many units carry each critical component. Which of those components can be updated remotely. What a workshop visit costs per vehicle including customer handling. Then what proportion of current revenue depends on models whose type approval could be affected. Those four convert a vulnerability into a figure.

How Do You Estimate Frequency Here?

Partly from conventional data and partly not, and separating the two is what keeps the figure defensible.

The access mechanisms borrow well. A compromise reaching a manufacturer's backend telematics platform arrives through credential abuse, a supply chain path or an exposed interface, all of which have base rates in conventional loss data. What has no base rate is the step from that compromise to a safety-relevant manipulation of vehicle behavior, since very few such events have occurred and none at a scale that supports a rate.

What Follows From That Split?

Model the access frequency conventionally, then treat the escalation to physical consequence as a conditional probability stated as a range rather than a point. The output becomes a loss given compromise with a stated conditional, which is more useful to an engineering audience than a single annualized figure and more honest about what is known, and working without an observed population applies the same reasoning.

Which Figure Should Be Reported?

The loss given a safety-relevant event, because that is the number a decision turns on. A board asked to fund a security program for connected vehicles is deciding against the consequence rather than against an annual expectation, and the consequence is establishable while the annual expectation is not.

What About Transportation Fleets Rather Than Manufacturers?

A different position with one shared property, and the distinction is worth drawing because the sector label covers both.

An operator running vehicles carries interruption and casualty exposure without the recall term, since the fix is the manufacturer's obligation. What the operator carries instead is the loss of use while a fleet is unavailable, which is a business interruption calculation driven by duration and by whether the work can be caught up afterward. Interruption rather than data loss is the model that applies, and cyber risk quantification built from operational inputs is what produces it.

Borrow the Loss Categories From Product Safety

An information security loss model has no term for a recall, and in this sector the recall term frequently dominates everything else because it scales with production volume rather than with the incident. Whether the fix can be delivered remotely decides the order of magnitude. Type approval depending on a certified management system creates a revenue interruption caused by a governance finding rather than an attack, which no information model contains. Liability fragments across the supply chain while accountability stays with the manufacturer, so the exposure should be modeled gross with recovery as a separate offset. Kovrr's cyber risk quantification models loss by damage type, which is what allows a sector carrying unusual categories to be priced at all.

To see exposure modeled by damage type including categories a data-loss model omits, book a demo with our risk experts.

Tomer Shoolman

Product Manager

Automotive Cyber Loss FAQs

Speak to an Expert

Which loss categories does a standard cyber model miss here?

Why does the recall term dominate?

What is the largest sensitivity in the model?

How does vehicle type approval create exposure?

Where does liability sit when the defect came from a supplier?

Which exposures fall outside cyber cover?