Aggregate Cyber Risk Across Your Entire Portfolio
Cyber risk doesn't add up the way a balance sheet does. Shared vendors and overlapping attack surfaces mean portfolio exposure has to be correlated, not summed.







Portfolio Cyber Risk Aggregation
Speak to an Expert to Learn MoreWhat does it mean to aggregate cyber risk across a portfolio?
Aggregating cyber risk means producing a single, coherent view of financial exposure across multiple entities rather than reviewing each one in isolation. For a private equity firm, holding company, or multi-business-unit enterprise, the goal is to see where risk concentrates across the whole group. That requires more than collecting individual risk profiles, because the entities are not independent of one another. A true aggregated view accounts for how losses at one entity are likely to affect the others.
Why doesn't cyber risk simply add up across companies?
Because cyber losses correlate in ways financial line items do not. Two companies facing similar threats do not double the combined exposure when grouped, since shared vendors, shared cloud providers, and overlapping attack surfaces mean a single event can affect several entities at once. A supply chain compromise or a widespread cloud outage hits everything downstream of it. Without modeling that correlation, a summed portfolio figure is an estimate presented with more confidence than it has earned.
How do you build a portfolio group for cyber risk quantification?
It builds on quantification work already completed. Once individual entities are modeled in the platform, each with its own assets, controls, and risk profile, grouping them takes three steps: name the group, select at least two entities, and set a correlation value that reflects how losses across those entities are expected to interact. The platform then produces an aggregated result rather than a sum of the individual models.
What is the 1:100 annual loss figure?
The 1:100 Annual Loss is the loss amount with a 1% chance of being exceeded in any given year, drawn from the tail of the modeled loss distribution. Alongside Average Annual Loss, which describes the expected outcome, it describes the severe-but-plausible scenario. That pairing is what boards and insurers tend to focus on, because capital and coverage decisions are made against the tail rather than the average.
How does portfolio-level cyber risk quantification affect insurance decisions?
It replaces individual, posture-based reviews with a comparative financial view across the group, which changes what gets negotiated and where. One private equity firm managing a portfolio over 600 million euros across more than fifty mid-market companies quantified all fifty using integrations with Microsoft and ServiceNow. The results identified each company's areas of high financial exposure and produced a data-backed case for which twenty-four merited a stronger position with their broker, reducing portfolio-wide cyber insurance costs by seventeen percent while prioritizing mitigation elsewhere.





