Estimated reading time: 6 minutes
Swiss Re Institute read the risk disclosures of 91 Fortune-100 companies. Ninety-eight percent of them name cyber attacks as a risk to their business. No risk in the study appeared more often. With the London School of Economics, it compared filings from 2019 and 2026. Cyber attacks topped the list in 2026, up from 91% in 2019.
The same report then goes further.. Systemic risks such as “extreme cyber accumulation” by definition exceed the private sector’s capacity to carry them.
Cyber Accumulation Risk In The Filings
Swiss Re Institute published the study, The age of interconnected risks, on 25 September. It used a large language model to classify each company’s disclosed risks. It then mapped the causal links companies drew between those risks.
The filings compared date from early 2019 and February 2026. All 91 companies have headquarters in the US. They earn on average 30 to 40% of their revenue abroad. Regulatory and compliance risk was left out of the analysis.
Two findings stand out. The average number of links between risks rose 24% since 2019. AI emerged as one of the most connected points on the map.
AI and new technology risk moved fastest of any category. It appeared in 40% of filings in 2019 and 69% in 2026. Retailers, airlines, pharmaceutical companies, and food producers now disclose it. Most of them did not in 2019.
Data privacy and misuse rose from 32% to 40%. Mentions of critical infrastructure outages dipped from 53% to 48%.
One Event, Many Claims
The report spells out why concentration matters to insurers. The economy leans on a narrow set of data centers, cloud services, and networks. Three firms controlled 70% of global cloud infrastructure in 2024. Three companies process 97% of global credit card transactions.
That is where cyber accumulation risk begins for re/insurers. The report puts it plainly. One outage or cyber event can trigger “simultaneous claims across otherwise unrelated insureds and multiple lines of business.”
Cyber Insurance News mapped the same concentration problem through McKinsey’s research earlier this month. AXA XL and S-RM described AI losses that reach several policies from one failure. Swiss Re’s framing lands in the same place.
Ivan Gonzalez, chief executive of Corporate Solutions at Swiss Re, put it in business terms. Suppliers, technology providers and customers can all depend on the same infrastructure. “One disruption can therefore affect more parts of a business than expected,” he said.
Systemic Cyber Risk And Machine Speed
The report connects AI and cyber directly. It says AI models’ ability to find cyber vulnerabilities might make attacks on critical infrastructure easier. Attacks during stressed markets “could act as powerful crisis amplifiers,” it adds.
Speed is the second concern. Institutions increasingly use similar models and act on them instantly. Jón Daníelsson, director of the Systemic Risk Centre at LSE, described the result. “A containable shock can become systemic before there is time to respond,” he said.
Get Our Podcast
Executive Editor and host Martin Hinton interviews Peter Foster, Chairman of Willis’ Global FINEX Cyber Solutions. They break down how vendor concentration, ransomware, AI, and data privacy exposures are shaping the cyber insurance market for boards, risk managers, and SMEs.
That theme has come up on the Cyber Insurance News podcast. A Travelers executive explained how ransomware crews use chatbots to compress a victim’s decision time.
The report’s risk monitor adds context. Reported AI incidents stand at a record 362, drawn from the AI Incident Database. Reported cyber incidents sit in the high band at 700. The spatial concentration of data centers is also at a record.
Where Physical And Cyber Risk Meet
Concentration is physical as well as digital. More than a quarter of US data centers sit in areas with at least three large-hail days a year. More than 40% sit in zones of significant tornado risk. About 88% of Taiwan’s semiconductor plants are in areas of extreme seismic risk.
Single AI data center campuses can exceed 10 billion dollars in replacement value. Exceptional cases, such as Meta’s Hyperion, reach 50 billion dollars. Losses at that scale test business interruption and property wordings alike. They also raise the operational technology risks Cyber Insurance News has tracked.
Cyber Risk Concentration Needs Shared Capacity
The report closes with five priorities for businesses, policymakers and regulators. The fourth speaks directly to cyber insurance.
Pandemics, extreme cyber accumulation and wider critical infrastructure failures “by definition exceed the private-sector risk-bearing capacity,” the report says. It calls for layered solutions that combine public resources, re/insurance and capital-market instruments. The report names insurance-linked securities specifically. For cyber accumulation risk, that points toward the capital markets as well as the state.
Get The Cyber Insurance News Upload Delivered
Subscribe to our weekly newsletter!
The fifth priority asks supervisors to widen stress tests. Scenarios should cover AI-driven market synchronization, critical infrastructure failures and cyber incidents.
Jérôme Haegeli, Swiss Re’s group chief economist, framed the timing. Resilience “cannot start when a crisis hits,” he said. It has to be built beforehand, including by preserving the capacity to transfer risk.
FAQ – Cyber Accumulation Risk
What did Swiss Re Institute and LSE study?
They analyzed the 10-K risk disclosures of 91 Fortune-100 companies, comparing filings from early 2019 with those from February 2026. A large language model classified each disclosed risk and the links companies drew between risks.
How many companies name cyber attacks as a risk?
Ninety-eight percent of the 91 companies studied in 2026, up from 91% in 2019. Cyber attacks were the most frequently disclosed risk in the sample.
How fast is AI risk disclosure growing?
AI and new technology risk appeared in 40% of filings in 2019 and 69% in 2026. Retailers, airlines, pharmaceutical companies and food producers now disclose it.
What is cyber accumulation risk?
The risk that one outage or cyber event triggers claims across many unrelated policyholders and several lines of business at once. The report ties it to concentration in cloud, payments and data center infrastructure.
What does the report say about insuring extreme cyber events?
It says systemic risks such as extreme cyber accumulation exceed private-sector risk-bearing capacity by definition. It calls for public-private solutions combining public resources, re/insurance and insurance-linked securities.
Is the physical location of infrastructure part of the risk?
Yes. More than a quarter of US data centers face at least three large-hail days a year, more than 40% sit in significant tornado zones, and about 88% of Taiwan’s semiconductor plants face extreme seismic risk.
Related Cyber Insurance Posts
- Stolen Credentials Outlive The Malware That Stole Them
- Cyber Insurance Market Faces Slowdown as SMEs Hold the Key to Future Growth(Opens in a new browser tab)
- Ruh Roh! Swiss Re Predicts Dramatic Decline in Cyber Insurance Growth Rates(Opens in a new browser tab)
- Resilience Says Edge Clients Cut Extreme Cyber Loss Exposure by $1 Billion(Opens in a new browser tab)
- How to Understand & Improve Cyber Insurance Markets: Swiss Re Report (Opens in a new browser tab)