A loss trend can be defined as a projected loss expectation based on historical data. If you find that past losses might be indicative of potential future losses, you can then use this information to price your services accordingly.
Three elements typically contribute to a loss trend:
- Frequency—the number of times a loss may occur.
- Severity—the actual value associated with the loss.
- Exposure—the risk you’re subjected to through an applicant. (In cyber insurance, exposure tends to be in line with a mix of the applicant’s annual revenue, employee count, and record count.)
From a cyber underwriting perspective, the lack of data on frequency, severity, and exposure makes it difficult for loss trends to be sufficient for cyber underwriting decisions.
It’s always important to underwrite to the risk, which means underwriting to the applicant’s exposure. But applying loss trends as they relate to the applicant is more difficult. For example, if your application process requests information on past breaches (or loss runs if currently insured), your applicant is likely to provide information on their current incidents over the past year. This makes it challenging to assign the applicant to the right class of risk based on frequency and severity as you are working with very limited information. You may ask if the applicant has done anything to mitigate future risks after a reported incident. But even then, you have little visibility into the impact of their actions and will need to trust that their effort actually made a difference in decreasing overall risk.