Research basis
State of the art
The weighting of dimensions in this rating reflects the current empirical consensus across
cybersecurity risk research. The findings below summarise key studies and establish why
governance and organisational signals anchor the model, while technical indicators serve as
calibrating inputs.
Liu & Babar · Australian Journal of Management · 2024
Four-category risk taxonomy across 12 disciplines
A systematic review of 203 empirical studies — spanning accounting, computer science,
finance, information systems, law, management and six further disciplines — classifies
all identified cybersecurity risk factors into four categories: management factors,
firm characteristics, IT practices, and institutional factors.
Firm characteristics (size, sector, data holdings) and management factors each constitute
an independent risk layer that cannot be reduced to or substituted by technical metrics.
The authors also find that higher IT investment significantly reduces breach risk —
but only when substantively integrated; symbolic adoption without operational
embedding can worsen exposure.
203 empirical studies
12 disciplines
Firm characteristics as independent risk layer
DOI 10.1177/03128962241293658
Verizon DBIR · 17th Annual Edition · May 2024
68 % of breaches trace to a non-malicious human element
Analysis of 10,626 confirmed breaches across 94 countries in 2023 — the largest
dataset in the report's 17-year history — found that 68 % of breaches involved a
non-malicious human element: an employee error, a credential handed over in a
phishing attack, or a social engineering lure. This figure excludes malicious
insiders, making it a conservative lower bound. The median time for a user to
click a malicious link was 21 seconds; another 28 seconds to enter credentials.
Stolen credentials were the initial access vector in 53 % of all web-application
attacks and required a median of 292 days to identify and contain.
10,626 confirmed breaches
94 countries · 2023 data
68 % non-malicious human element
292-day credential detection window
Hu, Levi, Yahalom & Zerhouni · MIT · IEEE TDSC · 2025
Organisational attributes predict breach risk before any technical check
In the first large-scale machine-learning study of breach predictors, a model using
only firm-level organisational attributes — size, sector, employee count, supply chain
connectivity — already outperformed a random baseline (AUC > 50 %). This confirms
that cyberattacks are not uniformly distributed: large organisations and data-intensive
sectors such as healthcare face structurally higher targeting rates independent of any
technical vulnerability. Adding outside-in cybersecurity ratings on top of
organisational features raised the AUC meaningfully. Adding digital supply chain
network features on top of both improved the out-of-sample AUC by a further 2.3
percentage points — significant given that any individual breach is a low-probability,
high-impact event.
Large-scale ML study
Org. features alone beat random baseline
+2.3 pp AUC from supply chain features
arXiv 2210.15785 · IEEE TDSC 2025
IBM / Ponemon Institute · Cost of a Data Breach Report · July 2024
Breach cost scales with firm size, sector and data sensitivity
The 19th annual IBM Cost of a Data Breach Report — covering 604 organisations across
17 industries and 16 regions, breached between March 2023 and February 2024 — found
the global average breach cost reached USD 4.88 million, a 10 % year-on-year increase
and the largest single-year jump since the pandemic. Healthcare recorded the highest
sector average (USD 9.77 million) for the fourteenth consecutive year. Critically,
breach cost is driven not by the technical nature of the vulnerability exploited, but
by business disruption and post-breach response costs — both of which scale directly
with firm size and the volume of data held.
604 organisations · 17 industries · 16 regions
Global average USD 4.88 M (+10 %)
Healthcare: USD 9.77 M sector average
Cost driven by disruption, not exploit type
NetDiligence · Cyber Claims Study · 15th Annual Edition
2 % of claims by volume account for 51 % of total insured cost
NetDiligence's analysis of insurance claims data reveals a pronounced asymmetry in
the cyber-loss distribution. Small and medium-sized enterprises (revenue below
USD 2 billion) account for approximately 98 % of all claims by volume but only
49 % of total insured cost. The remaining 2 % of claims — all from large enterprises
— account for roughly 51 % of total cost, or approximately USD 2.4 billion. The
average large-enterprise cyber incident now costs USD 10.3 million per claim. This
bimodal distribution confirms that firm size is the dominant scalar for expected
damage magnitude, independently of the technical characteristics of any individual
incident.
SMEs: 98 % of claim volume · 49 % of cost
Large enterprise: 2 % volume · 51 % cost
Large-enterprise average: USD 10.3 M per claim
Size dominates damage magnitude
Bitsight / Verisk (AIR Worldwide) · Marsh McLennan · Independent validation
Technical security ratings correlate with breach — but span a narrow absolute range
Independent validation by Verisk (AIR Worldwide) across 27,458 organisations found
that those with a Bitsight Security Rating of 700 or above had a breach probability
below 1 %, while those below 500 faced a probability of approximately 3 %. A
separate Marsh McLennan analysis identified 14 specific Bitsight analytics —
including patching cadence and exposed service configuration — as statistically
correlated with cyber incidents. Patching cadence within a 90-day observation window
was shown to be as well-correlated with breach outcomes as a 300-day window,
confirming it as the strongest single actionable technical predictor. Importantly,
these technical signals function as calibrators that sharpen the organisational
baseline — they do not replace it.
27,458 organisations analysed (Verisk)
Rating ≥700: breach prob. <1 %
Rating <500: breach prob. ≈3 %
14 analytics correlated (Marsh McLennan)
Patching cadence: strongest technical signal
Market practice · Insurance underwriting · 2024 – 2026
Revenue and sector class are the primary underwriting variables; technical posture is a secondary modifier
Across the cyber insurance market, revenue is the primary pricing variable in most
standard underwriting models, with industry sector as the second determinant. Technical
security posture — including security controls documentation, EDR deployment, and
patching discipline — functions as a modifier, not the baseline. Carriers such as
Coalition and At-Bay that perform active pre-bind scanning represent a minority
practice; most market participants price from firmographic inputs alone. Businesses
with identical revenue and employee counts receive quotes that differ by up to 40 %
based solely on how their security posture is documented and evidenced — confirming
that control quality affects premium, but sits downstream of size and sector in the
pricing hierarchy. Aon's 2025 Global Cyber Risk Report found that verified cyber
preparedness reduces claim payments by up to 77 % in the US — illustrating the
scale of the gap between standard underwriting proxies and measurable risk reduction.
Revenue: primary underwriting variable
Sector class: second determinant
Technical posture: modifier, not baseline
Up to 40 % premium variance from control documentation
Preparedness reduces claims by up to 77 % (Aon 2025)