Why Are Insurers Still Pricing Digital Risk Like It's 2015?
When digital harm results in litigation, regulatory action, or insured loss, the debate rarely centres on intent. It centres on foreseeability: What risks were known, or should reasonably have been known and at what point in the system were they governed? In recent years, sign...
Emma Parfitt
What Gets Priced
Foreseeability, Not Intent
When digital harm results in litigation, regulatory action, or insured loss, the debate rarely centres on intent. It centres on foreseeability: What risks were known, or should reasonably have been known and at what point in the system were they governed? In recent years, significant attention has been paid to downstream controls: content moderation, enforcement, and post-incident response. These are visible, auditable, and comparatively easy to model. What remains less clearly priced is the risk that forms earlier, at the point of entry, where identity, access, and behavioural signals first converge.
Risk starts earlier
Upstream Exposure
Much of today’s digital risk assessment relies on an implicit assumption: that once access conditions are set, exposure meaningfully reduces. In practice, access controls are often treated as binary declarations rather than probabilistic risk layers. It is well established that users misrepresent themselves, provide false data, and bypass age or eligibility gates. These dynamics are not edge cases; they are predictable financial risks. From an insurance perspective, the question is not whether access rules exist, but whether the residual risk they leave behind is understood, monitored, and actively mitigated. Yet few underwriting models currently distinguish between platforms that treat access as a static gate and those that actively assess and document risk at entry.


