Why Traditional Cat Models Fail Systemic Cyber Risk
Traditional catastrophe modeling was built for hurricanes. Cyber is adversarial, dynamic, and evolves faster than any storm. Three structural problems make cat models a poor fit: they’re anchored in natural-catastrophe logic, they’ve never been stress-tested against a true industry-wide digital failure, and they model only the insured slice of the economy. That last point is the biggest blind spot. Modeling a portfolio without the rest of the economy is like assessing iceberg risk from the tip.
Vendor inertia compounds the problem. First-generation models overstated catastrophic scenarios to drive adoption. Now they’re embedded in regulatory and underwriting decisions, with little commercial incentive to correct course.
Building a Dependency Graph from Internet-Scale Scans
Coalition’s model starts from what is visible: every asset tied to an organization, scanned continuously at internet scale. From those assets, the tool fingerprints which cloud region, service, or third-party SaaS platform each organization depends on. A Shopify-hosted storefront, an AWS Athena deployment in us-east-1 for dynamic pricing, a specific CDN configuration — all become nodes in a dependency graph. Run that process across a million organizations and you have a data-driven map of aggregation technologies and vendors.
The graph visualization lets analysts filter by industry, centrality threshold, and criticality class, cutting noise without losing the signal.
Inc. 5000 and RIA Portfolios: What the Graph Reveals
Two portfolio demos ran live. The Inc. 5000 scan (5,000 fastest-growing US private companies) showed Google Workspace as a near-universal dependency and payment providers with highly variable concentration. The Inc. 5000 dependency graph live demo (17:46) filtered by payment category and surfaced a single provider reaching most of the portfolio.
The registered investment advisor dataset (22,000 firms, 18,000 domains) illustrated why outage granularity matters. A regional AWS outage priced at $100 million; a global outage at half that, because global services carry built-in redundancy. Cat models assuming week-long global cloud failures fail the engineering sniff test.
Industry-Specific SaaS: The Hidden Concentration in Real Estate
Connecticut real estate agencies revealed a concentration pattern no broad-market model would catch. The Connecticut real estate agency graph (22:34) filtered on industry-specific SaaS and, after noise reduction, surfaced Anywhere Real Estate (franchisor for Century 21 and Coldwell Banker) and Loopio as single points of failure. Keller Williams agencies shared IT infrastructure across the entire cluster.
Three of the major aggregation vendors behind Change Healthcare, CDK Global, and CrowdStrike were also named defendants in antitrust proceedings years before the outages. FTC filings on market concentration, it turns out, are a useful leading indicator for where to scan next.
What Policy Makers, CISOs, and Risk Modelers Should Do Next
Policy makers need to shift from reactive posture to proactive identification. That means redefining critical infrastructure around technologies that are “too connected to fail,” mandating SBOMs with a central repository to analyze them, and using dependency data to guide antitrust enforcement. Extreme tech concentration is a national security issue, not just an economic one.
For CISOs: supply chain resilience, real-time asset inventory, zero-trust containment, and cyber risk quantification tied to actual coverage gaps. For risk modelers: stop institutionalizing garbage inputs, model the full economy not just the insured slice, and calibrate catastrophe scenarios against real cloud outage history rather than hypothetical week-long global failures.
Notable Quotes
we must model uh what matters in systemic cyber risk Morgani · ▶ 9:33
it’s no longer about sector, it’s about individual technologies Morgani · ▶ 25:13
else we’re just going to be institutionalizing you know garbage in garbage out Morgani · ▶ 28:48
Key Takeaways
- Internet-scale scanning builds dependency graphs that reveal tech concentration before catastrophic failures occur.
- Traditional cat models overstate global-outage risk and miss industry-specific SaaS aggregations entirely.
- Systemic cyber risk requires proactive modeling of all organizations, not just the insured slice.