<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US">
	<id>https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3ASupply_chain_attack</id>
	<title>Definition:Supply chain attack - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3ASupply_chain_attack"/>
	<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Supply_chain_attack&amp;action=history"/>
	<updated>2026-06-14T01:30:00Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://www.insurerbrain.com/w/index.php?title=Definition:Supply_chain_attack&amp;diff=7146&amp;oldid=prev</id>
		<title>PlumBot: Bot: Creating new article from JSON</title>
		<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Supply_chain_attack&amp;diff=7146&amp;oldid=prev"/>
		<updated>2026-03-10T05:14:35Z</updated>

		<summary type="html">&lt;p&gt;Bot: Creating new article from JSON&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;🔗 &amp;#039;&amp;#039;&amp;#039;Supply chain attack&amp;#039;&amp;#039;&amp;#039; is a [[Definition:Cyber risk | cyber risk]] event in which a threat actor compromises a software vendor, service provider, or other upstream supplier in order to infiltrate the systems of that supplier&amp;#039;s downstream customers — a scenario that has become a central concern for [[Definition:Cyber insurance | cyber insurance]] underwriters. Unlike a direct breach targeting a single organization, a supply chain attack exploits the trust relationships inherent in modern technology ecosystems, enabling a single point of compromise to cascade across thousands of organizations simultaneously. The SolarWinds and Kaseya incidents are landmark examples that exposed the [[Definition:Aggregation risk | aggregation risk]] this attack vector poses to insurance portfolios.&lt;br /&gt;
&lt;br /&gt;
⚙️ From an insurance perspective, the mechanics of a supply chain attack create a correlated loss event: because many policyholders share the same compromised vendor, a single attack can trigger [[Definition:Claim | claims]] across a carrier&amp;#039;s entire [[Definition:Book of business | book of business]] at once. [[Definition:Underwriter | Underwriters]] evaluating this exposure typically assess a prospective insured&amp;#039;s [[Definition:Vendor management | vendor management]] practices, software inventory, and reliance on [[Definition:Single point of failure | single points of failure]]. [[Definition:Policy language | Policy language]] has also evolved, with some carriers introducing [[Definition:Exclusion | exclusions]] or [[Definition:Sublimit | sublimits]] for systemic or infrastructure-level cyber events, while others develop specialized [[Definition:Endorsement | endorsements]] that explicitly address contingent business interruption arising from a supplier&amp;#039;s breach. [[Definition:Catastrophe modeling | Catastrophe modeling]] firms such as CyberCube and Moody&amp;#039;s RMS now build supply chain attack scenarios into their [[Definition:Probable maximum loss (PML) | probable maximum loss]] estimates to help [[Definition:Reinsurance | reinsurers]] and primary carriers quantify tail risk.&lt;br /&gt;
&lt;br /&gt;
💡 The insurance industry&amp;#039;s response to supply chain attacks reflects a broader reckoning with [[Definition:Systemic risk | systemic cyber risk]] — the possibility that a single event could generate losses rivaling a natural catastrophe. [[Definition:Reinsurer | Reinsurers]] have pushed for clearer [[Definition:Contract wording | contract wording]] distinguishing between targeted attacks and widespread systemic events, and [[Definition:Regulatory body | regulators]] are beginning to scrutinize how carriers model and reserve for correlated cyber losses. For [[Definition:Insurtech | insurtech]] companies offering real-time risk monitoring, supply chain visibility tools that map an insured&amp;#039;s technology dependencies represent a significant value-add, allowing both the carrier and the policyholder to identify exposure before an attack materializes. As software ecosystems grow more interconnected, the ability to price and manage supply chain attack risk will remain one of the defining challenges in the [[Definition:Cyber insurance | cyber insurance]] market.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Related concepts&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Definition:Cyber insurance]]&lt;br /&gt;
* [[Definition:Aggregation risk]]&lt;br /&gt;
* [[Definition:Systemic risk]]&lt;br /&gt;
* [[Definition:Contingent business interruption insurance]]&lt;br /&gt;
* [[Definition:Catastrophe modeling]]&lt;br /&gt;
* [[Definition:Vendor management]]&lt;br /&gt;
{{Div col end}}&lt;/div&gt;</summary>
		<author><name>PlumBot</name></author>
	</entry>
</feed>