Terrorism
Why Terrorism Is a Cat Modelling Challenge
Terrorism occupies a unique and uncomfortable position in the world of catastrophe modelling. Unlike natural perils — where the physical laws governing hazard, frequency, and severity are well understood even if imperfectly measured — terrorism is driven by human intent. Perpetrators actively adapt their tactics, targets, and methods in response to defensive measures, intelligence operations, and geopolitical circumstances. This adaptive adversary problem means that historical data on terrorist attacks provides an inherently incomplete and potentially misleading guide to future risk.
Yet the insurance industry cannot simply ignore terrorism. The September 11, 2001 attacks caused insured losses of approximately USD 47 billion — at the time the largest insured loss event in history — and demonstrated that a single coordinated attack could produce losses rivalling major natural catastrophes. The attacks triggered a near-total withdrawal of terrorism coverage from commercial insurance markets within weeks, as insurers and reinsurers concluded they had no reliable basis for pricing the risk. The policy, regulatory, and modelling response to 9/11 fundamentally shaped how terrorism risk is understood, managed, and insured today.
Defining Terrorism for Insurance Purposes
Before examining how terrorism is modelled, it is essential to understand how it is defined in an insurance context — because the legal definition determines whether a given event triggers terrorism coverage or falls under a different policy provision.
Terrorism definitions in insurance policies typically require several elements to be present simultaneously:
- Intentional act: The damage must be deliberately caused, not accidental
- Political, religious, or ideological motivation: The act must be motivated by a desire to influence a government, population, or cause — distinguishing terrorism from ordinary crime
- Use of force or violence: Physical force or violence against persons or property must be involved
- Certification: In many markets (including the U.S. under TRIA), a government authority must formally certify an act as terrorism before the insurance backstop is triggered
The ambiguity between terrorism and other forms of political violence — riots, civil commotion, war — is a persistent challenge in insurance practice. The same physical event (an explosion in a city centre) may be terrorism, organised crime, or an industrial accident, and the insurance response differs significantly depending on classification. Policy wordings and legal disputes over classification are a major source of coverage uncertainty in terrorism insurance.
Attack Types and Their Physical Characteristics
Terrorism cat models must represent a wide range of potential attack modes, each with very different physical characteristics and damage patterns:
Conventional Explosives
Conventional explosive devices — car bombs, truck bombs, improvised explosive devices (IEDs), and person-borne devices — are by far the most common attack type globally. The 1993 World Trade Center bombing, the 1996 Manchester bombing, the 2016 Brussels attacks, and countless others demonstrate the persistent prevalence of this attack mode.
Explosive damage follows predictable physical laws. The primary damage mechanism is the blast wave — a supersonic pressure wave propagating outward from the detonation point. Damage severity decreases rapidly with distance from the explosion — proportional roughly to the cube root of the explosive yield (the scaled distance relationship). Key physical parameters include:
- Explosive yield: The weight of TNT-equivalent explosive determines the initial blast wave intensity
- Standoff distance: The distance between the device and the target is the single most important factor in damage severity — doubling the standoff distance reduces blast pressure dramatically
- Vehicle accessibility: Physical security measures (bollards, barriers) that prevent vehicles from approaching buildings directly are the most effective mitigation against large vehicle-borne explosive devices
- Building response: Glazing (windows) is the most vulnerable component, followed by facade cladding, then structural elements. Progressive collapse — where the loss of one column triggers cascading structural failure — is a primary risk from very large explosive devices
Chemical, Biological, Radiological, and Nuclear (CBRN) Attacks
CBRN attacks represent the most extreme tail of the terrorism risk spectrum. While historically rare, they represent scenarios where potential losses could vastly exceed conventional attacks:
- Chemical attacks: Toxic industrial chemicals or purpose-synthesised chemical warfare agents dispersed in enclosed spaces. The 1995 Tokyo subway sarin attack killed 13 people and injured thousands. Chemical attack modelling requires atmospheric dispersion modelling combined with dose-response relationships for specific agents.
- Biological attacks: Release of biological agents capable of causing disease in exposed populations. The 2001 anthrax letter attacks in the U.S. killed 5 people but caused enormous economic disruption and decontamination costs. Modelling biological attacks requires epidemiological modelling of disease spread, which introduces extraordinary uncertainty.
- Radiological attacks (dirty bombs): Conventional explosives combined with radioactive material, designed to spread contamination rather than cause nuclear explosion. The primary risk is economic — decontamination of affected areas, evacuation, and stigmatisation of the affected location — rather than direct radiation casualties.
- Nuclear attacks: Detonation of a nuclear device represents the extreme upper tail — losses from even a small device in a major city would be measured in hundreds of billions of dollars, potentially exceeding the capacity of the entire insurance industry.
Active Shooter and Vehicle Attacks
Since 2010, there has been a global increase in relatively low-complexity attacks — active shooter incidents and vehicle ramming attacks — that cause primarily casualties rather than structural property damage. The 2017 Las Vegas shooting, the 2016 Nice truck attack, the 2019 Christchurch mosque shootings, and hundreds of similar events demonstrate this trend. From a property insurance perspective, these events generate primarily business interruption losses (venues closed, businesses inaccessible during investigation), liability claims, and event cancellation losses rather than large property damage claims.
The Terrorism Modelling Framework
Terrorism cat models face a fundamental methodological challenge: the historical data is too sparse, geographically concentrated, and subject to strategic adaptation to support the statistical approach used for natural perils. The response has been to develop scenario-based and frequency-severity models that combine expert intelligence assessment with physical consequence modelling.
Threat Assessment
The hazard component of a terrorism model — the equivalent of seismic source characterisation in earthquake modelling — involves assessing the probability that specific types of attacks will occur at specific types of locations. This draws on:
- Historical attack databases: The Global Terrorism Database (GTD), maintained by the University of Maryland, documents over 200,000 terrorist attacks worldwide since 1970 — the most comprehensive public database of terrorist incidents
- Intelligence assessments: Government threat level assessments (the U.S. Homeland Threat Assessment, the UK's CONTEST threat level system) provide qualitative assessments of current threat environments
- Target attractiveness modelling: Not all locations are equally at risk. Iconic targets, high-density gatherings, symbolic institutions, and critical infrastructure attract disproportionate terrorist attention. Models must represent this non-uniform spatial distribution of risk.
- Attack mode frequency: How frequently different attack types (conventional explosive, CBRN, active shooter) have been attempted, and how this distribution is evolving
Physical Consequence Modelling
Once an attack scenario is defined (type, location, weapon yield or size), physical consequence models estimate the damage footprint:
- Blast models: For explosive attacks, blast wave propagation models (based on empirical data and computational fluid dynamics) estimate peak overpressure, impulse, and dynamic pressure at each point around the explosion — which are then converted to structural and glazing damage through building response relationships
- Dispersion models: For chemical or radiological attacks, atmospheric dispersion models estimate the concentration of agent at each downwind location, accounting for wind speed, direction, atmospheric stability, and building effects
- Fire models: For incendiary attacks or post-explosion fires, fire spread models similar to those used in wildfire modelling estimate the area affected
Accumulation and Correlation
A critical feature of terrorism risk that distinguishes it from most natural perils is that the worst-case scenario is not a geographically dispersed event but a highly concentrated one — an attack in the financial district of a major city, for example, could simultaneously affect the headquarters of multiple large corporations, financial institutions, and insurers. This geographic concentration means that an insurer's terrorism exposure in a single city block could represent an enormous proportion of their total portfolio value.
Accumulation management is therefore central to terrorism risk management. Leading market practice involves mapping all policies with terrorism coverage to a geographic grid and identifying locations where total insured value concentration is highest — the so-called "terrorism PML hotspots." Cities like New York, London, Paris, and Tokyo consistently emerge as locations where insurer accumulations warrant careful management.
The Role of Government Backstops
One of the most distinctive features of terrorism insurance globally is the role of government as a reinsurer of last resort. Following the market failure after 9/11, most major economies have established terrorism pool or backstop arrangements:
- United States — TRIA: The Terrorism Risk Insurance Act (2002, extended multiple times) requires insurers to offer terrorism coverage and provides a government backstop above a specified industry loss threshold. Insurers retain losses below their individual deductible; losses above trigger proportional government reimbursement.
- United Kingdom — Pool Re: Pool Re (Pool Reinsurance Company) was established in 1993 following IRA bomb attacks on the City of London. It is a mutual reinsurance pool backed by the UK government as reinsurer of last resort. Pool Re has evolved significantly since 9/11 and now covers a broad range of terrorism scenarios including cyber-enabled terrorism and CBRN.
- France — GAREAT: Garantie des Risques Attentats et Actes de Terrorisme provides reinsurance for large property terrorism losses through a pool structure backed by the Caisse Centrale de Réassurance (CCR), a state-owned reinsurer.
- Australia — ARPC: The Australian Reinsurance Pool Corporation provides a government-backed terrorism reinsurance facility covering declared terrorist incidents.
Cyber-Enabled Terrorism
An emerging and rapidly evolving frontier in terrorism risk is the use of cyber means to cause physical damage — cyber-enabled terrorism. Attacks on industrial control systems of critical infrastructure (power grids, water treatment, pipelines, financial systems) could cause physical damage and economic disruption that triggers property and business interruption policies without any conventional explosive or weapon being deployed. The 2021 Colonial Pipeline ransomware attack (which caused fuel shortages across the U.S. East Coast) and the 2015/2016 attacks on the Ukrainian power grid demonstrate that cyber-physical attacks on critical infrastructure are not theoretical — they are happening.
The insurance implications are profound and not yet fully resolved. Standard property policies typically require physical loss or damage to trigger coverage — a cyber attack that disrupts operations without causing physical damage may fall into a coverage gap between cyber policies and property policies. Pool Re in the UK extended its coverage to include cyber-enabled terrorism in 2018, recognising that the terrorism risk landscape is evolving beyond purely physical attack modes.
Post-9/11 Evolution of Terrorism Risk
The terrorism threat landscape has evolved significantly since 2001, with important implications for cat modelling assumptions:
- Decentralisation: The shift from centralised, hierarchically organised groups (Al-Qaeda's pre-9/11 structure) toward decentralised, franchise-model organisations (ISIS) and lone-wolf attackers has changed the risk profile — more frequent, smaller attacks rather than fewer, catastrophic coordinated ones
- Domestic terrorism: Right-wing extremism, eco-terrorism, and other forms of domestic political violence have grown as a proportion of total terrorism risk in Western countries — with different geographic and target distributions than international Islamist terrorism
- Attack complexity: The most sophisticated recent attacks (Paris 2015, Brussels 2016) have demonstrated that coordinated multi-location attacks causing very large aggregate losses remain possible even in a decentralised threat environment
- Soft target focus: Hardening of traditional hard targets (government buildings, financial institutions) has shifted terrorist attention toward soft targets — public gathering places, transport hubs, entertainment venues — with large people concentration and low physical security
Knowledge Check — Terrorism
Answer all five questions. You need 4 of 5 (80%) to pass.