Modules/Lesson 5.1
MODULE 05 · MAN-MADE PERILS

Terrorism

📖 ~16 min read· Includes Quiz

Why Terrorism Is a Cat Modelling Challenge

Terrorism occupies a unique and uncomfortable position in the world of catastrophe modelling. Unlike natural perils — where the physical laws governing hazard, frequency, and severity are well understood even if imperfectly measured — terrorism is driven by human intent. Perpetrators actively adapt their tactics, targets, and methods in response to defensive measures, intelligence operations, and geopolitical circumstances. This adaptive adversary problem means that historical data on terrorist attacks provides an inherently incomplete and potentially misleading guide to future risk.

Yet the insurance industry cannot simply ignore terrorism. The September 11, 2001 attacks caused insured losses of approximately USD 47 billion — at the time the largest insured loss event in history — and demonstrated that a single coordinated attack could produce losses rivalling major natural catastrophes. The attacks triggered a near-total withdrawal of terrorism coverage from commercial insurance markets within weeks, as insurers and reinsurers concluded they had no reliable basis for pricing the risk. The policy, regulatory, and modelling response to 9/11 fundamentally shaped how terrorism risk is understood, managed, and insured today.

September 11, 2001 — The Event That Changed Everything
The 9/11 attacks on New York and Washington D.C. killed 2,977 people and caused insured losses of approximately USD 47 billion across property, liability, workers' compensation, aviation, and life lines. Property losses alone exceeded USD 11 billion from the collapse of the World Trade Center complex. The attacks revealed that standard commercial property policies — which did not exclude terrorism — could generate catastrophic correlated losses from a single human-directed event. Within months, reinsurers had withdrawn terrorism cover from most treaties, and primary insurers followed. The U.S. government was compelled to create the Terrorism Risk Insurance Act (TRIA) in 2002 to backstop the private market.

Defining Terrorism for Insurance Purposes

Before examining how terrorism is modelled, it is essential to understand how it is defined in an insurance context — because the legal definition determines whether a given event triggers terrorism coverage or falls under a different policy provision.

Terrorism definitions in insurance policies typically require several elements to be present simultaneously:

  • Intentional act: The damage must be deliberately caused, not accidental
  • Political, religious, or ideological motivation: The act must be motivated by a desire to influence a government, population, or cause — distinguishing terrorism from ordinary crime
  • Use of force or violence: Physical force or violence against persons or property must be involved
  • Certification: In many markets (including the U.S. under TRIA), a government authority must formally certify an act as terrorism before the insurance backstop is triggered

The ambiguity between terrorism and other forms of political violence — riots, civil commotion, war — is a persistent challenge in insurance practice. The same physical event (an explosion in a city centre) may be terrorism, organised crime, or an industrial accident, and the insurance response differs significantly depending on classification. Policy wordings and legal disputes over classification are a major source of coverage uncertainty in terrorism insurance.

Attack Types and Their Physical Characteristics

Terrorism cat models must represent a wide range of potential attack modes, each with very different physical characteristics and damage patterns:

Conventional Explosives

Conventional explosive devices — car bombs, truck bombs, improvised explosive devices (IEDs), and person-borne devices — are by far the most common attack type globally. The 1993 World Trade Center bombing, the 1996 Manchester bombing, the 2016 Brussels attacks, and countless others demonstrate the persistent prevalence of this attack mode.

Explosive damage follows predictable physical laws. The primary damage mechanism is the blast wave — a supersonic pressure wave propagating outward from the detonation point. Damage severity decreases rapidly with distance from the explosion — proportional roughly to the cube root of the explosive yield (the scaled distance relationship). Key physical parameters include:

  • Explosive yield: The weight of TNT-equivalent explosive determines the initial blast wave intensity
  • Standoff distance: The distance between the device and the target is the single most important factor in damage severity — doubling the standoff distance reduces blast pressure dramatically
  • Vehicle accessibility: Physical security measures (bollards, barriers) that prevent vehicles from approaching buildings directly are the most effective mitigation against large vehicle-borne explosive devices
  • Building response: Glazing (windows) is the most vulnerable component, followed by facade cladding, then structural elements. Progressive collapse — where the loss of one column triggers cascading structural failure — is a primary risk from very large explosive devices

Chemical, Biological, Radiological, and Nuclear (CBRN) Attacks

CBRN attacks represent the most extreme tail of the terrorism risk spectrum. While historically rare, they represent scenarios where potential losses could vastly exceed conventional attacks:

  • Chemical attacks: Toxic industrial chemicals or purpose-synthesised chemical warfare agents dispersed in enclosed spaces. The 1995 Tokyo subway sarin attack killed 13 people and injured thousands. Chemical attack modelling requires atmospheric dispersion modelling combined with dose-response relationships for specific agents.
  • Biological attacks: Release of biological agents capable of causing disease in exposed populations. The 2001 anthrax letter attacks in the U.S. killed 5 people but caused enormous economic disruption and decontamination costs. Modelling biological attacks requires epidemiological modelling of disease spread, which introduces extraordinary uncertainty.
  • Radiological attacks (dirty bombs): Conventional explosives combined with radioactive material, designed to spread contamination rather than cause nuclear explosion. The primary risk is economic — decontamination of affected areas, evacuation, and stigmatisation of the affected location — rather than direct radiation casualties.
  • Nuclear attacks: Detonation of a nuclear device represents the extreme upper tail — losses from even a small device in a major city would be measured in hundreds of billions of dollars, potentially exceeding the capacity of the entire insurance industry.
CBRN Exclusions
Standard terrorism insurance policies typically exclude CBRN attacks, or provide only limited coverage. This reflects the potentially unlimited loss potential of nuclear events and the near impossibility of pricing biological or chemical risks with any confidence. Specialist CBRN coverage is available in limited amounts through the London market and specialist insurers, but capacity is constrained. Cat modellers working on terrorism portfolios must understand which attack types are included and excluded in the policies they are modelling.

Active Shooter and Vehicle Attacks

Since 2010, there has been a global increase in relatively low-complexity attacks — active shooter incidents and vehicle ramming attacks — that cause primarily casualties rather than structural property damage. The 2017 Las Vegas shooting, the 2016 Nice truck attack, the 2019 Christchurch mosque shootings, and hundreds of similar events demonstrate this trend. From a property insurance perspective, these events generate primarily business interruption losses (venues closed, businesses inaccessible during investigation), liability claims, and event cancellation losses rather than large property damage claims.

The Terrorism Modelling Framework

Terrorism cat models face a fundamental methodological challenge: the historical data is too sparse, geographically concentrated, and subject to strategic adaptation to support the statistical approach used for natural perils. The response has been to develop scenario-based and frequency-severity models that combine expert intelligence assessment with physical consequence modelling.

Threat Assessment

The hazard component of a terrorism model — the equivalent of seismic source characterisation in earthquake modelling — involves assessing the probability that specific types of attacks will occur at specific types of locations. This draws on:

  • Historical attack databases: The Global Terrorism Database (GTD), maintained by the University of Maryland, documents over 200,000 terrorist attacks worldwide since 1970 — the most comprehensive public database of terrorist incidents
  • Intelligence assessments: Government threat level assessments (the U.S. Homeland Threat Assessment, the UK's CONTEST threat level system) provide qualitative assessments of current threat environments
  • Target attractiveness modelling: Not all locations are equally at risk. Iconic targets, high-density gatherings, symbolic institutions, and critical infrastructure attract disproportionate terrorist attention. Models must represent this non-uniform spatial distribution of risk.
  • Attack mode frequency: How frequently different attack types (conventional explosive, CBRN, active shooter) have been attempted, and how this distribution is evolving

Physical Consequence Modelling

Once an attack scenario is defined (type, location, weapon yield or size), physical consequence models estimate the damage footprint:

  • Blast models: For explosive attacks, blast wave propagation models (based on empirical data and computational fluid dynamics) estimate peak overpressure, impulse, and dynamic pressure at each point around the explosion — which are then converted to structural and glazing damage through building response relationships
  • Dispersion models: For chemical or radiological attacks, atmospheric dispersion models estimate the concentration of agent at each downwind location, accounting for wind speed, direction, atmospheric stability, and building effects
  • Fire models: For incendiary attacks or post-explosion fires, fire spread models similar to those used in wildfire modelling estimate the area affected

Accumulation and Correlation

A critical feature of terrorism risk that distinguishes it from most natural perils is that the worst-case scenario is not a geographically dispersed event but a highly concentrated one — an attack in the financial district of a major city, for example, could simultaneously affect the headquarters of multiple large corporations, financial institutions, and insurers. This geographic concentration means that an insurer's terrorism exposure in a single city block could represent an enormous proportion of their total portfolio value.

Accumulation management is therefore central to terrorism risk management. Leading market practice involves mapping all policies with terrorism coverage to a geographic grid and identifying locations where total insured value concentration is highest — the so-called "terrorism PML hotspots." Cities like New York, London, Paris, and Tokyo consistently emerge as locations where insurer accumulations warrant careful management.

The Role of Government Backstops

One of the most distinctive features of terrorism insurance globally is the role of government as a reinsurer of last resort. Following the market failure after 9/11, most major economies have established terrorism pool or backstop arrangements:

  • United States — TRIA: The Terrorism Risk Insurance Act (2002, extended multiple times) requires insurers to offer terrorism coverage and provides a government backstop above a specified industry loss threshold. Insurers retain losses below their individual deductible; losses above trigger proportional government reimbursement.
  • United Kingdom — Pool Re: Pool Re (Pool Reinsurance Company) was established in 1993 following IRA bomb attacks on the City of London. It is a mutual reinsurance pool backed by the UK government as reinsurer of last resort. Pool Re has evolved significantly since 9/11 and now covers a broad range of terrorism scenarios including cyber-enabled terrorism and CBRN.
  • France — GAREAT: Garantie des Risques Attentats et Actes de Terrorisme provides reinsurance for large property terrorism losses through a pool structure backed by the Caisse Centrale de Réassurance (CCR), a state-owned reinsurer.
  • Australia — ARPC: The Australian Reinsurance Pool Corporation provides a government-backed terrorism reinsurance facility covering declared terrorist incidents.
Why Government Backstops Matter for Cat Modellers
Government backstop arrangements fundamentally change the loss distribution faced by private insurers. The backstop effectively caps the insurer's net loss from any single certified terrorism event — above the threshold, the government absorbs losses. Understanding the specific terms of the applicable backstop (trigger threshold, co-participation rate, scope of coverage) is essential for accurately modelling net terrorism losses to any individual insurer's portfolio.

Cyber-Enabled Terrorism

An emerging and rapidly evolving frontier in terrorism risk is the use of cyber means to cause physical damage — cyber-enabled terrorism. Attacks on industrial control systems of critical infrastructure (power grids, water treatment, pipelines, financial systems) could cause physical damage and economic disruption that triggers property and business interruption policies without any conventional explosive or weapon being deployed. The 2021 Colonial Pipeline ransomware attack (which caused fuel shortages across the U.S. East Coast) and the 2015/2016 attacks on the Ukrainian power grid demonstrate that cyber-physical attacks on critical infrastructure are not theoretical — they are happening.

The insurance implications are profound and not yet fully resolved. Standard property policies typically require physical loss or damage to trigger coverage — a cyber attack that disrupts operations without causing physical damage may fall into a coverage gap between cyber policies and property policies. Pool Re in the UK extended its coverage to include cyber-enabled terrorism in 2018, recognising that the terrorism risk landscape is evolving beyond purely physical attack modes.

Post-9/11 Evolution of Terrorism Risk

The terrorism threat landscape has evolved significantly since 2001, with important implications for cat modelling assumptions:

  • Decentralisation: The shift from centralised, hierarchically organised groups (Al-Qaeda's pre-9/11 structure) toward decentralised, franchise-model organisations (ISIS) and lone-wolf attackers has changed the risk profile — more frequent, smaller attacks rather than fewer, catastrophic coordinated ones
  • Domestic terrorism: Right-wing extremism, eco-terrorism, and other forms of domestic political violence have grown as a proportion of total terrorism risk in Western countries — with different geographic and target distributions than international Islamist terrorism
  • Attack complexity: The most sophisticated recent attacks (Paris 2015, Brussels 2016) have demonstrated that coordinated multi-location attacks causing very large aggregate losses remain possible even in a decentralised threat environment
  • Soft target focus: Hardening of traditional hard targets (government buildings, financial institutions) has shifted terrorist attention toward soft targets — public gathering places, transport hubs, entertainment venues — with large people concentration and low physical security

Knowledge Check — Terrorism

Answer all five questions. You need 4 of 5 (80%) to pass.

1. What is the "adaptive adversary problem" in terrorism cat modelling, and why does it make historical data less useful than in natural peril modelling?

ATerrorists adapt their attacks to exploit weaknesses in cat model assumptions, making models self-defeating
BUnlike natural hazards governed by fixed physical laws, terrorists actively adapt their tactics, targets, and methods in response to defensive measures — meaning historical attack data reflects past behaviour under past security conditions, not necessarily future behaviour
CTerrorist attack data is classified and unavailable to commercial cat modellers
DTerrorism events are too rare to appear in historical loss databases

2. For a conventional explosive attack, what is the single most important factor determining structural damage severity at a given location?

AThe type of explosive material used
BThe standoff distance — the distance between the device and the target — because blast pressure decreases very rapidly with distance, making proximity far more important than any other single factor
CThe height at which the device detonates
DThe time of day the attack occurs

3. Why do terrorism insurance policies typically exclude CBRN attacks?

ACBRN attacks are covered under separate government emergency plans, making insurance unnecessary
BCBRN attacks carry potentially unlimited loss potential — particularly nuclear — that cannot be reliably priced, and biological and chemical risks have extraordinary uncertainty; the exposure is too large and too uncertain for private markets to absorb
CCBRN attacks are classified as acts of war rather than terrorism under all legal definitions
DCBRN attack modelling is prohibited by international treaty

4. What was the primary purpose of the U.S. Terrorism Risk Insurance Act (TRIA), passed in 2002?

ATo create a mandatory terrorism cat model standard for all U.S. insurers
BTo restore the availability of commercial terrorism insurance after the near-total market withdrawal following 9/11, by providing a government backstop above specified loss thresholds and requiring insurers to make terrorism coverage available
CTo nationalise terrorism insurance entirely under the federal government
DTo limit terrorism coverage to property damage, excluding liability and workers' compensation

5. How has the terrorism threat landscape evolved since 9/11 in a way that is relevant to accumulation management?

ATerrorism has shifted entirely to cyber attacks, eliminating physical property accumulation concerns
BThe shift toward decentralised organisations and lone-wolf attackers has increased attack frequency but reduced average severity; however, the hardening of traditional hard targets has shifted focus to soft targets — dense public gathering places — that may represent significant accumulations of people and insured value outside traditional financial district concentration zones
CThe threat has diminished sufficiently that accumulation management is no longer a priority
DAll major terrorist organisations now operate exclusively in developing countries, reducing accumulation risk in Western financial centres