Why Are Insurers Still Pricing Digital Risk Like It's 2015?
When digital harm results in litigation, regulatory action, or insured loss, the debate rarely centres on intent. It centres on foreseeability: What risks were known, or should reasonably have been known and at what point in the system were they governed? In recent years, sign...
Emma Parfitt
What Gets Priced
Foreseeability, Not Intent
When digital harm results in litigation, regulatory action, or insured loss, the debate rarely centres on intent. It centres on foreseeability: What risks were known, or should reasonably have been known and at what point in the system were they governed? In recent years, significant attention has been paid to downstream controls: content moderation, enforcement, and post-incident response. These are visible, auditable, and comparatively easy to model. What remains less clearly priced is the risk that forms earlier, at the point of entry, where identity, access, and behavioural signals first converge.
Risk starts earlier
Upstream Exposure
Much of today’s digital risk assessment relies on an implicit assumption: that once access conditions are set, exposure meaningfully reduces. In practice, access controls are often treated as binary declarations rather than probabilistic risk layers. It is well established that users misrepresent themselves, provide false data, and bypass age or eligibility gates. These dynamics are not edge cases; they are predictable financial risks. From an insurance perspective, the question is not whether access rules exist, but whether the residual risk they leave behind is understood, monitored, and actively mitigated. Yet few underwriting models currently distinguish between platforms that treat access as a static gate and those that actively assess and document risk at entry.
Gates aren't guarantees
Access Isn’t Binary
Online harm rarely emerges from a single failure. It develops through a sequence of events: who entered a system, how they interacted within it, and how early signals were interpreted or missed. When access pathways are weak or treated as a fixed assumption, downstream controls inherit disproportionate liability. Moderation teams, enforcement mechanisms, and response protocols are left managing risk that has already compounded. This concentrates exposure at a later layer of the system, increasing both severity and cost when harm materialises.
How harm escalates
Downstream Inherits Liability
None of this implies that platforms carry automatic or unlimited liability for all harm. Nor does it suggest that digital environments can be rendered risk-free. It does, however, raise a quieter underwriting question: whether current models over-index on visible controls, while under-pricing the conditions that shape risk before those controls ever engage. In other sectors, from fraud to fire prevention, insurers routinely distinguish between early-stage risk governance and post-incident response. The same distinction is possible in digital environments, but it requires visibility into systems that most underwriting frameworks do not yet capture.
A model gap
Visible Controls, Missed Causes
There is a growing case for evaluating digital risk closer to the point of entry, where identity, intent, and behavioural patterns first intersect. Systems that surface early indicators of elevated risk alter the loss profile in ways that enforcement alone cannot. They change not just outcomes, but frequency, severity, and predictability: the variables underwriting ultimately depend on.
Recognise real mitigation
Price Entry-Stage Governance
Treating access as a static prerequisite rather than an active risk layer leaves a gap between how digital harm forms and how it is currently priced. As digital environments continue to scale, liability is increasingly tracing back upstream. The question for insurers is no longer simply what controls exist, but where in the system risk is actually being governed.Frameworks that assess and document risk at the point of entry, rather than inheriting it downstream, are not theoretical. They exist. The question is whether underwriting models are built to recognise their value.

Emma Parfitt
Founder & Principal Consultant
Over a decade in social work and child protection. Founder of the Front Door Theory framework. Working with organisations to build safeguarding architecture that holds under pressure.
Related Risk Management

They Didn't Look at It. Now a Jury Made Them.
Yesterday, a New Mexico jury ordered Meta to pay $375 million for misleading users about child safety...

Detection vs Governance: What Insurers Are Actually Pricing
Much of the digital safety conversation is dominated by detection. Platforms point to moderation tools, automated alerts, and response protocols designed to identify harm once it occurs. These mechanisms are visible, auditable, and comparatively easy to evidence. They matter, ...