Will the new Cyber Monitoring Centre’s categorisation scale really help?

By Colin Hayes
Colin Hayes from Penningtons Manches Cooper shares his thoughts on whether the new cyber incident categorisation scale from the Cyber Monitoring Centre is likely to meet expectations
February 2025 saw the official launch of the Cyber Monitoring Centre (CMC), which had been operating in ‘stealth mode’ for the preceding 12 months.
What is the CMC and how does it work?
The CMC describes itself as a ‘an independent, non-profit organisation that uses an objective framework to assess the severity of major cyber events as they occur’.
The CMC will categorise cyber incidents on a scale from one to five, with five being the most severe incident. Relevant events will include large-scale cyber incidents (such as the CrowdStrike incident in July 2024), data breaches, targeted disruptive cyberattacks and supply chain cyberattacks. To be categorised, events must have a potential financial impact greater than £100 million, affect multiple organisations and have sufficient data to enable assessment. The estimated financial impact includes losses due to business interruption, data restoration, incident response costs, extortion (ransomware), transfer of funds and the downstream consequential impacts of a cyber event.
The categorisation is said to be data driven and has been refined during the 12-month incubation period. It combines a range of sources utilised to categorise major incidents, including bespoke polling, media scanning, public and private data sources (including via various data partnerships) and event modelling.
What are the benefits?
Categorising the severity of major cyber incidents has always been a difficult task for a number of reasons: a lack of standardisation, the limited availability of data, the sheer complexity of measuring the wider impact and the ever-evolving threat landscape. However, with a standardised framework to assess systemic cyber incidents, insurers can more accurately evaluate the risks connected with different types and scales of cyber threat.
This provides a number of additional benefits for cyber insurers, including:
data on the risks associated with different cyber events will enable underwriters to underwrite risks more precisely, assisting in the pricing of policies;
policies could be drafted with greater clarity and certainty. For example, clauses could be drafted with direct reference to specific event categories as triggers or limits on cover;
it may alleviate some of the issues arising from the use of (often ambiguous) policy exclusions in regard to systemic risks, including the problematic use of ‘war’ exclusions, which necessarily rely upon attributing a cyberattack to a state actor. This can take many months (or years) to become clear, and still leaves scope for major systemic events to slip through the net, where they cannot necessarily be attributed to a rogue state; and















