{
  "id": "ra-cloud-usage-extent",
  "type": "risk-attribute",
  "languages": {
    "en": {
      "id": "ra-cloud-usage-extent",
      "lang": "en",
      "type": "risk-attribute",
      "title": "Cloud Usage Extent",
      "shortDefinition": "Cloud usage extent records how much of an organisation's critical infrastructure, applications and data has moved to public, private or hybrid cloud environments, and how that dependency is configured and secured.",
      "synonyms": [
        "Cloud dependency",
        "Cloud adoption level"
      ],
      "linesOfBusiness": [
        "Cyber"
      ],
      "jurisdictions": [
        "CH",
        "EU",
        "Global"
      ],
      "tags": [
        "IT security",
        "Cloud"
      ],
      "relations": {
        "relatedTerms": [],
        "partOf": [],
        "appliesTo": [],
        "regulatedBy": [],
        "relevantFor": [
          "cov-cyber"
        ],
        "insurableVia": [],
        "mitigatedBy": [],
        "comprises": [],
        "alternativeTo": [],
        "complementedBy": []
      },
      "attribute": {
        "category": "it-cyber",
        "dataType": "enum",
        "questions": [
          "What proportion of critical systems and data is hosted on public, private or hybrid cloud infrastructure, and with which providers?",
          "Who is responsible for security configuration of cloud resources, and is a formal shared-responsibility model in place and understood by IT staff?",
          "Are cloud storage buckets, databases and administrative consoles regularly audited for misconfiguration and public exposure?"
        ],
        "evidence": [
          "Cloud architecture overview or asset inventory",
          "Cloud security configuration audit or cloud security posture management report",
          "Contracts or service-level agreements with cloud providers"
        ],
        "riskDrivers": [
          "severity",
          "accumulation"
        ],
        "ratingImpact": [
          "premium",
          "condition",
          "sublimit"
        ]
      },
      "profile": null,
      "coverageProfile": null,
      "clause": null,
      "legalBasis": [],
      "standards": [],
      "reviewStatus": "expert-reviewed",
      "reviewedBy": "Guido Hesse, Hesse Group Holding AG",
      "lastReviewed": "2026-09-04",
      "version": "0.1.0",
      "updated": "2026-09-03",
      "generated": {
        "by": "cursor-agent/claude-sonnet-5",
        "at": "2026-09-03T00:00:00.000Z"
      },
      "verified": [
        {
          "by": "human:ghesse",
          "at": "2026-09-04T00:00:00.000Z",
          "method": null
        }
      ],
      "staleAfter": null,
      "url": "https://hgh.ch/lexikon/en/knowledge/risk-attribute/cloud-usage-extent/",
      "alternateUrl": "https://hgh.ch/lexikon/de/wissen/risikomerkmal/cloud-nutzung/",
      "body": "## Why it matters for underwriting\n\nCloud usage extent matters to underwriters for two distinct reasons that pull in opposite directions. On one hand, reputable cloud providers typically deliver stronger baseline infrastructure security, redundancy and patching than many insureds could achieve on premises, which can reduce certain frequency exposures. On the other hand, heavy reliance on a small number of cloud providers concentrates accumulation risk across the insurer's entire cyber portfolio, since an outage or breach at a major hyperscaler can simultaneously affect thousands of otherwise unrelated policyholders. Misconfiguration of cloud resources, rather than a failure of the underlying provider infrastructure, is also now one of the most common root causes of large data breaches, making the insured's own configuration discipline just as important as the choice of provider.\n\n## Capturing the attribute and evidence\n\nProposal forms ask for the proportion of critical systems and data hosted in public, private or hybrid cloud environments, the specific providers used, and whether the organisation understands and has formally allocated responsibilities under the shared-responsibility model that governs security duties between provider and customer. Underwriters request a cloud architecture overview or asset inventory, evidence of a cloud security configuration audit or cloud security posture management tooling that continuously checks for exposed storage buckets, overly permissive access policies and unpatched managed services, and copies of service-level agreements confirming the provider's own security and availability commitments. Where a single provider hosts a disproportionate share of critical operations, underwriters also assess single-provider concentration as a distinct exposure.\n\n## Effect on coverage, premium and conditions\n\nWell-governed cloud usage, with documented shared-responsibility allocation, continuous configuration monitoring and diversified providers for the most critical workloads, supports standard terms and can favourably influence pricing relative to an equivalent on-premises estate with weaker baseline controls. Poorly governed cloud usage, characterised by unaudited configurations, unclear internal ownership of cloud security, or undisclosed shadow IT cloud services procured outside central IT oversight, typically results in a premium loading or a condition requiring a configuration audit. Heavy concentration in a single cloud provider without contingency planning can lead to a sublimit or specific condition addressing provider outage as a distinct business interruption trigger.\n\n## Mitigation measures\n\nFormalising the shared-responsibility model internally, so that specific individuals or teams own configuration security rather than assuming the provider covers it entirely, is a foundational recommendation. Continuous automated monitoring for misconfigured storage, databases and identity permissions, commonly through cloud security posture management tooling, is recommended to catch drift before it becomes exploitable. Organisations are also advised to maintain an inventory of all cloud services in use, including those procured outside central IT, and to build contingency and data portability plans for critical workloads concentrated with a single provider."
    },
    "de": {
      "id": "ra-cloud-usage-extent",
      "lang": "de",
      "type": "risk-attribute",
      "title": "Cloud-Nutzung",
      "shortDefinition": "Die Cloud-Nutzung erfasst, welcher Anteil der kritischen Infrastruktur, Anwendungen und Daten eines Unternehmens in öffentliche, private oder hybride Cloud-Umgebungen verlagert wurde und wie diese Abhängigkeit konfiguriert und abgesichert ist.",
      "synonyms": [
        "Cloud-Abhängigkeit",
        "Cloud-Nutzungsgrad"
      ],
      "linesOfBusiness": [
        "Cyber"
      ],
      "jurisdictions": [
        "CH",
        "EU",
        "Global"
      ],
      "tags": [
        "IT-Sicherheit",
        "Cloud"
      ],
      "relations": {
        "relatedTerms": [],
        "partOf": [],
        "appliesTo": [],
        "regulatedBy": [],
        "relevantFor": [
          "cov-cyber"
        ],
        "insurableVia": [],
        "mitigatedBy": [],
        "comprises": [],
        "alternativeTo": [],
        "complementedBy": []
      },
      "attribute": {
        "category": "it-cyber",
        "dataType": "enum",
        "questions": [
          "Welcher Anteil der kritischen Systeme und Daten wird auf öffentlicher, privater oder hybrider Cloud-Infrastruktur betrieben, und bei welchen Anbietern?",
          "Wer ist für die Sicherheitskonfiguration der Cloud-Ressourcen verantwortlich, und ist ein formales Shared-Responsibility-Modell etabliert und der IT-Abteilung bekannt?",
          "Werden Cloud-Speicher, Datenbanken und Administrationskonsolen regelmässig auf Fehlkonfigurationen und öffentliche Zugänglichkeit überprüft?"
        ],
        "evidence": [
          "Übersicht der Cloud-Architektur bzw. Asset-Inventar",
          "Cloud-Sicherheitskonfigurationsaudit oder Cloud-Security-Posture-Management-Bericht",
          "Verträge bzw. Service-Level-Agreements mit Cloud-Anbietern"
        ],
        "riskDrivers": [
          "severity",
          "accumulation"
        ],
        "ratingImpact": [
          "premium",
          "condition",
          "sublimit"
        ]
      },
      "profile": null,
      "coverageProfile": null,
      "clause": null,
      "legalBasis": [],
      "standards": [],
      "reviewStatus": "expert-reviewed",
      "reviewedBy": "Guido Hesse, Hesse Group Holding AG",
      "lastReviewed": "2026-09-04",
      "version": "0.1.0",
      "updated": "2026-09-03",
      "generated": {
        "by": "cursor-agent/claude-sonnet-5",
        "at": "2026-09-03T00:00:00.000Z"
      },
      "verified": [
        {
          "by": "human:ghesse",
          "at": "2026-09-04T00:00:00.000Z",
          "method": null
        }
      ],
      "staleAfter": null,
      "url": "https://hgh.ch/lexikon/de/wissen/risikomerkmal/cloud-nutzung/",
      "alternateUrl": "https://hgh.ch/lexikon/en/knowledge/risk-attribute/cloud-usage-extent/",
      "body": "## Warum relevant für das Underwriting\n\nDer Umfang der Cloud-Nutzung ist für Underwriter aus zwei gegenläufigen Gründen relevant. Zum einen bieten renommierte Cloud-Anbieter in der Regel eine stärkere Basissicherheit, Redundanz und Patch-Disziplin auf Infrastrukturebene, als viele Versicherungsnehmer im eigenen Rechenzentrum erreichen könnten, was gewisse Frequenzrisiken senken kann. Zum anderen konzentriert eine starke Abhängigkeit von wenigen Cloud-Anbietern das Kumulrisiko über das gesamte Cyberportfolio eines Versicherers, da ein Ausfall oder eine Sicherheitsverletzung bei einem grossen Hyperscaler gleichzeitig tausende sonst unabhängige Versicherungsnehmer treffen kann. Fehlkonfigurationen von Cloud-Ressourcen und nicht ein Versagen der zugrunde liegenden Anbieterinfrastruktur sind inzwischen zudem eine der häufigsten Ursachen grosser Datenschutzverletzungen, wodurch die eigene Konfigurationsdisziplin des Versicherungsnehmers ebenso wichtig ist wie die Wahl des Anbieters.\n\n## Erfassung und Nachweise\n\nAntragsformulare fragen nach dem Anteil kritischer Systeme und Daten in öffentlichen, privaten oder hybriden Cloud-Umgebungen, den konkret genutzten Anbietern und danach, ob das Unternehmen das Shared-Responsibility-Modell versteht und die Sicherheitsaufgaben zwischen Anbieter und Kunde formal zugeordnet hat. Underwriter verlangen eine Übersicht der Cloud-Architektur bzw. ein Asset-Inventar, den Nachweis eines Cloud-Sicherheitskonfigurationsaudits oder eines Cloud-Security-Posture-Management-Tools, das fortlaufend auf offen zugängliche Speicher, zu weit gefasste Zugriffsrichtlinien und ungepatchte Managed-Services prüft, sowie Kopien der Service-Level-Agreements mit den Sicherheits- und Verfügbarkeitszusagen des Anbieters. Übernimmt ein einzelner Anbieter einen unverhältnismässig grossen Anteil kritischer Betriebsabläufe, bewerten Underwriter diese Anbieterkonzentration zusätzlich als eigenständige Exposition.\n\n## Wirkung auf Deckung, Prämie und Bedingungen\n\nEine gut geführte Cloud-Nutzung mit dokumentierter Zuordnung im Shared-Responsibility-Modell, laufender Konfigurationsüberwachung und diversifizierten Anbietern für die kritischsten Workloads unterstützt Standardbedingungen und kann sich im Vergleich zu einer gleichwertigen On-Premises-Umgebung mit schwächeren Basiskontrollen günstig auf die Prämie auswirken. Eine schlecht geführte Cloud-Nutzung, erkennbar an ungeprüften Konfigurationen, unklarer interner Verantwortung für die Cloud-Sicherheit oder nicht offengelegten Schatten-IT-Cloud-Diensten ausserhalb der zentralen IT-Kontrolle, führt in der Regel zu einem Prämienzuschlag oder einer Obliegenheit zur Durchführung eines Konfigurationsaudits. Eine starke Konzentration auf einen einzigen Cloud-Anbieter ohne Notfallplanung kann zu einer Sublimite oder einer spezifischen Bedingung für einen Anbieterausfall als eigenständigen Betriebsunterbrechungsauslöser führen.\n\n## Massnahmen\n\nEine grundlegende Empfehlung ist die interne Formalisierung des Shared-Responsibility-Modells, sodass konkrete Personen oder Teams die Verantwortung für die Konfigurationssicherheit tragen, statt anzunehmen, der Anbieter decke dies vollständig ab. Eine kontinuierliche automatisierte Überwachung auf fehlkonfigurierte Speicher, Datenbanken und Identitätsberechtigungen, üblicherweise über Cloud-Security-Posture-Management-Tools, wird empfohlen, um Abweichungen zu erkennen, bevor sie ausnutzbar werden. Unternehmen wird zudem empfohlen, ein Inventar sämtlicher genutzter Cloud-Dienste zu führen, einschliesslich solcher ausserhalb der zentralen IT-Beschaffung, und Notfall- sowie Datenportabilitätspläne für kritische, bei einem einzelnen Anbieter konzentrierte Workloads zu erstellen."
    }
  }
}