Digital Dominoes: Scanning the Internet to Expose Systemic Cyber Risk

Black Hat USA 2025 · Day 1 · Briefings

Overview

Morgan Hervé-Minucci of Coalition, one of North America's largest cyber insurers, argues that the current generation of catastrophe models used to quantify systemic cyber risk are structurally broken — anchored in natural-catastrophe frameworks, fed on fear-driven scenarios, and blind to the actual technology dependencies that determine how failures propagate. His alternative: continuously scan the entire internet to build a granular graph of organizational technology dependencies, then model systemic risk from empirical data rather than speculation. ---

Watch on YouTube

Visual summary for Digital Dominoes: Scanning the Internet to Expose Systemic Cyber Risk
Visual summary for Digital Dominoes: Scanning the Internet to Expose Systemic Cyber Risk

Key moments

  1. 1:59 Scale: Change Healthcare, CDK Global, CrowdStrike show digital domino cascades
  2. 7:59 Gap: insurance CAT models only cover insured orgs, miss systemic societal risk
  3. 12:00 Methodology: internet-scale scanning identifies critical vendor concentration points
  4. 16:00 Finding: small number of software vendors underpin outsized share of exposed infrastructure
  5. 20:00 Demo: live internet scan quantifies real-time systemic risk from single vendor outage
  6. 24:00 Key stat: economic losses from cyber events dwarf insured payments, exposing protection gap
  7. 26:59 Conclusion: proactive vendor concentration mapping enables pre-event risk intervention

Digital Dominoes: Scanning the Internet to Expose Systemic Cyber Risk

Speaker: Morgan Hervé-Minucci, Head of Cyber Catastrophe Modeling, Coalition

Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas

YouTube: https://www.youtube.com/watch?v=sPyhJykSLUw

Reading Time: ~8 minutes

Type: Briefing

TL;DR

Morgan Hervé-Minucci of Coalition, one of North America's largest cyber insurers, argues that the current generation of catastrophe models used to quantify systemic cyber risk are structurally broken — anchored in natural-catastrophe frameworks, fed on fear-driven scenarios, and blind to the actual technology dependencies that determine how failures propagate. His alternative: continuously scan the entire internet to build a granular graph of organizational technology dependencies, then model systemic risk from empirical data rather than speculation.

Introduction

Three incidents in eighteen months made the fragility of digital supply chains viscerally clear. Change Healthcare's ransomware attack in 2024 effectively brought U.S. healthcare billing to a halt. CDK Global's outage took down up to fifteen thousand auto dealerships across North America. The CrowdStrike faulty update last summer grounded airline flights worldwide. These were not isolated failures — they were cascading collapses triggered by a single node in a highly concentrated dependency graph.

For Morgan Hervé-Minucci, who leads cyber catastrophe modeling at Coalition and previously developed cyber risk models for the largest CAT model vendor in the insurance market, these events were diagnostic. They exposed the mismatch between how the industry models systemic cyber risk and how that risk actually behaves. His talk at Black Hat 2025 presents a methodology to close that gap: internet-scale network scanning, dependency graph construction, and empirical loss modeling at the level of individual technology stacks and cloud service regions.

Why Current CAT Models Fail

▶ Watch: The Problem With Existing Models (10:00)

The insurance industry inherited its catastrophe modeling frameworks from natural disaster analysis — hurricane, earthquake, flood. The standard pipeline runs: define a scenario → identify exposed assets → estimate vulnerability → compute expected losses → produce a probabilistic loss curve. This is well-suited to physical perils with well-characterized historical distributions. It is a poor fit for cyber risk, for three fundamental reasons.

First, design misalignment: cyber events are adversarial, adaptive, and dynamic. A hurricane doesn't change strategy when it encounters a seawall. A threat actor does. Even accounting for climate change, hurricanes are more predictable than nation-state actors or ransomware gangs.

Second, measurement gaps: the industry has never experienced a "Category 5 digital hurricane" that validated model outputs at the tail. First-generation CAT model vendors doubled down on extreme scenarios to attract attention, and now that those models are embedded in regulatory and investment processes, there is little commercial incentive to revise them downward — even when empirical data suggests the extreme scenarios are implausible.

Third, granularity failure: traditional CAT models treat all customers of a given provider as interchangeable. All AWS customers are assumed to have the same exposure profile; all outages are assumed to have uniform impact. In reality, an AWS US-East-1 regional outage has radically different impact from a global multi-region outage. Companies running on AWS US-East-1 for a single pricing microservice have radically different exposure from companies running their entire customer-facing stack there.

The New Approach: A Dependency Graph Built From Internet Scans

▶ Watch: Building the Dependency Graph (12:00)

Hervé-Minucci's methodology models systemic cyber risk as what it actually is: a massive, interconnected graph of technology dependencies. The nodes are Aggregation Technologies and Vendors (ATVs) — software platforms, cloud providers, SaaS tools, CDN providers, payment processors, and any other technology whose failure would propagate to dependent organizations. The edges represent dependency relationships between organizations and ATVs.

To build this graph, Coalition leverages its proprietary network measurement infrastructure — the same system used to continuously scan policyholders for underwriting purposes — at internet scale. The process involves:

  1. Passive and active network reconnaissance across millions of organizational domains
  2. Technology fingerprinting to identify specific ATVs from observable signals (TLS certificates, HTTP headers, DNS records, open ports, response patterns)
  3. Cloud service attribution — distinguishing not just "this company uses AWS" but "this company uses AWS US-East-1 for Athena serving their dynamic pricing function"
  4. Continuous re-scanning to keep the dependency graph current as organizational tech stacks evolve

The result is a two-dimensional data matrix: along one axis, organizational details at increasing resolution; along the other, ATV-level details at increasing granularity. The bottom-left of this matrix — low organizational detail, generic ATV data — represents where traditional CAT models operate. The top-right — full organizational stack with service-level and region-level ATV attribution — is where this methodology aims to operate.

Three Deep Dives: Inc. 5000, Investment Advisors, and Real Estate

▶ Watch: Portfolio Case Studies (16:00)

Hervé-Minucci demonstrated the model against three distinct portfolios from the U.S. economy.

Inc. 5000 — Fastest-growing private companies: The dependency graph revealed that virtually every company in this portfolio runs on Google Workspace, creating significant concentration risk around a single productivity platform. The visualization allows filtering by ATV criticality and centrality to remove low-signal nodes and surface genuine systemic exposures.

Registered Investment Advisers (RIAs): Coalition scanned twenty-two thousand firms across eighteen thousand domains and found heavy technology monoculture — a pattern that creates both insurance aggregation risk and potential systemic economic risk. Notably, the model can distinguish between a regional AWS outage with a $100M estimated impact and a global outage with a different (and in some cases smaller, because resilient firms have multi-region architectures) impact. This regional granularity is invisible to standard CAT frameworks.

Connecticut real estate agencies: The analysis surfaced industry-specific SaaS platforms and franchisor IT systems that wouldn't appear in any macro technology analysis. Anywhere Real Estate (the franchisor for Century 21 and Coldwell Banker), LoopLink (used for agent marketing), and Keller Williams franchise technology each emerged as significant local concentration nodes. These are technologies no one would identify as systemic risks from a top-down analysis, yet their failure would disrupt most real estate transactions in an entire state.

The pattern across all three portfolios: standard CAT model scenarios assuming week-long global outages at major cloud providers are not credible based on empirical outage history, which has been concentrated at zone or regional levels. The actual risk lies in industry-specific SaaS and vertical software platforms that lack the resilience engineering of hyperscale cloud providers.

Regulatory Signals and Antitrust Data

▶ Watch: Policy and Regulatory Context (24:00)

Hervé-Minucci mines FTC antitrust data as a supplementary signal for technology concentration — regulatory scrutiny of market consolidation is a leading indicator of the same dependency centralization that creates systemic cyber risk. Categories flagged include mortgage software, real estate platforms, financial software APIs, and healthcare billing systems. Colonial Pipeline's 2021 attack produced the first TSA cybersecurity directive for pipelines and railroads. Change Healthcare's attack is likely to produce analogous mandates in healthcare billing. This historical pattern argues for using litigation and regulatory data proactively, before the next cascade, to direct scanning and monitoring attention.

Recommendations

▶ Watch: Recommendations for Three Audiences (24:00)

Hervé-Minucci structured distinct recommendations for three groups:

Policymakers: Expand the definition of critical infrastructure from "sectors" to "technologies" — the mental shift from "entities too big to fail" to "technologies too connected to fail." Continue mandating visibility into organizational technology dependencies. Use dependency data to guide antitrust and regulatory policy, because extreme tech concentration is a direct national security issue, not merely an economic one.

Risk owners and CISOs: You cannot prevent systemic cyber risk, but you can build organizational resilience against it. Map your own nth-degree vendor dependencies against macro concentration data. Maintain real-time asset inventories and attack surface management programs. Apply zero-trust and assumed-breach architectures to limit blast radius when upstream vendors fail.

Risk modelers: Prioritize data-driven economic loss modeling over the entire economy, not just the insured sliver. The insurance loss modeling problem is largely solved; the challenge is applying it to the broader picture. Commit to auditable model loss items — "garbage in, garbage out" scenarios credentialized by institutional adoption serve no one. Week-long global cloud outages are not useful stress tests; precise, granular, regionally specific scenarios are.

Notable Quotes

"We need to shift from thinking about entities that are too big to fail to identifying technologies that are too connected to fail."

— Morgan Hervé-Minucci ▶ 24:00

"Week-long global outages is not helping, and at the same time, missing out on what's happening into specific industries is a pretty big gap."

— Morgan Hervé-Minucci ▶ 28:00

"Extreme tech concentration is no longer just an economic issue — it's a direct impact on national security."

— Morgan Hervé-Minucci ▶ 26:00

"Not all outages are created equal. A regional outage and a global outage can have very different, and sometimes counterintuitive, financial impacts."

— Morgan Hervé-Minucci ▶ 20:00

Key Takeaways

  • Natural-catastrophe modeling frameworks are a poor fit for systemic cyber risk. Cyber events are adversarial, adaptive, and empirically unlike hurricanes or earthquakes in their distribution and propagation.
  • Technology monoculture is the real systemic risk. Industry-specific SaaS platforms and vertical software dominate real-world failure cascades far more than the hyperscale cloud outages that dominate CAT model scenarios.
  • Granularity matters enormously. The difference between a regional and global cloud outage — in terms of actual organizational impact — is invisible to standard models but observable through continuous internet scanning and technology fingerprinting.
  • Antitrust data is a proactive leading indicator of technology concentration that deserves systematic use in systemic risk assessment.
  • Reactive policymaking must give way to proactive dependency mapping. Every major policy intervention — from post-WannaCry SBOM mandates to TSA pipeline directives — has come after a major incident. The tools to anticipate the next cascade now exist.

Slides: No slide PDF was available for this talk.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Coalition's Head of Catastrophe Modeling is arguing that the insurance industry's cyber risk models are broken, which is true, and his empirical alternative — continuous internet scanning to build a granular technology dependency graph — is more rigorous than anything the CAT model vendors are currently doing. Cross-disciplinary find for the right audience; niche for everyone else.

Heather Calloway (CISO) — MUST SEE

A cyber insurer who continuously scans the entire internet just showed that the catastrophe models driving regulatory policy and insurance pricing are structurally broken — anchored in hurricane frameworks, blind to actual technology dependencies, and systematically wrong about where systemic risk actually lives. The real concentration risk isn't AWS going down globally; it's the vertical SaaS platforms nobody's modeling. This is the governance conversation the industry has been avoiding.

→ Top-rated talks at Black Hat USA 2025

All talks from Black Hat USA 2025