As data centres become increasingly critical infrastructure, insurers and reinsurers are seeking more sophisticated analytical models to better quantify potential losses from political violence and terrorism (PVT) risks, according to Tim Brewer, Chief Operating Officer at Synthetik.
Synthetik is a research and development company based in Austin, Texas. It specialises in advanced computational modelling, physics-informed AI, and synthetic data solutions for complex challenges across defence, security, energy, environmental resilience, transportation security, and insurance.
In an interview with Reinsurance News, Brewer explained how the market’s perception of data centres has evolved, with the asset class moving from a standard property exposure to a highly specialised risk requiring more detailed analysis.
“There’s more and more detail around what these assets are and how they work, and the effort that goes into understanding what the exposure is and what the losses might look like,” said Brewer.
“For the market, insured values are high because a data centre can contain orders of magnitude more value than a typical building of the same size, but it’s more the tail risks that insurers are seeing. As we know, it’s not like a normal building. It contains very sensitive bits of equipment that are networked and have all these other dependencies across a different network of services. Those tail risks are where the market sees the most uncertainty, and they’re really trying to quantify what that might be,” he added.
Brewer went on to outline what makes data centres a particularly complex asset class when it comes to modelling PVT exposures.
He said, “We look at different threats, and in different parts of the world there are obviously different threats. In conflict-affected parts of the Middle East, scenarios can include drone and missile strikes. Whereas, if you look at the rest of the world, it’s very different. Maybe strikes, riots and civil commotion or other things are going on.
“Then there’s how those threats interact with the structure, the property and how it can be damaged, but also the dependencies of the data centre: power, cooling and network connectivity, which is another big part of that, and then the people that rely on it. The interaction between all of those things is different.
“These assets can be orders of magnitude more valuable than a normal property of the same size, and their internal equipment can be much more sensitive to shock, vibration and pressure than standard building contents such as laptops and computers. It makes them a really fascinating asset type for us to look at, particularly given the amount of value locked up in them in terms of the asset value and the insurance policies that cover it. Those are the key challenges we have to wrestle with.”
Brewer highlighted that existing market models can be effective at triaging risks, helping identify higher-risk and lower-risk exposures.
He added that insurers and reinsurers are increasingly focused on more sophisticated models that can help them better understand and quantify potential losses.
“The effort that people are putting in at the moment is more detailed analytical models to understand what the losses might be, really trying to quantify it. So, going from a relative measure to actually what a loss might look like, and then how does each threat or hazard type affect or impact that quantified loss? Whether that might be a drone strike or a missile strike in the Middle East, or something more benign or more disruption focused than a weapon hitting a data centre.”
In terms of how re/insurers should approach accumulation risk in this sector, Brewer said insurers and reinsurers should assess exposures through four key lenses.
“One is the physical lens, so what does the building look like? And then, what are the dependencies? That means things like transmission lines, fibre-optic cables, cooling, water and other critical dependencies. The services, ie who the data centre is working for, because a single data centre might serve one hyperscale cloud provider or technology company, or it might serve a mix of different clients, so there might be some interesting dependencies there. And then the contractual and insurance-related terms: how is this covered? What does that structure look like? Is there redundancy in that? Is there adequate capacity in that?”
Looking ahead, Brewer commented on the developments he expects to see in how the insurance market assesses data centre risks.
“I would say more consistency in terms of taxonomy, in other words, what we call things. Data centres are quite heterogeneous structurally; one is not the same as every other one. It’s about understanding what the components are and insurers understanding what that means in terms of their exposure.
“More advanced scenario modelling is another area, and I think that’s true across PVT. Things are much more complex than they were in the 1990s or 2000s. So, they’re going to have to look at more complex modelling and analysis, especially for those tail risks. One of the key issues is that, in normal damage models, we link business interruption to how damaged the building is. If the building has been very damaged, there’s going to be a long period of business interruption to repair it. But with data centres, that kind of gets thrown out. There may not be much visible damage to the building, but the internal components could be severely damaged and need to be replaced. So those older models get out of kilter pretty quickly. That’s another important consideration.”
“Finally, there’s the portfolio management piece, getting differentiation across maybe tens or thousands of data centres. Here in Texas, there are new data centres going up all the time. So, it’s really about understanding, at a portfolio level, how you differentiate and then how you look at those accumulations of risks, both spatially and regionally,” Brewer concluded.




