When the European Union General Data Protection Regulation (GDPR) came into effect in May 2018, we in the cyber insurance industry all wondered how zealously each national enforcement agency would levy fines for the inevitable infringements.
At the time of the announcement, the Cyence Cyber Risk model was predicting that Marriott had a probability of 83% of having any incident and a probability of 43% of having a data breach specifically. Perhaps more relevant, our model estimated a 12% probability of having an insurance relevant incident.