Ask a terrorism underwriter and a cyber underwriter the same question what's the one loss that could actually break you?, and increasingly you get the same shape of answer: something that hits everyone at once, spreads faster than the policy wording anticipated, and doesn't show up anywhere in the historical loss data.
That is not a coincidence. It is, in large part, a direct inheritance from 11 September 2001, twenty-five years ago this month.
Long before 9/11, actuaries had a rough checklist for deciding whether a risk belongs in an insurance policy at all: can the potential loss be modelled with any confidence, does it occur more or less at random, and does it stay reasonably independent of other losses rather than clustering into one another? A single house fire passes easily. A coordinated, deliberate attack on multiple targets does not, it is designed to happen, designed to concentrate damage, and arrives with none of the decades of loss history that price a flood or a car crash.
That was exactly the problem 9/11 handed the market. A single event tore through property, aviation, life, workers' compensation and liability lines simultaneously, in a way no actuary had modelled and no reinsurer had reserved for.
According to the Insurance Information Institute, the attacks eventually cost insurers and reinsurers around $59 billion in 2024 dollars, with reinsurers picking up roughly two-thirds of that bill.
Very few catastrophes since have come close to that figure in real terms. Hurricane Katrina is the clearest one that has, but Katrina, like almost everything else on that list, was an accident. 9/11 was not, and that distinction is exactly why the loss broke the market rather than merely straining it: nine years earlier, Hurricane Andrew had already pushed several insurers into insolvency and forced the invention of modern catastrophe modelling, but at least a hurricane's failure mode was random. Terrorism's isn't, and reinsurers responded to 9/11 by pulling cover altogether rather than trying to reprice something they couldn't model.
What happened next is the part of the story that matters most for our industry today, because it is essentially a working template for any risk that fails the insurability test at scale: government steps in as reinsurer of last resort, and the private market slowly claws capacity back over time.
In the US, that meant the Terrorism Risk Insurance Act of 2002, a federal backstop that has been renewed repeatedly and now runs to 2027. France built GAREAT the same year; Germany followed with Extremus.
The UK's Pool Re actually predates 9/11 by nearly a decade having been set up in 1993 after the IRA's Baltic Exchange bombing, but 9/11 forced it to widen dramatically. Reinsurers had been willing to sit alongside Pool Re's narrower fire-and-explosion cover before 2001; afterwards they weren't, so in 2002 Pool Re moved to an "all risks" basis and dropped its exclusions for chemical, biological, radiological and nuclear attacks.
Pool Re has spent the past decade pulling the risk back towards private capital rather than leaning further on the state: it now covers cyber-triggered terrorism and non-damage business interruption, and its fourth catastrophe bond, priced in early 2026, took its insurance-linked securities capacity to £200 million on top of a £2.75 billion traditional retrocession placement. Its own published figures put total insured liabilities at roughly £2.2 trillion which is a remarkable scale for a scheme that started life patching a 1990s market failure.
"We are committed to reducing the financial burden on UK taxpayers," Pool Re chief executive Tom Clementi said when the reinsurer placed its third catastrophe bond in 2025 - a line that could just as easily sum up the entire 25-year arc since 2001: build the public backstop first, then spend a generation shrinking it.
9/11 left one more legacy that has nothing to do with terrorism pools at all. When the towers fell, the final policy wording for the World Trade Center's property cover hadn't actually been signed off as cover had been bound informally, on the understanding that the wording would follow. That left one enormous, expensive question open: were the two aircraft strikes one occurrence or two? Given the policy limits at stake, the answer was worth billions, and it took years of litigation to resolve.
The London Market's response was to tighten up how it does business at the most basic level. "Contract certainty" - agreeing and documenting every term before cover incepts, rather than binding first and finalising the wording later - became the standard the market has worked towards ever since. It is a dry, back-office sort of reform, but it exists because of a dispute over two towers and an unfinished document.
None of this is really about terrorism anymore. War risk affecting shipping and aviation, systemic cyber events capable of cascading through thousands of unrelated policyholders through a single shared supplier, and the modelling uncertainty attached to AI-enabled attacks are all, in insurability terms, the same problem 9/11 first forced the market to confront: a loss that is too large, too clustered, or too poorly understood for private capital to hold alone.
The response the industry built a quarter of a century ago was pool the exposure, bring in capital markets, keep government as a backstop rather than a permanent crutch. That is now the default followed whenever a new systemic risk turns up. Pool Re's journey from niche IRA-era reinsurer to sophisticated ILS issuer is arguably the clearest UK proof that the model can eventually work itself out of a job, at least partially. Whether cyber and AI risk will get twenty-five years to do the same is the question the market is now living through in real time.