A family identifies the mechanism to examine
Terms such as “hack” or “failure” are not enough to understand a loss. They can bring together very different events. Ask which mechanism was compromised and how that reached the position: the answer helps locate the relevant risk family.
The catalogue uses seven families: protocol, custody, loss of peg, bridge, validator penalty, exchange and other declared risks. Cyber Risk describes a perspective on cyber incidents that can cut across those families; it is not an automatic cover or an eighth category in the catalogue.
The family organises the search. The contract defines the event, the limits, the eligibility and the exclusions of a specific cover. Recognising the category of an incident is only part of the reading needed to assess a request.
Locate what the position depended on
For each position, identify who or what allows its safekeeping, its movement and its restitution. The same position may depend on more than one mechanism, so the families do not need to be treated as isolated risks.
Examine the code for protocol risk; who controls the assets for custody; the mechanism that seeks the reference for a depeg; the connection between networks for a bridge; the validator's rules for slashing; and the exchange's safekeeping and withdrawal conditions for exchange risk. Specific events outside these groups require their own description in the contract.
This map also makes it possible to recognise common dependencies. Different assets or services may use the same custodian, contract or infrastructure. An incident at that point can reach several positions; the number of assets, on its own, does not describe the concentration.
Relate the map to the cover conditions
Organise a list with the position, the network, who is responsible for safekeeping and the services used. Add the relevant families and the controls already in place. The aim is to know where a loss could come from and which records would make it possible to understand an incident.
Then compare the exposure identified with the published covers. Consider costs, limits, requirements and exclusions alongside the operation's controls. Purchase depends on availability and does not replace management of the dependencies that remain.