The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Chattinn Cyber
Chattinn Cyber artwork

The Origins of Cyber Insurance with Pioneer Bob Parisi

Chattinn Cyber · 2026-04-21 · 53 min

0:00--:--

Key moments - from our scoring

Substance score

61 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber16 / 20
Specificity & Evidence13 / 20
Conversational Craft9 / 20

In this special 100th episode, Marc Schein interviews Bob Parisi, one of the architects of commercial cyber insurance, tracing the product's 25+ year trajectory from mid-1999 through present day. Parisi details how AIG assembled a dedicated technology team under Phil Hoyt to address e-commerce exposures, partnering with brokers like Emily Freeman at Marsh and Peter Foster on products like Net Secure. The conversation reveals how cyber evolved from a dot-com bubble play to a privacy-focused product (2004-2015) before pivotal recognition around 2015 that business interruption and technology dependence were the real driver. Parisi explains the silent cyber issue - underwriting gaps between property/casualty and dedicated cyber forms - and how it forced alignment around cyber-specific underwriting with appropriate pricing and reserving. The discussion addresses today's paradox: while 50-100 cyber carriers and MGAs exist, capacity fragmentation prevents large industrials from accessing needed limits (typically capping at $700-800M despite $2B+ capacity), and the market remains bifurcated between SME carriers offering breach response and large account platforms managing sophisticated vendor relationships. For B2B risk managers and brokers, Parisi advocates against isolated cyber placement, emphasizing integration with E&O, crime, and property lines where exposures naturally overlap.

Key takeaways

  • →Cyber insurance originated not from underwriter innovation but from AIG's strategic 1999 decision to focus on e-commerce exposures, with the first truly scalable commercial product (Net Secure) developed collaboratively with Marsh brokers Emily Freeman and Peter Foster.
  • →The market evolved through distinct phases: dot-com startup coverage (1999), privacy breach response dominance (2004-2015), and business interruption recognition (2015+), with silent cyber forcing alignment around dedicated cyber underwriting separate from property and casualty.
  • →Despite 50-100+ cyber carriers and MGAs existing with $2B+ aggregate capacity, market fragmentation - each carrier using different forms and approaches - prevents large industrials from accessing needed limits, typically capping at $700-800M due to misaligned underwriting.
  • →The SME cyber space innovated more aggressively than large account segments, with carriers like Beazley, HSB, and Muncaster embedding breach response services and forensics vendor management to control claims and fill gaps small companies lack (CISOs, legal relationships, internal hierarchy).
  • →Cyber insurance should not be placed in isolation; overlapping exposures with professional liability, crime, property and casualty require integrated coverage strategies and careful coordination to avoid ambiguous dual-policy responses to the same risk.

Guests

Bob Parisi

Topics in this episode

Cyber insurance origins and historySilent cyber coverageNet Secure policyBreach response servicesAIG cyber insurance divisionProfessional liability (E&O) integrationProperty and casualty cyber overlapsBusiness interruption from cyber eventsCyber MGAs and insurtech platformsCyber insurance capacity fragmentation

Questions this episode answers

Who created the first commercially scalable cyber insurance policy in 1999?

Peter Foster at Marsh developed Net Secure, which Parisi describes as probably the first truly commercially scalable cyber policy, developed collaboratively with Emily Freeman at Marsh and AIG's team under Phil Hoyt.

What was silent cyber and why did it matter to the insurance market?

Silent cyber refers to cyber exposures hidden within traditional property and casualty policies - when underwriters didn't explicitly reserve or exclude cyber coverage. It forced the property/casualty market to pull back from cyber-related risks and required dedicated cyber insurers to build cyber-specific expertise, pricing, and reserving.

Why can't large industrials access their full needed cyber insurance limits today?

Despite 50-100 cyber carriers offering $2B+ total capacity, each carrier uses different forms and underwriting approaches, preventing alignment and aggregation on single risks; large industrials typically cap at $700-800M despite needing $2B+ limits because the market cannot coordinate across so many fragmented players.

What's the difference between SME and large account cyber insurance approaches?

SME carriers like Beazley and HSB embed breach response services and forensics vendor management because small companies lack internal resources (CISOs, legal relationships); large accounts with Fortune 500 sophistication want managed vendor panels and balance-sheet protection, not dictated claims processes.

Should cyber insurance be purchased as a standalone policy?

No - cyber exposures overlap materially with professional liability, crime, and property/casualty, and placing them separately risks ambiguous dual-policy responses to the same loss; integrated placement with E&O and property is best practice.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains genuine substance about the market's evolution - the post-dot-com-bust tech adoption spike, the shift from privacy product to BI product, and the capacity alignment problem in large accounts - but it is diluted by historical narrative, vague hedging, and conversational filler. A smart operator learns real things but must work through considerable padding to find them.

one of the metrics that we saw was a quadrupling of uh, the use of Internet and technology by brick and mortar companies
there's more than enough capacity to probably get US to roughly 2 billion, but we can't get the market to align all on one risk

Originality

11 / 20

There are a few genuinely fresh framings - the milk-spilling vs. milk-storage analogy for US vs. EU privacy law, the three-bucket AI taxonomy (fanboys, deniers, middle lane), and the attribution challenge as the real war-exclusion problem - but the bulk of the conversation recycles standard industry talking points about MFA, silent cyber, and IoT cycles.

for the longest time, the US And North American privacy laws were about, someone spilled some milk, how do we punish them? Uh, and then you saw, you know, GDPR in the EU and that wasn't about punishing someone if the milk spilled. It was, how do you. How do you keep the milk from spoiling?
The folks that are fanboying over AI and can't wait to deploy it everywhere they possibly can, can in their organization, they scare me. Uh, the folks that say they are not using any AI, they will never use it. They hate it. It's the most horrible thing in the world. Another red flag

Guest Caliber

16 / 20

Bob Parisi is a genuine practitioner who was inside AIG's professional liability group at the literal creation of cyber policy in 1999, spent 15 years on the broker side at Marsh, and now sits at Munich Re - he is a rare primary source, not a recycled thought leader, and his institutional memory is verifiable throughout the transcript.

they sent me over there because most of these people that were, uh, most of these underwriters they were bringing over were not AIG folks. Right? They were coming from other companies. So I got sent over there to make sure they did it the AIG way
we worked, uh, very closely with Marsh at the Time woman named Emily Freeman had was, I'd say one of the, if you wanted to talk about the OGs of uh, cyber insurance, she's right there. Peter Foster at um, now, uh, you know, now at Willis, then at Marshall, uh, brought something uh, a concept called Net Secure

Specificity & Evidence

13 / 20

The transcript offers useful named specifics - people (Emily Freeman, Peter Foster, Phil Hoyt), products (AI Link, Net Secure), companies (Beazley, HSB, Municree), and the concrete capacity figure of 7 - 800M actual vs. ~2B theoretical - but there are no loss ratios, premium data, or hard claims statistics to anchor the market assertions.

there's more than enough capacity to probably get US to roughly 2 billion, but we can't get the market to align all on one risk. So what you're left with is in many cases large industrials viewing cyber as their biggest risk, um, in that direct loss context where they normally would buy a couple of billion, but they still can't get to more than say, you know, 7 to 800 million, um, out of the cyber market
we rolled the policy out in, I believe it was mid 99

Conversational Craft

9 / 20

The host demonstrates genuine domain knowledge and navigates the topic arc competently, but defaults repeatedly to open-ended tee-ups without following up on specific claims or pushing back on vague assertions; the closing Pokémon tangent consumes time that could have been used to press on unresolved threads like Munich Re's actual war exclusion language.

So Bob, that's interesting. You're kind of talking about the dot com era and when you speak to a lot of brokers now they talk about kind of the early days of Cyber was around 2015 to 2018. So can you tell us about how kind of the product has evolved
Is there any one control or any one policies and procedure that an underwriter looks at and says, hey, if you don't have this, you know, you know you're going to go to the bottom of the pile

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B84%
  • Speaker A16%

Most-used words

cyber82risk33privacy22insurance22market22property21different18policy17technology17large15coverage14sure14seen14data13started13back13

Episode notes

Summary In this milestone 100th episode of Chattinn Cyber , Marc Schein sits down with one of the most influential figures in cyber insurance, Bob Parisi. Widely regarded as a pioneer in the space, Parisi reflects on the origins of cyber insurance, tracing its roots back to the late 1990s during the dot-com boom and the early recognition that traditional insurance products were not equipped to handle emerging digital risks. Parisi shares a candid look at how cyber insurance evolved from a niche product designed for tech companies into a critical component of enterprise risk management. From the early days of privacy breach notification laws to the growing realization that business interruption and operational dependency on technology represent the true magnitude of cyber risk, the conversation highlights the key inflection points that shaped today’s market. The discussion also explores how the insurance industry has responded to ongoing complexity and volatility. From “silent cyber” to the challenges of aligning capacity across a fragmented marketplace, Parisi explains why cyber insurance still exhibits characteristics of an emerging market - even after decades of development.

Full transcript

53 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello cyber friends. This is Chatting Cyber and um, I'm your host, Marc Schein. This podcast focuses on how companies can help qualify and quantify the cost of a data breach. Chatting Cyber features some of the most well respected privacy and cyber experts in the world. Join the conversation with business leaders, government agencies and cyber experts to learn more about how and why they got into this ever changing field that we call cyber risk. Hello cyber colleagues. I'm Marc Shine, national co chair of the Cyber center of Excellence here at Marsh McLennan Agency. And today we have a true cyber celebrity, US, Bob Parisi. Bob, thank you for joining.

Speaker B: Mark, uh, it's a pleasure. Um, I'm a little annoyed you haven't invited me sooner.

Speaker A: Well, Bob, hey, listen, I wanted to save one of our top goats in the cyber insurance arena for our 100th episode. So thank you for all the support and some of the conversations that we've had to help get us here to this hundredth episode. So let's just dive right into it. Bob. Um, in my personal opinion, and I know the opinion of many others in the cyber insurance business, they call you the Goat, uh, for many different reasons. One, because I think you're one of the most sophisticated underwriters in the marketplace to date. Two, you also helped create the cyber insurance policy. But before we get to that, how did that all come to be? Did you always know you wanted to be a cyber underwriter? Did you know you wanted to create one of the more meaningful cyber products out there?

Speaker B: Yeah. Well, first, congratulations on 100, uh, 100 episodes. That's uh, that's amazing. Quite an accomplishment. And to answer your question, simply, absolutely not. Uh, you know, I, uh, you know, I describe myself as a failed, not a failed attorney, recovering attorney and a failed engineering student. So uh, so early on in my educational, uh, career, I flamed out on the stem side. Uh, but uh, yeah, so I, I started as basically, uh, an insurance attorney, a coverage attorney, doing claims work at a firm called Mendy's and Mount. That's been around close to a hundred years now. Um, uh, went in house at a, uh, small coverage attorney, a uh, small firm that was doing outside counsel work for Reliance. So you can imagine where that went.

Speaker A: Sure.

Speaker B: Uh, and then AIG picked me up, um, to basically be in house counselor, referred to as divisional council, really just doing uh, professional liability endorsements, manuscript policies when, when there still were professional liability groups. Everything wasn't called cyber back then. So, yeah, so I started, uh, as I like to call it, I'm the uh, I'M the underwriter from the last century, uh, but my career started decidedly outside of technology. It just kind of right place, right time, frankly.

Speaker A: Sure. So when you're thinking about kind of that creation of that first cyber product, was that something that, you know, you as an underwriter thought that the marketplace needed, or was it the clients coming to AIG and suggesting, hey, we have this exposure, how do we cover it?

Speaker B: Oh, it absolutely wasn't me. Uh, I was, uh, as I said, I was doing kind of, uh, chief underwriting, uh, work and divisional council work inside AIG's professional liability group. We had some technology policies. We had a policy called AI Link, uh, which actually mentioned insurance. But, uh, what really happened was, um, um, there was a change inside National Union. They decided at know, a level well above my pay grade that they wanted to focus on the dot com, uh, the E commerce. Right. Uh, everything in, you know, 99, 98 was, you know, we were gonna, the world was gonna change because of the Internet. Um, and what AIG did at the time was they started hiring a team that had some serious technology shops, uh, either straight tech, you know, um, doing ah, package policies for tech companies. And they started to put that group together inside aig, um, under a gentleman by the name of Phil Hoyt, uh, who came, I believe from Chubb at the time could uh, be wrong. Uh, and they sent me over there because most of these people that were, uh, most of these underwriters they were bringing over were not AIG folks. Right? They were coming from other companies. So I got sent over there to make sure they did it the AIG way. Uh, so it was, it was more kind of go make sure nothing, nothing, uh, weird happens with those Chubb folks we hired. Uh, and it was a great experience. I learned a lot. But that's, that's where that started. Uh, and um, came about that we started looking what are the, what are the exposures that dot com companies have that are different than traditional brick and mortar companies? So we really started to look at that. I would love to say I did the first policy, but, you know, can't claim that honor. Uh, we looked at a bunch of policies that were kicking around, including you know, the, that weird AI ah Link policy that was out there. Uh, and we tried to see what, uh, what would work for, uh, you know, the broadest reach of companies that were moving around at the time looking at this as something other than just a tech EO risk. Um, and that's what happened. We worked, uh, very closely with Marsh at the Time woman named Emily Freeman had was, I'd say one of the, if you wanted to talk about the OGs of uh, cyber insurance, she's right there. Peter Foster at um, now, uh, you know, now at Willis, then at Marshall, uh, brought something uh, a concept called Net Secure, which was probably I would describe as the first truly commercially scalable cyber policy. And then you had a rollout of uh, a variety of others including um, what AIG rolled out the time, which was a suite of products that were focused on uh, the cyber risk as well as doing a blended policy that encompassed a uh, variety of professional liability, including the tech, telecom, media stuff.

Speaker A: So Bob, that's interesting. You're kind of talking about the dot com era and when you speak to a lot of brokers now they talk about kind of the early days of Cyber was around 2015 to 2018. So can you tell us about how kind of the product has evolved from when you were working on in the dot com bubble to kind of the early mass, uh, adoption days, the 2015 to 2018 and, and then kind of what we're seeing in 2026 now.

Speaker B: Sure. Market. At the risk of kind of slipping into okay, boomer, uh, territory, you know, uh, we rolled the policy out in, I believe it was mid 99, uh did the normal insurance broker, you know, just road shows. Uh, and it had, it had a weird genesis in many ways. Uh, it was partly, let's try and ride the dot com bubble, let's see, seeing that as an underserved community in terms of buying insurance. But we also saw some weird kind of coverage decisions coming out. I mean at the time, uh, we saw the casualty market say that if you had a website, you were a broadcaster or a publisher, so you lost your advertising or in uh, advertising and um, privacy, uh, coverage. So you saw some holes starting to develop. I mean uh, that you've got a website, you're a publisher, uh, went away. But there were a bunch of things pushing it, um, including what we thought was a whole new type of company and uh, the coverage not being entirely fit for purpose on the property casualty side. Uh, as you said though, you know, I still love it when I hear people say, you know, cyber still, you know, it's not a mature coverage. You know, you and I've been doing it for almost 30 years now. Right. So it's, I'm not sure at what point it gets mature, but I think what you saw was a uh, recognition that the risk was always there, it wasn't always transparent. So the dot com bubble burst. And one of the things we saw, one of the metrics that we saw was a quadrupling of uh, the use of Internet and technology by brick and mortar companies. So you know, you, you had the risk, the risk was there and it was increasing. All that, all that great dot com technology, which now was going for cents on um, the dollar, was getting adopted by, you know, regular companies. So their technology risk was increasing dramatically and has continued to increase exponentially. Whether you call it AI or quantum computing. What, what really changed and what really kind of gave, you know, a shot of steroids into the cyber market was or came about, uh, I think roughly late, uh, 04. Um, yeah, late 04, early 05, when you started to see the uh, the advent of privacy breach notifications, uh, the very state laws and uh, for a While, probably almost 10 years, cyber became a privacy product. Right? It was all about, you know, sending out notice, providing credit, monitoring. It really was entirely focused on that privacy breach, um, type of risk. At the same time though, and this is one of the things I struggled with as a broker, uh, you know, when we were, you know, at Marsh, was getting people to recognize, yeah, privacy is a big issue. Um, it's not developing the way we thought. It didn't become the new epli. There wasn't. The litigation really wasn't coming. A lot of, lot of regulatory activity, a lot of breach response stuff. But what was, what was kind of the. And I view that as kind of the tip of the iceberg really. The biggest problem continued to be the, you know, the reliance and dependence upon technology. And that's what you started to see be recognized probably in 2015, that it, it wasn't um, responding to a state breach along with regards to lost credit cards. It was the business interruption. It was the value of those intangible assets, the software, the data. And I think that's where you started. If you kind of looked at, you know, some pivotal moments for cyber, it was, you know, you had the, the birth of it in late 99. You had the privacy breach notification. And then around, you know, let's say somewhere, somewhere between 2010 and 2015, you know, who knows, right? But in that time, uh, uh, that growing recognition and that final awareness that the business interruption piece was really the, you know, the monster that was, uh, we should be concerned about. And then when you think about it, you know, fast forward a couple of years after that silent cyber going, yeah, um, this is what's been underneath every risk that we have. We need to deal with it. Differently.

Speaker A: So you mentioned silent cyber. What is the marketplace doing with that in 2026?

Speaker B: Yeah, I, you know, it, it uh, I, it was real big for a while, wasn't it? Right. That was all we could talk about for, uh, it seems, it seems, you know, it seems like the cyber community locks in, uh, or the cyber insurance community locks in on a, on a phrase or a term, you know, you know, every cycle. Whether it was, you know, Iot that was big for a while. Now uh, it's AI and quantum computing for a while. I mean for I'd say a good, you know, two years, silent cyber became, um, you know, the thing we talked about, you know, the CZ code, if you're talking uh, to London underwriters. And really what it is, is it's saying that if you're going to give cyber coverage, you either got to do it expressly and reserve for it or you got to exclude it. What? Uh, as a practical matter that um, that really forced property and casualty markets to pull back, um, for a couple of reasons. One, they got hit with a couple of losses, uh, not pet you wanna cry was probably the biggest one, uh, that kind of rippled through the property market. Uh, but it really said, look, if you're gonna write cyber, you as a company need to put it in, in the cyber practice. Do it with an appropriate policy, do it with appropriate underwriting, with pricing and reserving. And what that's manifested itself today is several, uh, gap filler products, uh, or enhancements to a cyber product, usually around, uh, property damage, uh, a cyber event that causes property damage, a cyber event, uh, you know, that causes property damage, uh, from a liability or from a property perspective, um, we're seeing that coverage baked in on some forms, we're seeing it offer that as an enhancement or as a standalone coverage. So if you think about it as this enormous, you know, you know, canyon, you're, you're seeing the cyber market slowly bridge completely across to that, uh, you know that, that gap that was created when the property casualty market pulled back from offering cyber related risks.

Speaker A: So Bob, we've talked about silent cyber and IoT and we'll get into AI and quantum computing and later in the conversation. But when these new uh, uh, exposures or concerns come out, does it change capacity in the marketplace? Are carriers willing to offer less limits because they're perhaps more intimidated, or do they say, hey, you know, people are looking to buy higher limits, we can get higher rate. How does that typically work?

Speaker B: Yeah, I think, uh, I don't know, uh, I Think cyber continues to be, you know, um, there's some volatility and some chaos, uh, that seems to be baked into the cyber market. Right? And for, uh, a not insignificant number of years, it was one of the few products that was growing organically, uh, in the insurance world. So you had this real fear of missing out. That occurred in waves of new, uh, markets coming in, uh, you know, experienced players starting MGAs. So you had a real abundance of capacity. Uh, and for a time, uh, capacity far outstripped demand. And I think that's, that's lessened. I don't think there's a lot more capacity that's just wandering around out there wondering how to get an invite to the party. Um, but, uh, what we've got in many cases is an abundance of capacity, but an inability to align around a risk. And what I mean there is, there's got to be, you know, depending on who you talk to, there's, you know, you know, four or five dozen to a hundred different, uh, cyber insurers, fintechs, insuretechs, MGAs. Uh, but they're, you know, but they're chasing two different markets. Uh, right. There's, there's a whole ecosystem that is focused entirely on the SME M space. Uh, they have a very different approach. And then you've got the large risk space. There's more than enough capacity to probably get US to roughly 2 billion, but we can't get the market to align all on one risk. So what you're left with is in many cases large industrials viewing cyber as their biggest risk, um, in that direct loss context where they normally would buy a couple of billion, but they still can't get to more than say, you know, 7 to 800 million, um, out of the cyber market. So there's a lot of capacity out there. It's not layering up or it's not aggregating in the way we've seen it in, uh, in other areas. So, you know, in that respect, maybe we still are an immature market trying to figure out how to deal with it. The problem is, you know, of those, let's say, you know, 50 or 60 markets that are out there chasing it, each one of them is a slightly different form. Each one of them has a slightly different approach. Everyone thinks they've got the secret sauce as to how to do this, and you're left with, um, still, ah, a little bit of chaos. Much less so than we saw back in, uh, you know, 1999. I think there's an alignment around what the Risk is there's an alignment around aggregation issues, there's alignment around, you know, needing this to be sustainable. Uh, there's an alignment around, uh, underwriting discipline. But you've got a lot of different, a lot of different carriers or MGA's, um, chasing the same thing.

Speaker A: So, uh, just sticking on the kind of the bifurcation of the marketplace thinking in that mid market space and that kind of national or global account space. Do you think that there's certain, um, controls or activities or best practices that the middle market can learn from that large national account space? Or is that large national account space so sophisticated and have such a budget that it would never be able to be able to be deployed into the middle market?

Speaker B: Yeah, that's a great question. I, uh, think I flip it around and I would say we've seen probably the most innovation, uh, in the SME space. Um, we saw it move from being a simple risk transfer piece to being a risk transfer plus a significant value add in terms of the service offerings. Right. Uh, uh, you know, Beasley's breach response was an early innovator, uh, that said, look, small, medium company, we know you don't have the sophisticated hierarchy. So as part of the insurance we're going to give you all of this, uh, all of these services. This shiny red fire engine is going to appear when you have an event and that those service offerings. And I realize I'm giving a lot, a lot of other companies some call outs here, but I mean uh, hsb, uh, does something similar as does uh, the folks at uh, Municree Specialty and a lot of others. Um, they provide that service that small and medium companies don't have. Because if we're talking about the privacy piece, a lot of this is regulatory compliance. A lot of this is dealing with an event when you don't have or for small companies you don't have that hierarchy or those relationships to deal with it. So the carriers very cleverly thought, well, why don't we meet that need? Because at the same time controlling the claims, controlling the defense, controlling the forensics is also a way to control the cost and make this product more sustainable and profitable. That model doesn't always translate, uh, to uh, large risk. Small companies don't have a relationship, they don't have, they may not have a CISO. Um, when you migrate into that Fortune 500, Fortune 100, they've got a CISO, they've got relationships, they've got red, blue, purple teams, they have all of that. They're not looking for that value. Added. They're looking for that. Oh, my God, we've got a catastrophe. Help us basically protect our balance sheet kind of loss. So what we've seen is probably a little bit of a migration, uh, from the SME approach in terms of the large account model being better at creating and managing panels, uh, of forensics vendors and offering that as a, an assistance or a guidance to the large accounts. When they're saying, hey, we've got this relationship, do you have another relationship? Who have you used? Um, but they're two very different approaches. I mean, one is you get on a train in the SME space and you run down that rail. There are no changes you, you're told to use. That's not going to, uh, that's not going to fly with a Fortune 100 company that's taking, you know, a $50 million retention. They want a level, uh, of, uh, freedom. Um, so you've got kind of more of a curated claims approach, uh, as opposed to a very, uh, dictated claims, uh, approach.

Speaker A: I appreciate that. And Bob, I know we're just about coming up on time on our first session of the, uh, podcast, so I wanted to thank you for your time today. This, um, has been very informative and looking forward to part two.

Speaker B: Great. I've been enjoying it, Mark. Thank you. Great.

Speaker A: Okay. Uh, welcome back, uh, uh, chatting cyber colleagues, uh, Mark Schein, national co chair of the Cyber center of Excellence. And today we have the cyber insurance goat with us, Bob Parisi. Bob, really looking forward into getting into, uh, phase two of our conversation.

Speaker B: I, I'm looking forward to it too. I, uh, you know, I don't know whether I want goat or godfather of cyber Insurance. You know, uh, I, you know, I've had, I've had a lot of people rib me, uh, about that, but, uh, uh, uh, uh, let's just say I was, uh, uh, I was there right time, right place, back, uh, uh, you know, back in 99.

Speaker A: Fair enough, fair enough, fair enough. Always so humble. Um, so let's just dive into now some coverage considerations. So, you know, one of the common questions as a cyber broker, people come up to me and say, hey, can you write a standalone cyber policy? And I'll often say yes, but it's not in your best interest. You know, where do you see the cyber exposures really most material overlapping with traditional lines? You know, we spoke about silent cyber and property, whether it be business interruption or dependent business interruption. DNO, E&O crime. Are you still seeing the same overlaps within cyber and these other traditional lines? Of insurance.

Speaker B: You know, Mark, that's a great question. I think, uh, probably back, you know, from like 2000 to 2020, uh, or 2019. Let's kind of use Covid as the delineator. Uh, you continue to see some overlap. Silent, uh, cyber solved some of that, you know, if not most of it. I do think what, uh, and again, I sat, uh, I walked in your shoes for 15 years as a broker. My, my recommendation today, even when we talk to, uh, you know, our insureds, is that you don't want to look at cyber in isolation, cyber insurance in isolation. Um, the same way we, you know, I'm sure you talk to clients that cyber is not an alternative to good risk management. Cyber shouldn't be placed in isolation from other lines. Uh, and there it kind of moves from the obvious to the subtle. Um, if you're a company that needs, um, professional liability or, you know, coverage, it's always been kind of a truism that you probably shouldn't place the cyber and your E O, your tech, you know, your, you know, telecom, you know, separate from your cyber because the, the lawsuits, the breaches, something, whatever's going to happen is likely to happen in, in the context of your rendering that professional service. So the claim is going to be, you know, really tangled. It's going to be hard to unbake that cake. And that's probably the way the market has evolved, uh, in its most fulsome way, uh, in, in large part because pretty much came out of EO groups. Uh, when you talk about crime, um, when you talk about property and casualty, it's a different discussion. Um, you know, crime was often one of the biggie, the biggest confusing areas because just because it happened involving a computer didn't make it cyber. There's been computer crime out there for a long time. So we have seen the evolution of E crime, uh, and gap filling, uh, in the cyber policy. With regards to property and casualty, that's been a different experience. I think what cyber has done is if you look at the cyber grants, uh, they pretty much are property and casualty type grants. They're not really financial lines grants. Um, and what the cyber market has done is it has, um, slowly learned how to handle, uh, property and liability exposures that come about from a cyber event and make the cyber policy look and feel more like a property policy, more like a casualty policy. But for these, you know, these intangible perils, um, what we've probably seen is the biggest, not overlap, but gap has been what happens when you have a Property loss, a business interruption, a damage to physical assets that the cyber event is in that chain of causation may not be the proximate cause, but it's, you know, it's right there. And we've seen the property market pull back from that to some extent and we've seen the cyber market, you know, move into it either as offering a, you know, property damage enhancement to the, to the cyber policy, or in many cases, or in some cases a standalone gap filling product that's, that only deals with property damage from a cyber event. So I think we're seeing the market get better about meshing together those coverages. But you know, if you talk to a risk manager, they don't buy any of their coverages in isolation. They want to make sure they know how all of these could, um, you know, are providing the kind of, that blanket over the risk that they have. Uh, I don't know, but kind of the worst thing is to have two policies responding to the same risk in a different way and you know, ambiguity starts to creep in and that's, that's, that's a dirty word in insurance.

Speaker A: So let's change the, let's change the topic and uh, not to talk about dirty words. Um, so given the rapid evolution of, you know, applications, cloud architecture, APIs, IoT, all the buzzwords, has that actually changed the way that underwriters are contemplating writing the risks or is it just another buzzword and we'll have to deal with another new buzzword in another two years from now?

Speaker B: Well, I can guarantee we're going to have another new buzzword. Uh, you know, uh, in 2027. I have seen the underwriting start to change in some very positive ways in two different spaces. And again that kind of, that to market approach, you know, the SME space and the large risk space. When, when cyber started out you had a lot of folks who knew nothing about technology. So we reached out to third parties, uh, whether it was, you know, IBM or Unisys or Net Diligence or what have you to actually conduct the, you know, the audits or the assessments of the companies that were applying. Uh, you then had a migration or the evolution of self assessment. Uh, AIG had one, Marsh had one, Munich Re now has, I mean everybody's got their application, which is in many cases a self assessment. Whether you're using the NIST framework, whether you're using the ISO standards, doesn't really matter. Uh, it's still a bit of a pen and paper exercise. You then had the, well, we'd like to talk to your ciso. Uh, so the standard model became give us your submission, give us the assessment, answers, and we're going to have a discussion with your cisa, your Chief Privacy Officer. And that served us pretty well for probably almost 20 years. Right. Uh, um, you saw the advent of the outside in scans, kind of the drive by, uh, security analysis that stayed outside the perimeter. The, that was helpful. A, uh, couple of companies do that, still do that. Well, I, uh, think what you saw was two developments, um, in the SME space. You saw the push of technology. Hey, we looked at your company, we got the submission. We don't think you've got great mfa, uh, or we don't think you've got this or that, and we're going to give you this, that technology and that's a requirement for us to insure you. So pushing, pushing risk tools, uh, technology tools onto the company. And several, several insurers have actually developed infosec vendors, um, as part of their, their offering on the large risk space. What you had was now looking, trying to find a way to get inside out data, um, you know, uh, being able to look at how things are configured in the cloud, getting something other than a subjective statement from the insured, getting really an objective, an objective look at, you know, how they're actually doing things. So I think those two, those two evolutions, uh, and they're starting to kind of mix uh, into uh, you know, you've got some large risk companies that are saying, well, why don't you look at this technology, we can help you with that. And you've got the SME space saying, hey, we'd certainly like to be able to look at uh, that inside the firewall, um, information. I think that evolution of better information is going to help us be more transparent in the underwriting and hopefully also uh, provide a, make the policies and the coverage more sustainable as we get to better understand where the risks are occurring and, and what are the, you know, what are the levers that you can push to make a company a better risk and more resilient? Uh, you know, it's one thing to say you're hard and crunchy and you've got that deep moat and that high wall, but uh, if the barbarians storm the gates, you know, everybody loses. It's, it's how you manage through that crisis. And I think that's where the cyber insurance world is leaning in many cases is how can we evaluate how resilient, uh, how, what's the word I'm looking for? How Are they able to deal and work through that crisis? Because what we've seen is a very real one to one relationship. Companies that aren't able to deal with that crisis are the ones that lose the most money. Sure, you know, uh, have the most expense and frankly cost the insurance world the most cash.

Speaker A: You know, Marsh, we have our, the, the top 12 controls that we typically focus in on. But from an underwriting perspective, is there any one control or any one policies and procedure that an underwriter looks at and says, hey, if you don't have this, you know, you know you're going to go to the bottom of the pile or contradictory. If you have this, you're going to go to the top of the pile.

Speaker B: Yeah, I, I've, uh, I, I've heard so many people, uh, you know, you know, just, you know, basically set out the hill they want to die on, uh, from whether it's multi factor authentication, whether it's endpoint protection, I, I can't even begin to guess uh, what it is. I mean at Municry, we actually look at things from the point of view of where are they against the ISO standard. Right. That's, that's one way that we look at it. Um, you know, you can, you can also look at it from a DNO perspective, management liability perspective. You know, have you got a ciso, have you got a Chief Privacy Officer? Do they report inside up into the board and you start looking at, uh, what's their level of governance? Because frankly, if you don't have that kind of, that digital DNA, uh, if you can't tie it up with that kind of digital shoelace, uh, it's, it's not there. So it's got to be. I, uh, would say when we're looking at it from an underwriting perspective, if we don't see that, that, that approach to security, to privacy, to, to resilience isn't part of the company's mode of operation. From the CISO down to, you know, the loading dock, that's the biggest red flag. It's when you start seeing silos in a company that aren't talking to each other. Big, uh, red flag. When I was, you know, again, uh, you know, on your side of the house. Broken. If I was introducing the Chief Privacy Officer to the ciso, uh, before we were going in to craft the submission for the carrier, I knew I was going to have a problem because the stakeholders are not talking to each other.

Speaker A: Sure, sure. Um, pivot to something, I guess, a little bit more sensitive. Um, given that we're Q2, 20, 26, uh, and everything going on from a geopolitical perspective, um, and you're starting to see the rise in state sponsored cyber activity and just kind of geopolitical conflicts. Is it, do you believe that it's going to start to reshape policy wording, thinking about things like exclusions or reinsurance appetites, um, anything that you can say either on a personal level or, or what Munich stance is understanding this is a very sensitive topic.

Speaker B: Yeah, well, thanks for having me Mark. Uh, you know, it's been great talking. No, uh, uh, the, I, I, I think, you know, I think let's, let's kind of level set, uh, you know, in the, you know, in the nearly 30 years that the cyber policy has been around, it's my understanding from what I know, talking to other carriers, other brokers, there's never been an event, uh, that's been excluded under the old war exclusion, the new war exclusions. Now I'm not Talking about the WannaCry, not Petcha, where the property casualty market excluded it because in that case you had companies that were excluding it. But it was because they, it wasn't the cyber markets. The cyber markets were pain. So whether it was North Korea, whether it was, you know, Russia, whoever, uh, we've seen those nation states engage themselves in things that have rippled into the cyber insurance market. None of them have been excluded for that reason. Um, there is a very, it's a very interesting discussion that's been going on for the last couple of years around, uh, around how to deal with war, uh, and you know, how to come up with a fit for purpose war exclusion. I don't think that anyone, at least when I talk to, you know, my old clients, none of the risk managers I've spoken to think that war is covered. The question is what, what is war in 2026? Right. You know, the war exclusion's been, you know, uh, you know, the first one came about after World War I. It then got changed after World War II to reflect the Cold War. We then had the Lockerbie piece. So you then had to change it again to reflect the, you know, the terrorism has crept into, into our world in a, in an unfortunate way. So you've seen it change at least three times. The looking at what is war in the, you know, in the 21st century has resulted in a large number of war exclusions. Um, I think at the end of the day their push comes to shove, no one thinks war is covered. The question is how do you define war in a cyber in a cyber world. And that's really the hardest part. I would look at it more from a very much more basic approach. Right. Uh, if the event occurs, it triggers the coverage. It's then up to the carrier. Uh, if they want to exclude it, it's our duty or our obligation to prove that the exclusion applies. And I think you're looking at situations that are, you're seeing in cyber all the time. It's, how do you attribute an event to an actor? And, and that's always going to be challenging. Uh, so, uh, you know, it's that Chinese curse. May you live in interesting times, uh, is what it is. Uh, you know, you've got a, you know, every carrier seems to have their own approach to how they're going to handle war and civil unrest, uh, and how that, uh, how that wording has evolved. I think at the end of the day, there is a consensus that people, no one thinks that war is covered, and no one has an expectation that war is going to be covered. The devil's in the details as to how we come up with the definition of war and how, how the facts and circumstances of the first event that gets litigated plays out. So I, I, this short answer is, I don't know. Uh, I know Munich Re has taken a very strong and clear position that we're not going to cover war, and we're going to be very express and clear about it. And I think, you know, that's the right way, uh, to do it. Uh, you know, being, being kind of cagey or not being clear about what your intent is, I don't think helps anyone.

Speaker A: I would agree with you. Um, I guess the other kind of piece that's really kind of changing over the last, we'll call it 12 to 24 months, is really the privacy developments globally. And how is that starting to now impact underwriting, if at all?

Speaker B: Yeah, Mark, you know what? I never enjoyed the privacy wave. Uh, it wasn't as much fun as other stuff. So I thought once we got everyone talking about business interruption, uh, talking about crisis management, I thought we were done with privacy for a while. When we didn't see the litigation, um, arise the way we thought it was going to be from all the breach notifications and things like that, uh, and we got people thinking about this is an operational risk. Let's talk about it from that perspective. And then all of a sudden, biometrics comes in, right, and just changes, changes. Uh, the approach. The, uh, pixel litigation that we're seeing, the fact that the plaintiff's Bar has now tried to take kind of, uh, regulations from the 70s and apply it to the way that data is handled today. Uh, I heard a great phrase a while ago, called the prospective plaintiff. I'm like, wait a second. Don't you at least have to have someone who's actually been harmed? You know, prospective plaintiff sounds like, yeah, we'll go and find someone. Right? But I. I think privacy has now been infused, at least in North America, with a lot of the concepts that we saw develop in Europe. Uh, it's not just about. It's not just about the breach. It's about the handling. Right. Uh, a. You know, it helps me to understand things by using analogies. And if you think about it, for the longest time, the US And North American privacy laws were about, someone spilled some milk, how do we punish them? Uh, and then you saw, you know, GDPR in the EU and that wasn't about punishing someone if the milk spilled. It was, how do you. How do you keep the milk from spoiling? Where did he store the milk? It was much more about the managing of the data as opposed to reacting when the data got lost or, uh, exfiltrated. And you're seeing that. You're also seeing, um, a conflicting approach to how people view privacy, uh, in terms of just challenging business models, whether it's a large business, whether they're data brokers looking at that. It's like, uh, you know, that's changed the way folks have looked at the risk, and it's changed the way we started to see litigation around privacy. Biometrics is out there, but people are now challenging the fact that, well, you're handling data in a different way, in many ways to make the experience for the client better. But it also means you're giving up a certain level of privacy around your data. Right. If. If. You know, what's the. If. If you're not, you know, if you're not paying for the product, you are the product. Right. So, uh, they're challenging the business models of large companies that are mining data to better operate their business because that means that they are looking at more data. Uh, uh, I'm not saying it well, but I think you get the sense of.

Speaker A: Understand where you're going.

Speaker B: No, uh, you know, if you think about it, you've probably experienced it in your own life. I know I have. The ads I get are not as random as they used to be. Uh, so someone is figuring out someone in the back. Someone behind my. Yeah, my m. Computer screen is looking at my searches and going, all right, he likes hiking, he likes rowing, he likes watching, you know, Marvel movies. And I'm getting, you know, I'm getting ads for alpaca wool socks. I'm getting, you know, I get things that are very specific to my interest, whereas before it was just a haphazard scattergun. So that data mining and that's, that is causing a lot of privacy, uh, privacy advocates, concerns as to what's going on behind the scene, what is being done with all that data. And that's where you're starting to see, uh, additional litigation.

Speaker A: So let's pivot to perhaps the most common phrase, or most used phrase, uh, in 2026 is AI. And my question to you, Bob, is really, how is the market viewing AI risk today? There is no real state, or rather I shouldn't say, is there, you know, is there a certain product that people need, um, when they're engaging in AI? And then how are underwriters really just kind of thinking about it? Is there going to be additional applications or is it just going to be covered? What's your thought process?

Speaker B: Yeah, so if you think about it, this. Let's kind of look at it from the most basic. Because that's my strength. Right. I'll start at the simplest. Uh, AI is technology, um, you know, plain and simple. Uh, so to the extent that AI causes a covered peril under cyber policy, you know, uh, you know, I don't see that as any different than any other technology, uh, causing. Now, AI does have a lot of, you know, it's got a lot of differences from other technologies, but it's a technology. The issues start to come in when you look at the novel risks that AI causes, uh, and we've seen those largely come around, um, or arise out of intellectual property issues. Uh, whose information are you training your large language model on? So that's a very simplistic way to look at it. Um, as far as how the insurance community has dealt with it. I've seen endorsements that deal with covering the intellectual property piece. Um, you know, uh, I've seen coverage that deals with ensuring or warranting the output of the AI, the AI model. Um, so it's, it's kind of all over the map. I think what we're seeing is at the same time the insurance world is looking to understand it. So too is the CISO and CIO communities are looking to understand it. And there are a lot of bright folks out there looking to come up with standards and approaches at a, at a very basic level, um, as an underwriter. I, I kind of bucket, you know, it into three, you know, three buckets. Um, you know, two are red flags. One is. Okay, let's talk. Uh, the, the folks that are fanboying over AI and can't wait to deploy it everywhere they possibly can, can in their organization, they scare me. Uh, the folks that say they are not using any AI, they will never use it. They hate it. It's the most horrible thing in the world. Another red flag, because you know what? It's happening in your organization. You can deny it and say you don't want to do it, but it's there, and you're ignoring it at your peril. I think staying in that middle lane of companies that are talking about, look, we're deploying it. Uh, we're looking at it. Uh, we recognize that, um, really raises the level of. Of threat actors, right? Because all of a sudden, you know, they can use the AI changes their ability to, uh, make things seem more natural. The, the vishing things. Uh, you know, the language is not as stilted as you would get in some of those social media or those media attacks. Uh, but at the same time, it's a tool that the CSOs and the companies can use to better defend against it. So I think it's a new technology. My biggest concern, or the thing that causes me to, uh, kind of be concerned about it, is not it in and of itself. It's the speed of the adoption. And, uh, I'll kind of put it in context. When Gutenberg came out with the printing press, it was probably about, you know, 100 years before, you know, society said, all right, this isn't the tool of Satan. Uh, printed books are not a bad thing. Um, we're good. Way to go, Gutenberg. Um, but that's. That's a century, you know, certainly several decades. AI is evolving and being adopted in real time, if not faster than real time, if that's possible. So you've got a different way of. It's just a different nature of the risk. I'm. I'm the wrong. I mean, again, I'm not gonna figure out, uh, you know, what AI is. Uh, uh, all I can say is that, uh. And, you know, I, I've. I've used this analysis. If south park makes fun of it, I think we'll be okay. And they've got an episode where they made fun of AI, they've made fun of NFTs and NFPs, so I think we'll be okay. Uh, but that doesn't Mean, we should ignore it. You know, if you want. The closest analogy is probably Y2K, right? Everyone thought the world was going to end because we didn't have the ability to go to 2000 in the software. Well, everyone recognized that. They jumped on it and they, you know, they looked at how to solve the problem. I, I think, you know, same thing with cloud. There was a lot of people rushing into the cloud early on because it was one, it was cheap and it just was cool to do. But you also had the folks who were saying, look, let's, let's make sure it's fit for purpose. Let's bring it into our environment in the way we bring all novel and new things in, and let's manage it and make sure we've got the governance around it. So that's my hope, uh, that AI transitions into the technology universe or spectrum that we deal with, uh, under cyber risk, and next year we worry about something else.

Speaker A: So. So, Bob, we've spoken about a wide range of, uh, concerns, issues, how the insurance industry is addressing them, best practices for clients, brokers, insurers, so on and so forth. Uh, when I was practicing for this podcast, one of the dying questions that I had is, I'm not sure if you remember, uh, you invited me into your office about 10 years ago, uh, for an interview. And during that interview, I was so locked in on you, but I kept looking to the left of your whiteboard and I happened to see a Pokemon card facing the whiteboard. So 10 years later, Bob, which Pokemon was it in the office? And is there any significance behind it?

Speaker B: Yeah, the only significance behind it was, I believe my son brought it, uh, along, uh, on bring your kid to work day.

Speaker A: Okay.

Speaker B: And it was a Japanese language card for Snorlax.

Speaker A: There you go. All right. Ten years later, uh, the burning desire.

Speaker B: Uh, yeah, now you have to. I, I used to have it on my desk, but, you know, once we all went remote, uh, after Covid. Yeah, uh, I lost all of my tchotchke.

Speaker A: Fair enough. So, Bob, before I let you go, is there anything that I should have asked you that I didn't get to ask you?

Speaker B: No, you know, uh, well, other than, you know, hey, Bob, when can you come back? Uh, you know, uh, but, uh, no, you know, Mark, this has been great. Uh, I've, I've enjoyed watching, uh, the nine years that you've been doing this. Uh, you know, I wish you another nine years doing it. I don't know if I'll be around for another nine years to come back, but, uh, this has been great. Thank you for having me, and best of luck, uh, in keeping this, uh, keeping this going.

Speaker A: Thank you very much. And we look forward to having you back on a few trips.

Speaker B: Sa.

More from Chattinn Cyber

All episodes →
  • Beyond Passwords: Passkeys, AI & Identity with Ben Wilcox
  • Bridging the Cybersecurity Gap: Leadership, AI, and Real-World Strategies for 2026
  • Bridging Cybersecurity and Economic Strategy: Insights from Cyber Policy Pioneer Alex Niejelow
  • Context is King: Tailoring Cybersecurity with Courtney Hans
  • Unveiling the Dark Web: Cyber Threat Intelligence and Forensics with Alyssa Lisiewski
Explore the best B2B Ops podcasts →
All Chattinn Cyber episodes →