The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Finance/Insurance Tomorrow
Insurance Tomorrow artwork

Cybersecurity: managing threats & breaches

Insurance Tomorrow · 2026-06-11 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

50 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality11 / 20
Guest Caliber13 / 20
Specificity & Evidence8 / 20
Conversational Craft8 / 20

Cyber risk has dominated the Allianz Risk Barometer's top five for five consecutive years, a reality shaped by increasingly complex, integrated IT systems and the expanding digital supply chain. Jack Wright emphasizes that businesses operate like sprawling cities requiring proper asset management and third-party risk oversight, while John Choi describes how CyberCube's risk models move beyond historical data to factor in specific vulnerabilities detected through outside-in scanning - the same reconnaissance approach attackers use. The conversation highlights persistent gaps: multifactor authentication and patching remain inconsistently deployed despite their critical importance, and small-to-medium businesses particularly struggle due to resource constraints and over-reliance on outsourced IT providers without proper integration into business strategy. Regulatory pressure is mounting via the FCA's operational resilience requirements and the PRA's CBES cybersecurity exercises, while new AI-related coverages and liability questions emerge. Brokers and their clients benefit from well-rehearsed, simple incident response playbooks informed by public standards rather than complex threat-specific plans, though phishing, ransomware, and business interruption remain top concerns. Quantum computing, by contrast, poses minimal near-term risk despite its long-term encryption implications.

Key takeaways

  • →Multifactor authentication and timely patching are the most consistently overlooked controls despite being fundamental to preventing breaches across organizations of all sizes.
  • →Businesses must understand their critical assets and third-party dependencies - treating cyber resilience as a business continuity issue, not just an IT problem requiring technical solutions alone.
  • →CyberCube's outside-in scanning approach mirrors threat actor reconnaissance, allowing insurers to identify specific vulnerabilities (open ports, end-of-life products, missing MFA) and refine underwriting models accordingly.
  • →The FCA's operational resilience mandate and PRA's CBES exercises require organizations to demonstrate controls are in place and customers remain protected, not merely that controls exist.
  • →Quantum computing remains 10-20 years away from practical deployment; the near-term priority is managing current encryption and cryptographic systems for regulated data retention.

Guests

Jack WrightJohn Choi

Topics in this episode

Business continuity planningRansomwaresupply chain attacksMultifactor authentication (MFA)Allianz Risk BarometerFAIR Institute risk frameworkoutside-in scanningCyberCube cyber risk analyticsFinancial Conduct Authority (FCA) operational resilienceCybersecurity and Resilience Bill

Questions this episode answers

Why has cyber risk remained the top global business concern for five consecutive years?

IT systems are increasingly complex and integrated across domestic and international supply chains, leaving organizations running leaner with less resilience between each connection; AI and new applications compound this daily, making impacts anywhere in the business ripple across the entire operation.

What are the most common security failures that lead to breaches?

Multifactor authentication is inconsistently deployed despite widespread availability, patching is done infrequently (quarterly or monthly instead of immediately after release), and phishing remains highly effective because almost no control prevents social engineering attacks on employees.

How do CyberCube's risk models differ from traditional actuarial cyber insurance approaches?

CyberCube uses the FAIR Institute framework to assess probability and magnitude of attacks based on specific vulnerabilities detected through outside-in scanning (software vulnerabilities, open ports, missing authentication controls), rather than relying solely on historical incident data from similar companies.

What are the main regulatory pressures impacting cyber insurance?

The FCA requires demonstration of operational resilience (not just technological restoration but customer access continuity), and the PRA's CBES program conducts simulated hacker attacks; the Cybersecurity and Resilience Bill expands scope to treat digital infrastructure as critical infrastructure.

What security controls are insurers now expecting as minimum standards?

Identity and access management with multifactor authentication, network segmentation to limit lateral movement, phishing awareness campaigns, and verified data recovery/backup systems that can be deployed quickly during an incident.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode contains a handful of genuinely useful observations - particularly around AI agent identity proliferation and the nation-state asymmetry in deploying advanced cyber tools - but these are diluted by repeated, formulaic advice on MFA, patching, and phishing across multiple speakers and segments. The insight-to-filler ratio is adequate but far from dense for a 29-minute runtime.

give it five years and you've got your engineering team who are spinning off 50, 100 agents in an hour. Now you need to be tracking all of those because you are accountable for what those AI agents are doing
most skilled adversaries are not wasting them on you. They are going to dedicate those to the most critical target

Originality

11 / 20

There are two genuinely counterintuitive arguments - that nation states deliberately hold back their best cyber tools rather than deploying them broadly, and that quantum computing may become the 'next nuclear fusion' perpetually 10-20 years away - but the majority of the episode recycles standard cyber hygiene frameworks that circulate widely in any insurance or infosec context.

Nation states, like you mentioned before, they are, in any intelligence circle, they often protect the asset more than they will utilize it
does this become the next nuclear fusion? This is always going to be 10 to 20 years away

Guest Caliber

13 / 20

Both guests hold genuinely relevant practitioner roles - Jack Wright leads cyber resilience at a major insurer and John Choi brings an actuarial and risk-modelling background at a specialist cyber analytics firm - and they speak from operational experience rather than generic thought leadership. Neither is C-suite and neither has built or scaled something at an unusually distinguished level, which caps the score.

I'm an actuary by background, and so what we typically do as actuaries is look at historical experience and use that to project into the future
We have a global threat intel team, well several actually, based in many different countries and we all share information together

Specificity & Evidence

8 / 20

The episode references a handful of named frameworks and regulatory bodies (FAIR Institute, FCA, PRA, CBES, Cybersecurity and Resilience Bill) and the Allianz Risk Barometer ranking, but actively avoids naming breach victims or clients and supplies no dollar figures, loss rates, or concrete case study outcomes - the actuarial modelling discussion gestures at a methodology without any illustrative numbers.

take a large auto manufacturer in the UK. I won't name who, but we would take those sort of groups and project their experience into the future
we've seen reports from Anthropic regarding vibe hacking

Conversational Craft

8 / 20

The host covers the topic breadth competently and the questions are topically sequenced, but they are almost entirely agenda-driven rather than probing - there is no meaningful pushback on any claim, no follow-up that challenges a vague assertion, and the weakest moment ('Agree with that, John?') illustrates a recurring tendency to invite endorsement rather than friction.

Agree with that, John?
Jack, I want to focus more on supply chain attacks. How should businesses and brokers be responding here?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cyber24insurance19quantum17businesses16cybersecurity14jack14systems14risk13access11john10software10brokers9small9seeing9controls9computing9

Episode notes

How can businesses best defend their networks and day-to-day operations as cyber threats evolve and hackers make greater use of AI? Cybersecurity concerns topped the 15th annual Allianz Risk Barometer in 2026, making this an increasingly urgent issue for businesses everywhere. Our host, financial broadcaster and journalist Georgie Frost, is joined by Jack Wright, Head of Cyber Resilience at Allianz UK, and Jon Choi, Director of Insurance Risk Consulting at CyberCube, a global provider of cyber risk analytics software. In this episode, we discuss: How the digital threat landscape is changing and what it means for brokers Data breach incident response, vulnerability detection and network security Cyber risk assessment, access management and AI-powered threats facing the insurance industry Protecting a business's digital 'crown jewels' How much of a security danger is quantum cloud computing? Follow the series for notifications about future episodes. You can watch the podcast on Spotify and YouTube | Want to help shape our future episodes? Share your ideas, thoughts and comments here |

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

WEBVTT - Cybersecurity: managing threats & breaches Hello, I'm Georgie Frost. Welcome to another episode of Insurance Tomorrow, brought to you by Allianz. In this series, we'll explore the technologies, risks and trends impacting the future of the insurance industry. If you have any comments or new topics to suggest, please do get in touch via the link in the show notes.

Now, one area insurance professionals are increasingly focused on is cybersecurity. In fact, cyber incidents came top in the 15th annual Allianz risk barometer this year, just two places ahead of concerns over business interruption. If you're struggling to maintain your identity right now, give it five years and you've got your engineering team who are spinning off 50, 100 agents in an hour. Now you need to be tracking all of those because you are accountable for what those AI agents are doing.

Having multifactor authentication, making sure that the most valuable assets are properly securitized, these are the sorts of things that I think the insurance industry, insurance brokers really need to educate the insurance buyers on. What are the actual cyber risks that they face? To explore how the digital threat landscape is changing and what it means for brokers, I'm joined by Jack Wright, Head of Cyber Resilience at Allianz UK, and John Choi, Director of Insurance Risk Consulting at CyberCube, a global provider of cyber risk analytics software.

This is a topic we've returned to over the years on Insurance Tomorrow, as businesses around the world grappled with data breaches, phishing attacks, and ransomware dangers. By far the most significant threat, certainly to small businesses, will come from cyber criminals who are motivated by financial gain of what money they can get out of attacking you. And by far, the majority of these kind of attacks come in the form of untargeted, non- sophisticated attacks. Examples of that is phishing emails, which we're all familiar with.

These are very cheap for these criminal gangs to launch. They don't have to spend a lot of time targeting you. They will just send hundreds of thousands of such emails out and if anybody falls victim, that's a bonus for them. So you can't really think that as a small business, no one's targeting you, because they are.

And we just heard there from a national cybersecurity center officer from our 2018 episode focused on this topic, who remained anonymous to protect his identity. Jack, John, welcome. Jack, cyber risk has been the number one global business concern in the Allianz risk barometer for five consecutive years. Why does it continue to dominate, do you think?

The reason it's so large is that more than ever our IT systems are incredibly complex and integrated. Before, businesses used to be stood up and they would just be almost predominantly physical things. They existed, you saw the machinery, it was very clear. Your supply chain was a literal chain; you could probably link the businesses together.

Now we are more complex than ever. We are tied to businesses internationally, domestically, and because those businesses are only becoming more complicated, they're run thinner and thinner. So there's much less resilience in between each organization. You don't need to look at the advance of AI to see how well- connected and how many new systems, more applications that we're adding on day after day.

And when you have that, an impact in any part of the business is going to cause you huge amounts of problem. So cyber is only going to go on the rise. It stays at the top five because we're just seeing such a huge surge in incidents. And I suspect with AI, that's only going to be on the increase.

I presume that's something that resonates with you, John. Yeah, absolutely. That's no surprise at all. If we think back to the earlier episode you mentioned, that was a very prescient prediction in terms of cybersecurity being on the top of mind, increasing cyber attacks.

So with AI on the horizon here, we're only going to see more and more digitalization, more and more use and implementation of these technologies. In terms of the digital supply chain, we're also seeing this within the software sphere, too. And so when you think about software development, it's not just that one company is developing their entire software from top to bottom; they're relying on software packages that are from other open source providers, the community developed types of open software packages as part of a corporate software package.

And so this digital supply chain is becoming much more of a web rather than a chain. Jack, as I mentioned before, this is a topic that we've been revisiting on the show over the years, and not a surprise, it's such a big topic. But what emerging threats to brokers and their clients need to be focused on today? So I think take exactly what John just mentioned there.

You have a web, and what people need to think about is beyond themselves right now. So a lot of, especially small and medium businesses, they focus on how their business operates and they're not really tracking, think of a third party risk management, " How are my suppliers? How are my brokers? And more importantly, how are my customers being affected by these sorts of incidents?"

So what sorts of things can people do today? They need to pay attention to what their assets are. So imagine that you're a sprawling city and you're growing day- by- day. You need to understand where your roads are.

You need to understand where your houses are. And if you don't do it now, it's going to be much harder to regain down the line. So simple steps like really good asset management, what devices do I have? How do I interact with them?

That is a brilliant first step. And actually people sometimes get so focused on the exciting stuff, the Gartner Hype Cycle, stuff that's coming down the road, they forget actually the foundations keep needing to be built, and sometimes people lose sight of that. What are you seeing on your networks, John? So what we're starting to see here is really more focus on exactly these types of controls, what technology dependency is going to lead to, what AI is going to lead to.

It's not going to make cybersecurity controls obsolete. If anything, it's going to make the basics that much more, or not having the basics, I should say, that much more punishable. So it's like getting into a car without wearing your seatbelt. It's just things like this: having multifactor authentication, making sure that the most valuable assets are properly securitized.

These are the sorts of things that I think the insurance industry, insurance brokers, really need to educate the insurance buyers on. What are the actual cyber risks that they face? How much could it cost them in terms of business interruption, in terms of downtime, as well as potentially some of the reputational risks that you might face if you have an IT security incident? Jack, I want to focus more on supply chain attacks.

How should businesses and brokers be responding here? What brokers really need to do is just understand, well, what communal systems are there? So oftentimes there are applications that are common amongst most brokers, they all use it. And what you want to understand is, how can I remain competitive if these breaches are inevitably going to occur?

So if your default response within your business continuity plan is simply, " Oh, well, the system will always be fine." Or, " Don't worry, I've outsourced my IT and they'll just recover it," you've got to assume that those technical processes aren't going to work. And that's where actually we're seeing this really good connection now between drawing together your business continuity program into your IT service continuity and your cyber response, and you're drawing these all together.

And that's a particular challenge for smaller companies because they're such specialist areas that actually you need to dedicate some real time to understanding what are those critical assets that we mentioned before and then how am I going to protect it? And realizing you don't just have to protect IT assets, first and foremost you're actually protecting the business. So how do I keep serving the customers? And that might be, I employ 10 people for the next three weeks picking up the phone and dialing.

And oftentimes people aren't thinking of those manual methods. They're so stuck in the, " I need another tech solution." What are the big mistakes that you are seeing organizations make time and again? So we have a global threat intel team, well several actually, based in many different countries and we all share information together.

And one of the things that we see is that whether it's in the UK, whether it's in the US or anywhere, it is really those fundamentals that are being missed time and time again. So it is annoyingly the basics. Think of like multifactor authentication. We sort of understand it.

We see it in all of our systems, day in day out, we're on our phone, and yet there are so many important business processes that just don't have it. We see people's business emails get compromised all the time, and businesses just aren't preparing for it because they think, " Well, I've never had a breach before." And it is a bit frustrating. I've got to go get my little code and I've got to type it in.

It's a little bit of a burden, but if you lost your business because of it, that burden would be nothing. So MFA is a huge one. Patching, so making sure your systems are up to date. So companies put a lot of effort and time into making sure that their systems are as protected as possible.

For every AI scare story about people trying to use it maliciously, there are all these companies that are using it to scan their networks and to make themselves more protected. They push out patches so that they're as safe and as secure as possible. And when people decide that they're not going to patch it, or they're going to patch it, but they do it quarterly, the problem is that malicious actors, as soon as a patch comes out, they identify, " Well, what's the gap between the two?"

And then they can retroactively work out, " Well, actually here's the gap." So anyone who doesn't have the version 18, well, now they're vulnerable. And if you've decided, " Well, I'll just do it on a quality basis. I'll just do it monthly," that's the problem.

Well, the advantage of AI is that now tools are scanning constantly and you need to be on it so that you can say, " Right, this patch came out yesterday. What's our plan?" And little things like that are causing breaches day in, day out. And finally, obviously phishing.

No matter how good your security controls are, if somebody calls up pretending to be your IT help desk or pretend to be a member of your security team and they say, " Would you like to tell me your password or give me access?" Almost no control is going to prevent that. I want to talk to you, John, if that's all right, about your risk models. How are you reflecting these trends in your models?

So I'm an actuary by background, and so what we typically do as actuaries is look at historical experience and use that to project into the future. So take, for instance, we'll look at cyber incident history, lost history of otherwise similar- looking companies, take a large auto manufacturer in the UK. I won't name who, but we would take those sort of groups and project their experience into the future. That's your traditional actuarial or insurance approach, so to speak.

What we're seeing more and more from cybersecurity and a pricing solution is models like The FAIR Institute taking a look at what is the probability of companies suffering a cyber attack from the onset. And if they were to get hit by a cyber attack, what is the potential magnitude of those cyber attacks? Based on the specific cyber resiliencies that those companies have in place, the controls, the governance, how does that then adjust their risk posture in terms of the probability of an attack and the magnitude of attack?

What we're more and more looking at these days is what are the specific vulnerabilities that companies have on their networks? Are there specific software vulnerabilities or end- of- life products that they're using that are no longer supported? Do they have various open ports for different services that hackers could use to get into their networks? Do they have things like multifactor authentication or other authentication software on their networks?

And this is information that you can get with what we call outside- in scanning. So it's very similar to if we think about property underwriting, for instance, you send a risk engineer to survey the building, you can use data to see how close the building is to the nearest flood zone or the nearest fire station, what have you. Very similar concept here from a cybersecurity perspective where you can scan companies' networks, their websites, their IP addresses, to get a sense as to what types of vulnerabilities they might have.

And this is the same approach that threat actors are going to use to do their initial reconnaissance. And we're now factoring that into the risk models to get a better and more refined understanding of the potential incidents that a company could suffer from a cyber perspective. Jack, let's take a look at regulation. What cyber- related regulation is on the horizon that we need to be aware about?

So the two main regulators that you want to think about, you've got the Financial Conduct Authority and their concern is about operational resilience. And like we mentioned before, it's about not just thinking about how can you restore your technological system, but it's about how does the customer keep getting access to it. And in insurance, that's particularly important because you can imagine that we ensure all sorts of critical functions. The authority's purpose there is to make sure that resilience isn't just having some controls.

Yes, you've got some cybersecurity controls, you've gone up to a partner that's really valuable, that's good, but actually you need to be able to demonstrate that those controls are in place. So the regulator is tightening up there and expecting people to be able to demonstrate that they can protect customers. And then you've got the Prudential Regulatory Authority, the PRA, and well it's called CBES, but it's offensive cybersecurity exercising. So simulated hackers targeting your systems, and we're seeing the Cybersecurity and Resilience Bill, and in it, what they're doing is they're expanding the existing scope of powers.

So right now, think about infrastructure, we think about water plants and we think about electricity. They're saying now that actually our digital infrastructure is just as critical and they're including those digital elements into that. So that's going to give an expanded scope to the regulators and it also increases the reporting of responsibility on organizations. John, what about new areas of liability, particularly with increased reliance on AI for decision making?

Yeah, it's really interesting, and it's one that's an active discussion in the market right now. I think there are questions around, does AI sit within existing lines of businesses? Does it sit wholly within the cyber insurance line of business or is there going to be new AI insurance product? What are the kind of coverages that we're seeing, especially with AI and cybersecurity risks?

Well, the classic ones that we've already talked about, business interruption, of course, one of the top ones on the Allianz Risk Barometer. Unsurprising because this is really, especially for small businesses, their livelihoods. If the business shuts down for a period of time due to a cyber attack, there is a possibility that they have to shutter, unfortunately. And so really when we think of business interruption, that's probably top of mind.

As we think of the digital dependencies that we're all reliant upon today, there are so many technologies and service providers out there in the world, many of which we just don't interact with directly as individuals, but they're really the backbone of the digital economy of the internet, frankly. And so if one of these service providers in this web that we talked about earlier were to go down and shuts down a very critical piece of software or technology provider that one is reliant upon, you have contingent business interruption.

The other areas that we're thinking about, too, from insurance loss perspective, of course, errors and emissions. If the AI goes rogue or if it makes a bad decision, who's responsible for that? What minimum cybersecurity controls and workflow assurances are insurers increasingly expecting? So I think it comes back to some of the basics, really.

Do you have proper identity and access management in place, making sure that you are verifying who's accessing your systems when they're accessing it? With that comes in multifactor authentication, which we spoke about earlier. Jack touched on network segmentation, ensuring that different parts of your systems are properly segmented from one another so that if a threat actor gets in, it makes it harder for them to get from point A to point B and move laterally across within the network.

And then certainly in terms of the awareness, the phishing awareness campaigns that we talked about earlier, that is something that is going to be hypercritical going forward. And then last but not least, the data recovery, the backups, making sure that you have those in place and they can be spun up quickly if you are indeed hit by a cyber attack. Those are some of the things that we're seeing from our clients who are helping insurance buyers just better understand their cyber risks.

Jack, you mentioned small firms a little bit earlier. In terms of security, what are the key vulnerabilities for SMEs when you compare it to larger firms? The human element is by far the biggest part. So quite frankly, small businesses are prioritizing, as they should, their profit and loss and their revenue and they're trying to generate excellent products for their customers.

And that means they probably don't have the resource to be able to dedicate to in- house IT staff and probably not information security or cybersecurity. So if you imagine all the different specializations and areas of knowledge that you could have, small businesses are having to trust their IT providers, their information security providers. And that's not necessarily a bad thing. There are lots of fantastic ones out there, but what they then often fail to do is make sure that those are appropriately integrated into the business.

So no IT provider or information security provider can adequately protect you if they don't know what your crown jewels are, what things really matter to the organization. And you have to be able to decide in a breach, " Where am I going to contain, where am I going to segment, and what part of the business might I be willing to cut off?" And oftentimes people just haven't done that sort of tabletop exercise where they spend a couple of hours each quarter going through and saying, " Look, here are my critical systems, how are we going to recover, and here's how that integrates into those IT teams."

You've touched on, Jack, some of the points of what brokers can do, but is there a playbook, I suppose, a blueprint for how you can build cyber resilience while also supporting your clients? Yeah, there's a lot of publicly available, really good runbooks and playbooks for various elements. Like I say, it's so connected that you need different playbooks at different levels. And so I oftentimes think that the most value to be had is a well rehearsed but very simple plan.

So no plan survives first contact. So don't worry too much about the specifics of the types of threat you might face. You can take probably some of the most likely vulnerabilities. The most likely threats that you could have are phishing, ransomware, those types of things.

But actually oftentimes people get too bogged down in the details of the precise mechanism. Because our estate is so complicated, you're never really going to know what's affected. It's trying to rehearse for every single type of fire. Actually, as long as you've got a well- equipped team, you've trained them appropriately with good equipment, that is going to be what's most useful.

And fortunately, you can go to AI and get really good runbooks now. There are lots of international standards. They're all publicly available. You can get them for free.

Jack, talk to me about quantum computing. How's that going to impact the sector? I would like to say that I think quantum's actually going to be minimally impactful in the medium term. So for those not aware, quantum computing is, just think of it as a very accelerated rate of compute, so people are able to just deliver more with what they've currently got.

But at its current stage, quantum is only available in a very specific, controlled environment. It's not really publicly available. You want to think about it just in the same way that you think about AI, in that it is a trajectory. It's not an end state.

12 months of wherever that is is not going to be the finished product, it's going to keep moving in that direction. And what it really means is that computers are going to become more powerful. I think for large organizations, it will be probably a distinguishing feature as to whether they're getting ahead of their peers. So if you work in investment banking, if you work with something where time critical elements are vital, you might consider quantum computing because it's going to have great cost, but it's going to have potential benefit because you can accelerate your performance.

But if you're in small, medium businesses, I think the utility to you is less because what'll happen is everything that you've got encrypted today, quantum computing will unencrypt. So organizations want to think about their cryptographic systems and like, " Where is this most vital data that in 20 years I still need to store because it's required by a regulator?" Agree with that, John? Yeah, I agree that.

In the short term, certainly not on the top of our minds right now. We're certainly watching the space and we'll adjust that opinion as it progresses. There's a question mark in my head, does this become the next nuclear fusion? This is always going to be 10 to 20 years away.

We shall see because there are certainly going to be practical and engineering and physics limitations to quantum computing that a lot of people, much smarter than I am, are trying to figure out right now. I think when we get to a point when quantum computing is more practical, though, these are really big machines, and the chips themselves are probably small, but the machinery itself, there's a lot of cooling that's involved, below zero type of cooling. And when you see these pictures of massive quantum computers, most of that is the cooling mechanism.

This is not something that every hacker around the corner is going to be able to get access to. Now I think there's going to be a lot of quantum cloud computing, so it will probably consolidate to a handful of major companies that have this capability. The question when we get to a post- quantum world is, who else can get access to this? It's probably going to be more nation state driven, folks with deeper pockets, or if we have a consolidation of quantum cloud computing using those legitimate businesses, legitimate quantum cloud compute for illicit purposes.

When we get to that point, there's going to be a sort of transition risk, I think, where if we think that quantum computing is going to be able to crack all your encryption pretty darn quickly, the encryption piece, essentially the verification, authentication tokens, passwords, etc, that's the layer that's going to have to evolve post- quantum. There's already development around post- quantum cryptography, which is going to help harden systems, harden authentication for a post- quantum world.

But again, we'll see as this develops. I don't see it becoming in the fore in the next five years or so at least. Well let's stay in the future, but let's go five years on top of that over the next decade. Based on what we know, Jack, what we've been speaking about, what cyber risks do you think are set to dominate the digital world into the 2030s?

Well, AI is going to introduce almost an infinite number of identities. Right now, your identity system, your IAM, you've got let's say a thousand employees, a hundred employees, it's manageable, it's trackable. You have your roles based on that access to it, you've got privileged access management. There's some good controls in place right now, but soon we won't be able to just imagine your AI agents as another device.

It's not a laptop. That's another person, because that agent is doing things on your devices onto your system, and you need to start tracking those. You're not going to give every AI agent the same access. You're going to have some that have privileged access to only the most sensitive systems and some that don't.

And people will realize that now, if you're struggling to maintain your identity right now, give it five years and you've got your engineering team who are spinning off 50, 100 agents in an hour. Now you need to be tracking all of those because you are accountable for what those AI agents are doing. So if we assume that AI is able to determine the vulnerabilities of the outside face of your infrastructure, you've got to assume compromise. And then what are they going to do once they're in?

Well, now they're looking for lateral movement. They're looking for " Where else can I get in the organization?" And your identity system is the perfect means because it broadly connects everything. So we've got to harden our identity access systems much more than we've done before.

We've got to pull that core technology into our recovery processes. So things like immutable backups, these are backups where they're stored out of region or offline, you can't just do that for your application data anymore, right at that coal face. Now you have to do it for everything, the full depth of your IT infrastructure. And so that identity system is going to be the means and also the mechanism by which you protect yourself.

And then I imagine that support of automated AI offensive and defensive capabilities will become the standard. Humans simply cannot respond quick enough because they're automated. With all that in mind, John, what then should organizations be doing to prepare for these evolving risks? What are the next immediate steps, almost?

Yeah, and I agree with Jack. I think AI is going to be that next rising risk over the next decade or so that folks will have to think about as it relates to cybersecurity. What happens if AI shuts down? Are they going to still have the technical capabilities, the knowledge, the experience to get back into the work itself to stay productive or will this be a business interruption?

Will it be just a decrease in productivity? Do we have the right governance in place when it comes to AI rollouts so that if we need to switch from one AI provider to the next AI provider, it's not a huge change management and transformation project, but we've got the right processes in place so that as this technology evolves and as these AI companies are going tit- for- tat in terms of their own advancement of capabilities, that we're able to stay resilient in this new landscape that we have here?

The other thing that actually I really appreciated your point, Jack, around the offense and the defense capabilities. One of the things that I see, at least in the near term, I'm curious if you disagree with this, is with threat actors getting their hands on more and more of this agentic AI and coding platforms, we've seen reports from Anthropic regarding vibe hacking. There's another one around threat actors using their AI agents to really autonomously, nearly autonomously, attack companies, perform the initial reconnaissance, the lateral movement, finding the valuable assets and targets.

Now, who knows if all of that was a lead up to Mythos, which they talked about recently. They are getting ready to IPO, so who knows what their intentions there are. But at some point we're going to have these capabilities. It's going to be in the hands of both the good guys and the bad guys.

And so I agree with you that over the next 10 years, I think we get to that point where there is almost an even match between offensive and defensive capabilities. But one of the things that I think business need to be vigilant about over the next 10 years is whether there's a temporal effect, whether the bad guys have the upper hand for the first few years of that next 10 years. I think it's really interesting. Nation states, like you mentioned before, they are, in any intelligence circle, they often protect the asset more than they will utilize it.

So whether you have, imagine you're this amazing hacker, you're a brilliant coder and you've developed something that you think is incredible, you're not wasting that on a low value target because this could be the thing that makes or breaks your professional career as a cyber criminal. So the fear that often most companies have is that these tools are available. Most skilled adversaries are not wasting them on you. They are going to dedicate those to the most critical target.

And if you're a hostile state, you are going to use that only when you absolutely have to at the exact opportune time. Most people will still be bothered by, " Oh yeah, somebody picked up and they phished me. And I just gave them the password." So even though there are these brilliant technologies in place, the thing that affects most businesses is going to be day in, day out, routine business staff.

How well did you educate your staff? Did you give them appropriate tokens and did you revoke access when they didn't need it anymore and stuff like this? So yeah, I'm always balancing the really exciting future technologies that come out with the inevitable fear that is used to sell those, versus the practical and much less sexy and exciting stuff, which is like just good business information security hygiene is probably going to save your business. Business continuity plans, disaster recovery plans, just doesn't sell subscriptions.

But still vital. Yeah, absolutely. Jack, John, thank you so much for your time and for sharing your experience. We've mentioned this a few times on the show before, and I imagine it's not going to stop today because this is changing very fast, isn't it?

Thank you very much. Thanks for having us. Thank you. That's it for today.

Next time on Insurance Tomorrow, are we approaching a driverless dawn for UK roads? As the US and China forge ahead with autonomous vehicles on public roads, we look at the picture here in the UK. If you've enjoyed this episode, please subscribe so you don't miss future discussions as soon as they're released, and you can catch up with all our episodes on Spotify, LinkedIn, YouTube, and Apple podcasts. And as always, we'd love to hear from you.

What are the issues you're discussing with your colleagues or your clients? Is there a question you'd like us to put to our experts? Just drop us a message by the link in the show notes. Insurance Tomorrow is brought to you by Allianz.

I'm Georgie Frost. Thanks for listening and we'll see you next time.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How AI Is Rewriting the Rules of Cybersecurity | Truffle Security & SocketAI + a16z · on supply chain attacks95 / 100
  • Building a Cybersecurity Culture in Your Company (Encore)The Backup Wrap-Up · on Ransomware86 / 100
  • Reframing Cyber Risk with Jane Frankland MBEBCG on Compliance · on Ransomware84 / 100
  • AI-Accelerated Supply Chain Attacks with Mackenzie JacksonRunAs Radio · on supply chain attacks83 / 100
  • When Cybersecurity Becomes a Safety Issue: Protecting Autonomous and Critical SystemsExploited: The Cyber Truth · on supply chain attacks81 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Ransomware80 / 100

More from Insurance Tomorrow

All episodes →
  • BIBA 2026: Time to connect
  • AI: Future risks & opportunities
  • Insurance Tomorrow returns soon…
  • 2025 Roundup: Top trends, risks & industry challenges
  • Fraud: Detecting deception in the digital age
Explore the best B2B Finance podcasts →
All Insurance Tomorrow episodes →