
Navigating Cyber Risk · 2026-01-21 · 32 min
Key moments - from our scoring
Substance score
35 / 100
Five dimensions, 20 points each
Awais Farooq, Head of Digital Claim Solutions, Catastrophe and Contractor Connections in Canada for Crawford & Company Insurance, breaks down the critical distinction between cybersecurity (the shield) and cyber risk (the storm) - emphasizing that data theft differs fundamentally from physical theft because organizations often don't realize theft has occurred until irreversible damage is done. The conversation explores how reputational risk, not just financial loss, drives CEO concern after breaches, with clients abandoning vendors over trust violations rather than competing on price. Farooq details the phased panic organizations experience during cyber incidents, advocates for a "human plus AI" approach rather than full automation, and warns about shadow AI - employees uploading sensitive data to ChatGPT and similar tools without corporate oversight or expense tracking. He highlights Crawford & Company's work on voice AI for claims handling, controlled Copilot implementation, and the vendor risk complexity created when data flows through multiple third-party AI services. The episode offers practical guidance for insurance carriers, MGAs, and any organization managing claims data or integrating AI tools without creating downstream liability exposure.
Cybersecurity is the shield (protective measures), while cyber risk is the storm (the threat itself). The key distinction is that cyber theft happens silently - organizations often don't know data has been stolen until it's too late, unlike physical theft where loss is immediately obvious.
Organizations lose client trust and face mass exodus after breaches. Regaining lost customers requires 10 times the effort and spending versus preventing the breach initially. Customers will abandon vendors over data loss rather than compete on price, making reputation the true competitive advantage.
Shadow AI occurs when employees use personal ChatGPT subscriptions or similar tools on their own dime to upload company data - claim details, financials, client information - without IT awareness or approval. This puts sensitive data in third-party systems with no visibility or control over how vendors share it with their own vendor networks.
Instead of traditional back-and-forth estimates between adjusters and contractors, Crawford provides pre-vetted contractors, writes estimates aligned with policy guidelines, warranties the work, and brings properties to pre-loss condition affordably - eliminating contractor inflation and consumer overwhelm.
When organizations feed data into AI models or vendor systems, they're responsible not just for their own data security but also for how each vendor uses that data with their own 18+ vendors and support systems. Contracts must clarify data usage, ownership, and permission, or organizations expose themselves to liability from data they don't even own (client data).
Our reviewer’s read on each dimension, with quotes from the episode.
A few usable points emerge - reputational risk outweighing financial risk, and the importance of translating risk into dollars for executives - but they are separated by long stretches of generic advice, mutual agreement loops, and filler. Insight rate per minute is low.
the biggest risk is the reputation
preparation is not about what you said you did, right. It's what you can prove
The framing devices ('shield vs. storm,' alligator-pond analogy for catastrophe response) are colourful but not original thinking; the underlying arguments - people are the weakest link, AI complicates vendor risk, translate risk to dollar figures for CFOs - are thoroughly circulated takes with no contrarian or first-principles development.
I look at cyber security as the shield and cyber risk as being the storm
you're in a pond infested with alligators and you're in the middle and if you panic, you're going to attract a lot more attention
Awais Farooq is a genuine practitioner with real operational scale - nine years at State Farm running catastrophe operations, leading North America commercial claims across 19 lines at Chubb, standing up P&C claims at a Berkshire Hathaway entity - but cyber is a secondary line within a broader insurance-operations career, and his current role is in claims management rather than cyber risk leadership specifically.
I went to Chubb Insurance. I led their North America commercial claim operations. Essentially, all the ACE businesses were so expanding from property to now 19 different lines of businesses
Started with State Farm, spent nine years of my career there
Almost every number in the episode is hypothetical or illustrative ('$1.2 billion,' 'a team of 20 people working five months') rather than drawn from real cases; the one concrete operational stat - call answer times under 10-15 seconds - is a product pitch, and the Pixar anecdote offered by the host is unverified and vague.
if all of our policies are impacted, we now opened up door to $1.2 billion of uh, impact to our organization
we're answering calls under like 10, 15 seconds in most cases
The host's questions are almost entirely open-ended and predictable ('what are the most significant threats,' 'what trends are coming,' 'what are you most excited about'), with no substantive pushback or challenge to any claim; the host frequently talks as much as the guest and the episode drifts into a company sales-pitch segment without redirection.
what do you believe are some of the new trends that are coming?
what are you currently working on that you're most excited about?
Computed from the transcript - who did the talking, and the words that came up most.
Cyber risk is no longer just about firewalls and passwords - it’s about reputation, trust, and preparation in a world where AI can amplify threats. Awais Farooq, Head of Digital Claim Solutions, Catastrophe, & Contractor Connection in Canada for Crawford & Company, joins John Riley to unpack the evolving cyber risk landscape, from phishing scams and “Shadow AI” to the growing role of cyber insurance. He explains why reputational damage can outweigh financial loss, how organizations should prepare for cyber disasters, and why proving preparedness matters more than promises.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: This is Navigating Cyber Risk podcast with me, John Riley and George Ucy as your hosts. Join us as we explore the challenges faced by executives as they grapple with new and ever changing cybersecurity mandates. Welcome to Navigating Cyber Risk with your host, John Riley, where we explore the challenges faced by executives as they grapple with the new cybersecurity mandates. Today we have an awesome guest and he speaks four and a half languages fluently. We'll talk about the four and a half. I think first and his family to earn a college degree. He's got an incredible story of resilience. Once falling off a roof and walking off with a laugh. He's the head of Digital claim Solutions, catastrophe and contractor connections in Canada for Crawford Company Insurance. Welcome to A Ways Farooq.
Speaker A: You got it. Thank you, John. I really looking forward to the conversation. Wow, you guys captured a lot more details than I thought you had about me.
Speaker B: How do you get four and a half languages? That's what I got to understand.
Speaker A: So I can read and write Arabic very fluently. I don't fully 100% comprehend it, but I can, uh, write word by word what you're saying. So there's that half. I consider it a half.
Speaker B: That's a pretty good half, I gotta say. Okay, what are the other four? Just outta here. What are the other four? That's, uh, it.
Speaker A: I speak Urdu, which is from Pakistan, Punjabi, Hindi, English. And then in addition to that, I grew up around a Brazilian neighborhood, so I could do Portuguese and Spanish in addition to that, so I could get my way in and out of trouble.
Speaker B: Man, we have a lot in common. I like it. All right, so we're going to jump right in here on this next piece, which is the actual podcast piece. And so how would you explain that difference between what cyber security is and what cyber risk is?
Speaker A: Yeah, I look at cyber security as the shield and cyber risk as being the storm. And I think a lot of people just think about risk in a very unique way. Right. You historically had your personal possessions, so back in the day when you owned a lot of gold, you would protect that, put it in a safe, then it was evolved into the materialistic things and your money being in the banks. And you're trying to minimize your risk when it comes to making sure that the impact it will have right on your wellbeing as well as your financial net worth or financial impact as to you as a whole, and then the entities and so on, so forth. And I think cyber is something new to Us, Right. When we start thinking about theft, right. If somebody came in and stole your car, that's a huge impact, Right. If somebody walked into the building, a bank and just took, uh, everything that was in the, um, safety deposit boxes, Right. That's a huge risk. But when you think about the silence of cyber risk that exists out there, you don't even know it's gone. And by the time you know it, it's too late. Right. And it's like, what do you do with that? And I think this has been a huge growing industry as a whole, whether it's cyber security or cyber risk. I think organizations are realizing that they have, they have possession of data and insights about people and about their processes, which is much more powerful, if not equally powerful as money.
Speaker B: Well, yeah, that same data that they're using to mine the person, you know, for whatever reasons, for marketing purposes or for customer, you know, whatever kind of customer acquisition that they've got. As I said back in the day when Internet was just starting out, you know, if you're not paying for it, you are the product. Right. And so with all that data that they've collected, and now it's a matter of protecting it, because as you said, you don't even know. I think some of the. One of the stories that I heard was regarding a studio that like, like Pixar actually lost one of the films that they were working on because somebody had stolen like 6 gigs of data off of their server before they realized it. And it was for our new feature release and it was bad. Right. So it's interesting that the data there, whether it's human data or computing data, ip, you know, intellectual, uh, property of some sort, most things are stored digitally. I mean, and especially with an AI world coming around the corner, or here, or not sure if it's, if it's here, around the corner yet, but I think that that's going to be another interesting, interesting facet to that.
Speaker A: Yeah, no, 100% I agree with you. I think there's so many stories about that. Right. And you have entities just being locked down where the employees can't get into, access their emails, or just the blockade of things that can be done. And it's as simple as leaving the doors unlocked. Right. And how do you make sure that at the end of the day or at the end of whatever you do using, whether it's your vendor engagement, whether it's just your release of information to other entities as a part of that or a bridge that you're giving them, there's not a defect in that. How, how do you protect against just not simply locking the door, but then checking every single facet of it?
Speaker B: Right, yeah. Makes it interesting. So, so along those same, same lines then, like, what are the, what do you think the most significant threats are to a company today?
Speaker A: Yeah, look, I think AI, of course you talked a little bit about that, right. It's making its waves and it's all the algorithms and all the data that's out there is just creating a lot of opportunity for entities as well as a lot of risk. Right. When it comes down to knowing your most valuable assets in an organization are people. Right. Are your employees. And depending on how those have accesses, what permissions they have, how do you administer all that? And I think that's what the AI is really good at doing is understanding and knowing everything about your employees and then leveraging those employees to be able to do the things that are simple as once again leaving their badge behind. Right. It's no longer about, hey, don't leave your badge on the table or don't leave your laptop unlocked. Right. It's more about manipulating the employees to kind of doing things that they normally wouldn't do. I'll tell you for. There was a time where I was getting, trying to get hacked nonstop, where I would get a text message from my CEO that would just need very important piece of document from me and it was always on Friday, it was always 4pm and apparently a CEO of a 12,000 people organization cannot access anyone but me to be able to give him that valuable asset. So I think the vulnerability of people and the trust of people is being manipulated. And I think there's a lot to say about that. Because when you think about cyber risk and you think about the people that are impacted, a lot of that is just naiveness or not knowing. How do you safeguard and what are the protocols that you have to make sure that the access of your employees and access of their information is protected
Speaker B: and safeguarded, I think that's uh, partially a trust thing. I mean, you know, obviously the longer an employee has been with you, the more trust that you give them. But then the other side of that is sometimes an employee could be going through something personally that causes them to be distracted. And so then when they get that 4 o' clock email on a Friday afternoon, you know, in the payroll department to change the CEO's checking account and update their, you know, their whatever. Right, yeah. It becomes one of those things where they're, you know, maybe, maybe they had a fight with their spouse or, you know, something happened or so they're not doing the normal protocol things even though they may have been a long term employee. It's just, it uh, happens to be that day. So then as when you're talking to CEOs and such, how do you talk to CEOs about prioritizing that risk of m. Cybersecurity?
Speaker A: I think there is this misconception that cyber risk is only about the data that is stolen. And then we can start to think about those mitigation strategies of what do we do? But the biggest risk is the reputation. When you think about an organization that protects people's assets and is there to safeguard those assets and those uh, valuable information, like how do people going back to that trust issue, how do they trust your organization do work? Again, you can have a mass exodus of zoomer population and, or whether you're B2B or B2C, there's a huge concern, right? I mean we know this again and again there's been vendors that, that had data breaches and had uh, massive risk attacks and I mean cyber attacks. And what do we do? We said, hey, we're no longer going to do business with that entity because we have some serious concerns, right? And then you get into spending 10 times as much effort to regaining that client, to regaining that customer. So I think CEOs know, and good CEO has that understanding of knowing that it's reputational risk beyond just the financial impact that it will have and the emotional impact it will uh, have on, on people. It's about how will the uh, clients remember that experience of what it went through. So I think that's what I would say is more important than anything else to bring value into the cyber space is that reputation.
Speaker B: Well, m. And, and you actually just touched on the next question really, I mean, which is when you're dealing with cyber disaster, what does that look like for a CEO? I mean if, you know, if you were in their shoes, you might, it sounds like you might have been on, you know, you might have worked with a couple of CEOs that were in that situation based on what you just described. So how does that normally go? What kind of feeling? What are they, what are they experiencing?
Speaker A: I think you go through this motion of panic, immediate panic, right, of what's happening. You're calling everybody in, everybody's jumping on calls nonstop and trying to figure out, okay, what do we do? What is the strategy? Then the next piece is the blame gun throw gets thrown out. Uh, it was a finance department, no it was the IT department. Oh, it was the operation. And this person did this. And you're trying to manipulate and trying to figure out, okay, where did this start? And you're trying to get to that. Next phase is root cause. Right? Next phase is eventually coming in somebody, CEO or whoever, the executive is saying, we need to figure out where this started. Let's put the blame gun aside and pointing fingers aside and focus in on the root cause. And by the time you get to the root cause, the person who hacked you already is reading your emails about all of this going back and forth, right? So there are two steps ahead of you before you can even realize it. I think it's that phased approach of making sure that best advice that I received when I came to leading catastrophe operations was in a catastrophe environment. You're in a pond infested with alligators and you're in the middle and if you panic, you're going to attract a lot more attention and they're going to come come for you. But if you're calm, collected, have a, um, thought process, you know, you may be able to get out of there alive. Right? And I think that's the same scenario. When it comes into this, it is a catastrophe. Right? It is a huge concern. And m time, over time, what we see is the entities that go through this, I wouldn't call it an exercise, this catastrophe, they realize that they need to strengthen up and they do 10 times what they did before. Right? It's about the preventative measure more than the post event because you can and will get hacked again. Not, not saying you won't, but if you don't protect yourself at ah, the first place, you're leaving that door unlocked, I go back to that analogy. It's going to happen.
Speaker B: And I'll be honest with you, one of the big things that we find is that when somebody has a scare, maybe they didn't get a full breach, maybe they just had somebody send them something and they thought, oh no, I might have, uh, that feeling is what really gets them to think about that. And then it becomes a matter of, you know, how do you want to practice that? Do you want to be ready for it? Do you want to be standing in the Everglades with all the alligators around you, trying to figure out, you know, how to deal with them? Or do you want to maybe have a, have a chance of like some cardboard alligators to start off with to figure out what it should look like? So I definitely like that idea for being able to help the CEOs or executives just trying to understand what you don't want to be in that situation. Right.
Speaker A: 100%.
Speaker B: Uh, so from your perspective, what do you believe are some of the new trends that are coming? What kind of a profound impact will they have on the future?
Speaker A: Yeah, look, I touched on it a little bit earlier. I think the biggest challenge ahead of us is the fact that every single organization is jumping into the AI train right at this point. I think every organization is trying to do something with it and, and rightfully so. And you have to improve processes. And I'm a big supporter of technology and advancement, but I think it opens doors into so many challenges. When you think about if you're engaging a vendor or if you're engaging with a model that now gets access to your information or you're feeding into that model, what happens then? Like, where does that go? And I think it's just complicates things even more because now you're not just responsible for your data. You're not just responsible for the data that went out to the vendor. You're also responsible, responsible for the data how the vendor is leveraging it with the 18 other vendors that they have and the support mechanism that they've built around them to curate and give you whatever solution that's provided. So I think it's, it's just a trickle down effect of making sure that there's clear language in your contracts as well as in your process discoveries, of making sure that you're not opening yourself up to something much, much broader. Because the data that you have, it may not even belong to you, it belongs to the clients, right? What kind of agreements that you have there. I think it's just complicating so much more because this AI hype is now put data everywhere, right? Whether it's the employees just putting easy information into a model that somebody's built on back of a napkin. And now they got the information by looting in the employee and saying, we'll give you a summary of a claim, we'll give you summary of your client success, just upload your financials, just upload the claim details and boom. Now that gave so much more information out there that's just floating around, right? And I think we have to be cautious around what goes where, when and how.
Speaker B: And talking about that, I mean that's one of the things that's actually been driving our business as well as third party vendor risk management, uh, tprm, because people are having to check, you know, your vendors, I mean, and what I always like to equate it to, is that you're the vendor that has access to the database of your customer. It's really hard to, for somebody else come in and compete on price if you've got the trust and you haven't lost the trust by losing the data. So now you're providing an invaluable service on the data that the customer already has. You're not competing on price anymore. So you have, you have, you have a true value based service or whatever that, that customer is not going to go searching for saving a dollar. Right? They're not going to just bring in another vendor for that. So as long as you can prove that through your third party vendor management or through, you know, and then all your vendors are doing the same thing, that trickle down of uh, how to build those cybersecurity programs is becoming more important. As far as AI goes. Yes, it was interesting. I was talking to somebody the other day and they were talking about how AI, it's kind of shadow AI these days, right. Because what happens is the employees want the productivity boost. So they went and did this audit and found out that all these things were going across the firewall with AI. And so they went to the CFO and said, how much are we spending on AI? And the CFO said nothing. He said, what do you mean? So they went and asked some of the employees like, so what's this data? And the employee was like, well, yeah, I mean I use chat, GPT and these other services and you know, what I'm doing is I'm taking this data and I'm uploading it. And you know, they're like, well so did you not, are you not paying, that's 20 bucks bucks. I'm paying for it out of my own pocket. And I'm, you know, it makes me faster so I get paid more and I get a raise. Yeah, 20 bucks a month, so I'm not even expensing it. And so then you've got all this shadow it that's happening or shadow AI that's happening and what's really, you know, then, then you got a question like what data is going out? What did you upload to them? Um, because as you said, it's there and available now once, once you've given it to them. So going to be an interesting time to see. See what? I'd love to be a fly on the wall to see the stuff that people upload. Right?
Speaker A: Yeah, yeah, I'm sure somebody's going to come out with, you know, there's Going to be some lawsuits for sure.
Speaker B: Yeah.
Speaker A: And it's going to be very interesting to see, like, you know, some of the things that I hear of, um, just people in the, at least in the insurance industry, and they're like, oh, yeah, I just uploaded a claim. And not with our company, but just in general. Like, I'm like, how are you doing this? And they're like, oh, we're small insurance company, it doesn't really matter. We're just blanking out the information. And you're manually doing this and it's like giving me a heart attack there. And I'm like, no, do not do that. You know, you don't understand the impact of it. And there's ways you can leverage that. Like, we're partnered with Copilot and have done some very good use cases internally to help safeguard and protect that data because we don't want our employees leaving out of the system to be able to go anywhere. Right. I think, I think companies have to start giving access and ability to people, to your point, in a way that's, uh, that's keeping it controlled. It boosts the productivity overall as entity. Right. Because now you experience it from hundreds and thousands of employees and you're like, wow, this is the information that we need. Because now you've done your research in a matter of minutes or hours versus what took you years to gather on, uh, which process to automate and what do you need to do? Because if everybody's going to your model and writing a denial letter and claims, for example, or whatever it may be, and that's all they're doing, why not plug that into your own system and it becomes an opportunity, Right?
Speaker B: Absolutely. Well, so what are you currently working on that you're most excited about?
Speaker A: Yeah, I'm very much excited. On to your point. Like, you know, we're working on voice AI. We're taking that to market and activating it within my own organization here, which is exciting for me. We're doing it in a controlled environment, making sure that we're able to service the policyholders. Right. During catastrophes and during just high volume as well as just traditional volume of giving people that ease and personalized service.
Speaker B: Right.
Speaker A: So when people are calling in and you know, they no longer have to wait 30 seconds, 60 seconds, or whatever our turnaround times are, I mean, we're, we're answering calls under like 10, 15 seconds in most cases. So second, third, fourth ring where we're picking it up, if that. And you know, with that being said, I think it's important to not even let it ring. Right. How do you create that experience? And that's what we're all about. We're about building that connection that when people are contacting us, when people are inquiring about their claims or setting up a claim, it's very personalized to them and it has that element of we care and we have an approach of human plus AI versus just an AI. Right. We don't leave it at autopilot. We have a copilot strategy of making sure that you have the human enablement where, when and how it's needed. But the human is doing as little to no manual work that can be done in today's technology. I think it's moving at the speed of light and we're trying to make sure that we're taking claims forward with that.
Speaker B: So. Which is great. I mean I. There's an insurance, I live in Florida, so insurance has been an issue down here. So tell me a little bit more about, more about the company. Like what kind of companies, who do you help? I mean, are you, what kind of insurance do you provide? And I mean, yeah, so we are
Speaker A: a service provider to the insurance company. So we are a uh, claims engine for the industry, Crawford and company. We offer anything from the start to finish of a claim and even beyond that in subrogation and other elements of uh, fulfillments, etc. So we handle a uh, small fender bender, small leak in your room, completely. Houses being gone, buildings being disrupted, ship running into a bridge to a satellite in the space damage. Right. And uh, so we handle everything, all types of different claims and specialties that exist out there, Cyber being one of them. You know, we service all different types of lines of businesses. But more importantly, you know, we have an ecosystem within the claims environment to be able to partner with our insurance carrier partners as well as MGA's and other captive captives that want to be able to do claims more efficiently and build a solution. Right. I'll give you an example. I'm um, running our contractor connection model in Canada. Essentially, you know, traditional model is that you go in, an adjuster will call you, you'll set up a time to go in, look at the property, they'll write an estimate, cut you a check, you'll get a contractor, contractor will come out, give you their estimate, and then you go back and forth and nobody really is happy because everybody's trying to get the best for them. We eliminate all of that process with contract detection. Our goal is to bring you to pre loss condition. What's affordable in the policy. So we work with the insurance companies to understand what are their policies, guidelines that they would like us to follow. And we build an estimate, we provide the actual contractors to be able to repair that property instead of just saying good luck. Right. It's more than just cutting a check. And as a homeowner it's so frustrating to get a contractor to come to your house, give you an estimate and you know, as soon as they hear insurance claims, some of them will like, don't call me, I don't want to deal with it. Or others will be like, oh great, great opportunity, I can inflate this estimate. I could get you a new kitchen, I could do this, I could do that. All the promises that go along with it. And as a consumer you're overwhelmed. So we provide that solution, we warranty the work, we make sure that the policy is made whole and other instances where we have digital and uh, AI capabilities of voice AI. We make sure that the estimates that are written by contractors, adjusters, they're up to the standards of the insurance company. We have several digital solutions that offer that. But at the end of the day John, our biggest focus is that we are building the future of claims. We're providing enablement for anyone that has claims claims to be able to come to us and have either end to end solution from a first notice of loss of when a claim is filed to, to all the way to recovery. So provide everything in between.
Speaker B: Well, that's honestly really cool. I mean from, from my perspective, I mean I've been on the both sides. Well more on the side of, you know, trying to work with the insurance companies and that type of thing, but the ownership of the process and everything. I can see why you're successful at running that for an insurance company, especially bringing in all the right resources and your contractor connection. That's an amazing piece. That is a differentiator that I consumer would really appreciate that and being, becoming whole without having to prepare for the fight of uh, making sure that I'm going to get what I need, you know, get back to where I was. So that's amazing that you guys are on the, on the right track there. So tell me a little bit about yourself. Where did you come from? You know, where are you at now?
Speaker A: Yeah, absolutely. Been in the industry close to two decades. Started with State Farm, spent nine years of my career there. I started off in claims area with auto property and then managed catastrophe operations in the east coast and pretty much loved it. I love catastrophes. Not having them But I like helping people and getting them rebuilt and being put together. There's a fulfillment element to that, which is different. When you walk into somebody's house and nothing is left except for the foundation, and you're there holding their hand and saying, we'll make this right. So I love that element of it. That's what got my passion for claims. When I left school, I wasn't. I didn't even know I was going to go to the insurance industry. Right. It was more of an accident. Like most consumers, I was like, oh, they just. Insurance is just a scam. Right. It's just. They just take your money. Don't know what they give you. Having been in the industry, I can say it's a very rewarding and fulfilling work that I'm very passionate about. Since then, I. After State Farm, I went to Chubb Insurance. I led their North America commercial claim operations. Essentially, all the ACE businesses were so expanding from property to now 19 different lines of businesses, including cyber DNO, directors and officers and environmental to aircraft, uh, insurance, everything in between. So the things I didn't know, people insured. People were insured for the fascinating experience. Then I had the opportunity to go to a Berkshire Hathaway company where I started a PNC property and Casualty claims department for them and ran all of their property claims for personal and commercial lines. Went to a tech company focused on productivity and utilization. It became a passion of mine. You know, a lot of people complained about, hey, I don't have enough work, or people said, hey, it's too much work, and what is the balance in between? And that passion really led me into joining that organization and focusing my energy into figuring out what is the right balance of how do you keep people busy so they're not burned out, but at the same time, they don't have so much capacity that they feel bored at their job. Right. So there's something in between there then at Crawford and Company. Been here three years. As I told you a little bit about that. I was. I was running our strategy and transformation for our North America business and currently in the interim role of running, uh, part of our Canadian business. This has been exciting. I started in January, but Canada gets very cold in January. I've realized that. Made a lot of trips. Uh, so that goes to show my commitment to the organization that I'm willing to travel to a very cold place if needed and do whatever is needed.
Speaker B: I've had similar experiences traveling around, part of the job sometimes. Right. To, uh, cold places or the hot places.
Speaker A: Yeah, that's Right.
Speaker B: Just depends on which way you got to go. So how would, how would you like people to reach out to you? I mean, we're going to put all the information in the, uh, footer here. But I mean, you know, do you want, do you like email? Do you like them reach out on LinkedIn. What's the best way to reach you?
Speaker A: Yeah, the best way to reach out is LinkedIn. Connect with me. Follow me. I, uh, put a lot of content out there relating to the insurance industry and would love to get your feedback. And if anyone has any questions or want to dive deeper into any of the topics we've discussed, I'm passionate about this whole thing. So specifically cyber, because I think it's a new product and new offering that's just like emerged in the last decade to the next level and it's revolutionizing how and what we operate. Right. So, uh, LinkedIn would be the best way to get in touch with me and happy to connect and bridge connections.
Speaker B: Perfect. Let me. So let me ask you a question about that, because one of the things that I've seen in the industry from this side of it, right. Is that insurance started off very, very inexpensive. I'm not going to say cheap, but very inexpensive for cyber. Right. Because there wasn't an understanding of the risk. Then I think some of the claims started coming in and they started going, wait a minute, this is costing us more. Right. And so there's been a. I think, I think it's starting to get to mature, a more mature model. Right. Where the costs are getting up there. There's enough margin now for the insurance company. But I still think that there's. I think it changes more quickly than most organizations or most insurance. I mean, you've been insuring planes for a long time. I mean, planes only have a certain amount. You know, you can kind of know what it's going to look like when you're talking about, you know, new revolutionary things like AI coming out or other things. I mean, and things leapfrog as much as they do. How do you think that the industry deals with those types of things?
Speaker A: Yeah, no, a lot to unpack there, I will say. Look, I agree with you. I think the space is maturing quite a bit, uh, when it comes to the premiums and when it comes to understanding what type of risk that we're looking at. But it still, I think, has a long way to go. Right. And look, it's no different than insuring anything that you own. If you own a vehicle in a bad part of the neighborhood and, you know, there's theft there every single week. And your premiums are going to be pretty high. Or if you're driving on a highway which has a lot of accidents, your premium is going to be high. Right? And. Or if you yourself had multiple accidents, you go to buy an auto, auto policy, your premium is going to be high. And I think there's a lot of that built into it. Where organizations are looking at behaviors of companies that are, that are looking for cyber insurance, right. Of what practices do they employ? What are they doing as a preventative measure? How are they engaging you, right. In your organization of like, making sure that are you doing everything that you can in your power to prevent it? Because insurance is not there for the loss to happen. Right. We're there if the loss happens. And if companies are expecting, hey, it will happen, and we just want to make sure we'll get paid. Right? That's a, that's a wrong strategy as an insurance company. I wouldn't want to ensure that. I want to ensure for the people that are doing their best to make sure that the hurricane doesn't impact their house as much as possible. Right. So that way they don't have to go through that trouble.
Speaker B: And I mean, but that's partially the usage of the questionnaires that come along with the policies in the beginning. But I think that a lot of times what happens is that it's a, a CFO or somebody that fills that out. They may not be qualified for answering some of those questions about what protections they may have in place, or they may think that they've got something in place. But the IT person's like, no, we don't have that. You didn't want to pay for that one. Right? So I think that that's one of the other disconnects that we, we see a lot of times with that is, look, if you're, if you're listening to this as an executive and you get one of those questionnaires from your insurance company, please go talk to your technical people and make sure that everything on there is correct. Don't just fill it out and send it back. It will come to bite you in the middle. But if something does happen, we also like to say that, you know, it's, uh, a. When it happens, because no matter what, I mean, cybersecurity, it's not an if. It's a win. I mean, there's, there's always gonna be that you can only do so much and there's a certain amount of risk. Of just breathing, right? I mean, I think we learned that during COVID right? There's just a risk. You. You're trying to reduce that risk as much as you can and move forward the best way possible.
Speaker A: So, yeah, no, a hundred percent agree with you. I think that's where it's important. Right. To your point is it'll come back and bite you because of the fact that when you go in and your data is impacted and your entity is impacted and you go to the insurance company and insurance company goes, you don't have all these things that you said, right? And the person who filled it out is no longer there, like, you know, to defend that. Like, how do you go about that? But I agree with you. I think it's partially the fact is when. But at the same time, it's minimizing that, right? It's not, you know, when you're thinking about it, you're not thinking the worst case scenario of saying, my company is going to be impacted all the way around. Because that point, insurance companies are going to have much, much higher and different model for that. Right. And an example of that is like the warranty aspect of things, right? Where, you know, know, over time something's going to wear down and things like that. But I think there's a lot of education to be done, right? There's a lot of information that needs to be shared around what are the things that you can do to prevent it at all? Like, you know, there's always breaches that we don't even know about. Right. The, uh, IT team never brings it because it was so minor and that leak just turned into something massive.
Speaker B: Absolutely. Well, I mean, I appreciate it. So we got. Here's the last question for you and then m. We'll wrap it up here. But we'd like to end by giving, you know, our audiences some action items. Right. So what's one piece of advice or tip for we do their cyber risk that you. That you would give to our listeners?
Speaker A: Yeah, I would say preparation is not about what you said you did, right. It's what you can prove. I would say that again is preparation is not about what you said, right? It has nothing to do with that. Uh, it has to do with the action item of what you actually did. So when you take a step back in your roles and you look at what are you doing in your control, right? You may not be the CFO signing off on these deals. You may just be the operations person or you may just be the IT person, right? Are you raising the Questions when IT come come up and are you making sure that you're able to articulate that as well as you can instead of just getting frustrated? It's very easy, look, and in bigger organizations it is about how you articulate your message and who gets in front of it at what time they get in front of it, or is it past the budget? Is it after the budget? Like where, where do we stand in all of that? So the most important thing is don't get frustrated. Have a methodical approach to what is your problem and how can you relate it to that person. Right? When you go to a CFO and if you say, hey, we can have a security breach and it can impact x am of policies, right? And it can, can be very harmful for our organization, that is a different audience. But when you translate that into numbers and you say, hey, if all of our policies are impacted, we now opened up door to $1.2 billion of uh, impact to our organization. The wheels start turning, right? Or if you go to an IT organization and you say, hey, you're going to need a whole team to recover from an event like this. That will take you five months. And you're going to need a team of 20 people working at that. They're calculating this and saying, oh, all that coding, all that protection that we need to do. So you gotta, you gotta get people to the end state in wherever role they're at to be able to realize what your solution is. So uh, I think it's important to, you know, even from the front lines, uh, as people are seeing some concerns and saying, you know, whether it's phishing scams or whatever it may be, is like, share, share those ideas with your group and uh, be very methodical in how you approach, approach it.
Speaker B: Excellent. I definitely, I think that a lot of people are buying on feelings these days too. So I mean, that feeling of, um, what's that going to feel like? Or you know, and the specifics of, you know, $1.2 billion, as you said, that's when somebody goes, okay, now it made my heart skip a beat there for a second, right? Versus oh, there's a, there's a problem. You know, you go other problem. There's like, okay, well you know, I got, I got, I got a flat tire. I mean, you know, $1.2 billion is more than a flat tire. So I think having having the data and understanding what the real problem is and understanding where the data is, I think is a huge part of that. So. All right, aways Farouk, I appreciate your been awesome back and forth and it was good before we started and kept it going. So I love it. To our audience, thank you for listening. I hope you've learned something and I mean I sure have as far as the insurance industry. So I appreciate that. There it is. It's been another great episode of Navigating Risks with your host John and John John me, and we'll see you next time. Thanks everybody. This was another amazing episode of Navigating Cyber Risk powered by Omnistruck. Show us some love by subscribing and sharing today. Reach out to us with any comments, questions or ideas about future shows by emailing us at podcastnistru. Until next time. Remember, governance is not a technology.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.