Tag: Cyber Insurance

  • The Cyber, AI and Insurance Questions a Board Should Be Asking Now

    Written for the NED.

    AI is the part of this conversation that gets attention. Cyber resilience is the part that should keep a board awake. For a non-executive, the two are now connected — and most boards haven’t checked the join.

    There’s a question worth putting to any board, almost in passing: if the business had a cyber claim tomorrow, are we confident the policy would actually pay? Most directors assume yes. Then comes the follow-up — could management evidence the specific controls the policy assumes are in place? — and the confidence drains out of the room. For a non-executive, that reaction is the signal that a genuine assurance gap has just surfaced.

    It’s worth being careful and accurate, because insurance is contractual and every policy differs. The general point, though, is one every board should understand: a cyber policy is not an unconditional promise to pay. Many are written on the basis that the insured maintains certain security controls. If, when an incident happens, those controls turn out not to have been in place, a claim can become contested rather than straightforward. The policy’s conditions — not its headline cover — are where that lives, which is exactly the kind of thing a board should assure itself on rather than assume.

    What boards tend to misunderstand

    The misunderstanding isn’t recklessness. As one senior leader put it well, most leadership teams aren’t underestimating cyber risk — they’re competing with other priorities. Revenue, hiring, delivery, reporting deadlines. Cyber resilience sits on the list, rarely at the top, and has quietly become more of an operational board issue than a technical one.

    The hidden problem is that many businesses have grown more operationally fragile than they realise — more systems, suppliers, people and remote access, with controls that haven’t kept pace. And the thing assumed to catch them if it goes wrong, the insurance, is the thing whose conditions have often never been read against the actual setup. For a board, that’s an assurance question hiding in plain sight.

    Where AI changes the picture

    The textbook fraud has long looked like this: a supplier’s mailbox is compromised, an invoice arrives looking normal but with changed bank details, the payment goes to the attacker, and a painful argument follows about who carries the loss — often not the party that was breached. That dependency and liability risk is sobering on its own.

    AI sharpens it. The main defence against that fraud used to be human instinct — this doesn’t quite sound like them; I’ll pick up the phone. AI erodes exactly that instinct: writing style, tone and increasingly voice can be imitated well enough to clear the “that doesn’t feel right” bar. The attack isn’t new; what’s new is that the cues we relied on to catch it are becoming forgeable. For a board, this is the real shape of the AI-and-security story — not the exciting demos, but the consequence that the same technology makes social-engineering fraud harder to detect.

    The oversight questions that follow

    A board doesn’t need to become expert to get ahead of this. It needs to ask management the right questions and expect evidenced answers:

    Could we evidence our security controls to an insurer tomorrow — with what’s actually in place, not what we intended? What does our policy assume or require of us, and are those conditions? How does our cover treat social-engineering and “we were tricked into paying” fraud, as opposed to a technical breach? And where are we still relying on a human noticing that “something doesn’t sound right” as a control, now AI can imitate the people we trust?

    None of these needs a technical answer. All are governance questions about resilience, dependency and evidence.

    To be clear: no review guarantees a payout, and no board discussion can promise a regulatory or insurance outcome. The aim is assurance — that the controls the business relies on genuinely exist, and could be proven.

    A prompt to frame the discussion

    For a private, non-confidential board prep:

    “Act as an adviser to a board audit and risk committee. Draft the questions we should put to management about our cyber and AI resilience: what our cyber policy assumes we have in place, what evidence we could produce after an incident, how exposed we are to supplier and payment fraud, and how AI changes that exposure. Frame them as assurance questions, and flag where we should seek independent verification.”

    What to do next

    Put AI and cyber resilience on the board agenda as an assurance item, not a technical one. Ask management to map the business’s actual controls against what the cyber policy requires, and to report where they don’t line up. That mapping — the kind a structured cyber-policy or IT defensibility review makes systematic — turns “we think we’re covered” into “we can evidence that we are.”

    In closing

    AI is the attraction; cyber resilience is the consequence sitting right behind it. A board that assures itself on the exciting AI story while leaving the insurance and controls assumptions untested is overseeing in exactly the wrong direction.

    If your board would value a clear-eyed session on where AI, fraud and cyber insurance now intersect — and the questions to put to management — that’s a conversation Savant and Axulu are built for, with the defensibility and security depth to back it up.

  • Will My Cyber Insurance Pay? A Free Way To Check

    Most Businesses Don’t Know If Their Cyber Insurance Would Actually Pay

    Many business owners assume they have cyber insurance.

    Far fewer know whether it would actually pay after an incident.

    That sounds like the same thing. It isn’t.

    When a claim is submitted, insurers don’t just look at the policy. They look at what happened before the incident.

    • Were backups working?
    • Was MFA enabled?
    • Were staff trained?
    • Were security controls maintained?
    • Can you prove any of it?

    The uncomfortable truth is that many businesses only discover the answers after an attack, when money, reputation and operations are already on the line.

    The Problem

    Cyber insurance policies often contain conditions, exclusions and obligations that most businesses never read and rarely test.

    The result is simple:

    • You believe you’re covered.
    • The insurer expects certain controls.
    • Nobody checks whether those two things match.

    That’s a dangerous place to be.

    A Free Check Takes Minutes

    That’s why we built Check My Cyber Policy.

    It’s a free diagnostic that helps identify potential gaps between what your insurer may expect and what your business is actually doing.

    You answer a short set of questions.

    We analyse the responses.

    You receive a report highlighting areas that may need attention.

    No sales pitch. No obligation. Just a quick way to identify risks before they become expensive.

    The Best Time To Check

    The best time to find a problem is before you need to make a claim.

    A ten-minute review today is significantly cheaper than discovering a coverage issue during a ransomware incident, data breach, or business interruption event.

    Run the free assessment here:

    https://checkmycyberpolicy.co.uk/check

    You may discover everything is fine.

    Or you may discover something that needs fixing while you still have time to fix it.

  • The Cyber Insurance Question: Would Your Policy Pay If AI Caused the Breach?

    AI is the part of this conversation that gets people in the room. Cyber resilience is the part that keeps the board awake. The two are now connected — and most firms haven’t checked the join.

    There’s a question I’ve put to a lot of business owners, almost in passing: if you had a cyber claim tomorrow, are you confident your policy would actually pay? Most say yes without hesitation. Then I ask whether they could evidence the specific controls their policy assumes are in place — and the confidence drains out of the conversation.

    Insurance is contractual and every policy differs, so this needs care. A cyber policy is not an unconditional promise to pay. Many are written on the basis that the insured maintains certain security controls. If those controls turn out not to have been in place, a claim can become contested rather than straightforward.

    What most businesses misunderstand

    The misunderstanding isn’t that businesses are reckless about cyber risk. Most SME leadership teams are competing with other priorities: revenue, hiring, delivery, reporting deadlines and margin management.

    The hidden problem is that many firms have become more operationally fragile than they realise. Systems, suppliers, people, remote access and dependencies have multiplied, while the controls have not always kept pace.

    Where AI changes the picture

    For years, the textbook fraud has looked like this: a supplier’s mailbox is compromised, an invoice arrives looking normal except the bank details have changed, the payment goes out, and the money is gone before anyone notices.

    AI makes that harder to catch. The old defence was often human instinct — this email doesn’t quite sound like them. Writing style, tone and increasingly voice can now be imitated well enough to clear that bar.

    The attack isn’t new. What’s new is that the cues we relied on to catch it are becoming forgeable.

    The leadership question

    If you had to evidence your security controls to an insurer tomorrow, could you — today, with what is actually in place, not what you intended to put in place?

    And where are you still relying on a human noticing that “something doesn’t sound right” as a control?

    Three questions to take to your broker

    • What controls does our policy assume or require us to maintain, and are those written as conditions?
    • If we had a claim, what evidence would we need to produce to show those controls were in place at the time of the incident?
    • How does our policy treat social-engineering and authorised-push-payment fraud, as opposed to a technical breach?

    What to do next

    Read the conditions and requirements section of your cyber policy, and map your actual, current controls against it. Where they don’t match, you’ve found your priority list.

    No review guarantees a payout, and no article can promise a regulatory or insurance outcome. The aim is more grounded: make sure the controls your business is relying on actually exist, and that you could prove it.

    In closing

    AI is the attraction. Cyber resilience is the consequence sitting right behind it. A business that races to adopt AI while leaving its security foundations and insurance assumptions untested is moving fast in exactly the wrong direction.

    If your leadership team would value a clear-eyed session on where AI, fraud and cyber insurance now intersect, Savant and Axulu can help you check whether your controls match your cover.