The Cyber, AI and Insurance Questions a Board Should Be Asking Now

Written for the NED.

AI is the part of this conversation that gets attention. Cyber resilience is the part that should keep a board awake. For a non-executive, the two are now connected — and most boards haven’t checked the join.

There’s a question worth putting to any board, almost in passing: if the business had a cyber claim tomorrow, are we confident the policy would actually pay? Most directors assume yes. Then comes the follow-up — could management evidence the specific controls the policy assumes are in place? — and the confidence drains out of the room. For a non-executive, that reaction is the signal that a genuine assurance gap has just surfaced.

It’s worth being careful and accurate, because insurance is contractual and every policy differs. The general point, though, is one every board should understand: a cyber policy is not an unconditional promise to pay. Many are written on the basis that the insured maintains certain security controls. If, when an incident happens, those controls turn out not to have been in place, a claim can become contested rather than straightforward. The policy’s conditions — not its headline cover — are where that lives, which is exactly the kind of thing a board should assure itself on rather than assume.

What boards tend to misunderstand

The misunderstanding isn’t recklessness. As one senior leader put it well, most leadership teams aren’t underestimating cyber risk — they’re competing with other priorities. Revenue, hiring, delivery, reporting deadlines. Cyber resilience sits on the list, rarely at the top, and has quietly become more of an operational board issue than a technical one.

The hidden problem is that many businesses have grown more operationally fragile than they realise — more systems, suppliers, people and remote access, with controls that haven’t kept pace. And the thing assumed to catch them if it goes wrong, the insurance, is the thing whose conditions have often never been read against the actual setup. For a board, that’s an assurance question hiding in plain sight.

Where AI changes the picture

The textbook fraud has long looked like this: a supplier’s mailbox is compromised, an invoice arrives looking normal but with changed bank details, the payment goes to the attacker, and a painful argument follows about who carries the loss — often not the party that was breached. That dependency and liability risk is sobering on its own.

AI sharpens it. The main defence against that fraud used to be human instinct — this doesn’t quite sound like them; I’ll pick up the phone. AI erodes exactly that instinct: writing style, tone and increasingly voice can be imitated well enough to clear the “that doesn’t feel right” bar. The attack isn’t new; what’s new is that the cues we relied on to catch it are becoming forgeable. For a board, this is the real shape of the AI-and-security story — not the exciting demos, but the consequence that the same technology makes social-engineering fraud harder to detect.

The oversight questions that follow

A board doesn’t need to become expert to get ahead of this. It needs to ask management the right questions and expect evidenced answers:

Could we evidence our security controls to an insurer tomorrow — with what’s actually in place, not what we intended? What does our policy assume or require of us, and are those conditions? How does our cover treat social-engineering and “we were tricked into paying” fraud, as opposed to a technical breach? And where are we still relying on a human noticing that “something doesn’t sound right” as a control, now AI can imitate the people we trust?

None of these needs a technical answer. All are governance questions about resilience, dependency and evidence.

To be clear: no review guarantees a payout, and no board discussion can promise a regulatory or insurance outcome. The aim is assurance — that the controls the business relies on genuinely exist, and could be proven.

A prompt to frame the discussion

For a private, non-confidential board prep:

“Act as an adviser to a board audit and risk committee. Draft the questions we should put to management about our cyber and AI resilience: what our cyber policy assumes we have in place, what evidence we could produce after an incident, how exposed we are to supplier and payment fraud, and how AI changes that exposure. Frame them as assurance questions, and flag where we should seek independent verification.”

What to do next

Put AI and cyber resilience on the board agenda as an assurance item, not a technical one. Ask management to map the business’s actual controls against what the cyber policy requires, and to report where they don’t line up. That mapping — the kind a structured cyber-policy or IT defensibility review makes systematic — turns “we think we’re covered” into “we can evidence that we are.”

In closing

AI is the attraction; cyber resilience is the consequence sitting right behind it. A board that assures itself on the exciting AI story while leaving the insurance and controls assumptions untested is overseeing in exactly the wrong direction.

If your board would value a clear-eyed session on where AI, fraud and cyber insurance now intersect — and the questions to put to management — that’s a conversation Savant and Axulu are built for, with the defensibility and security depth to back it up.