Download

September 2026 ITL FOCUS: Agents & Brokers

ITL FOCUS is a monthly initiative featuring topics related to innovation in risk management and insurance.

ITL Focus Agents & Brokers
 
 

 

FROM THE EDITOR

Insurance agents have been told for years that technology is coming for their jobs. Direct-to-consumer models were supposed to replace them. It hasn't quite worked out that way — agency and brokerage valuations have climbed steadily even as carrier valuations have lagged. But what will AI do?

 The answer, it turns out, is nuanced. AI will not democratize selling. In fact, the gap between top performers and average ones is more likely to widen than narrow, because AI will act as a force multiplier for those who were already at the top of their game. But a lot depends on finding the Goldilocks balance: not too much automation, not too little… just the right amount, implemented just the right way

 That's the framework John Sviokla brings to this month's conversation. A longtime observer of how technology reshapes business — and co-founder of GAI Insights — Sviokla has a way of cutting through the hype without dismissing what's real. He's direct about where most insurance companies and general agencies are falling short on AI adoption, and practical about where the genuine opportunities lie: account planning, product knowledge, and sales simulation.

 He tackles the chronic problem of churn among new agents, explaining how AI can be a major help. He details why so many organizations stall out before AI delivers any lasting value — it has less to do with the technology than with organizational habits that predate it.

 Read the full interview to find out why Sviokla says AI can be a flight simulator for selling, what his RISE adoption framework means for agents trying to figure out where to start, and why the most important thing to understand about AI is that you can't simply buy it.

 
 

AI'S SUPERPOWERS FOR INSURANCE AGENTS

Paul Carroll

You’ve long been my go-to guy on the business implications of artificial intelligence. To start us off, how would you set the table for insurance agents and brokers in terms of how they should think about how AI will play out?

John Sviokla 

Well, first, I think it's important to reassert that salesmanship is going to continue to be needed—probably even needed more. How salespeople serve, what segments they serve, and so forth will be different, but the role remains.

read the full interview >

 

MORE ON OPERATIONAL EFFICIENCY

AI Can Transform Agency Financial Operations

by Dave Stevens

AI-powered reconciliation transforms month-end closing from a periodic fire drill into continuous real-time financial visibility for agencies.
Read More
 

Agency Growth Numbers May Be Misleading You

by Brian Jones

Revenue growth masks a retention crisis costing agencies millions in enterprise value and leaving half their book vulnerable to churn.
Read More
 

The Ghost in State Farm's Machine

by Riv Arthur

State Farm's sweeping cuts to agent compensation signal how private equity thinking now shapes even mutual insurers' operating models.
Read More

 

AI Agents Transform Buying Behavior in Financial Services

by Rahul Kumar

Agentic commerce is transforming financial services as AI agents evaluate products. Institutions must now compete for algorithmic visibility.
Read More

Insurance Agencies: Don't Panic on AI ROI

by John Markos

Insurance agencies investing in AI are seeing productivity gains but not yet revenue lifts—a predictable adoption phase, not a failure.
Read More

Independent Insurance Agencies Face Staffing Crisis

by Tricia Sabulis

Independent agencies must shift from passive job posting to active talent development as the insurance staffing crisis intensifies.
Read More

 


Insurance Thought Leadership

Profile picture for user Insurance Thought Leadership

Insurance Thought Leadership

Insurance Thought Leadership (ITL) delivers engaging, informative articles from our global network of thought leaders and decision makers. Their insights are transforming the insurance and risk management marketplace through knowledge sharing, big ideas on a wide variety of topics, and lessons learned through real-life applications of innovative technology.

We also connect our network of authors and readers in ways that help them uncover opportunities and that lead to innovation and strategic advantage.

Enterprise AI Adoption Will Soon Be Top-Down

Enterprise AI adoption will shift from grassroots experimentation to top-down mandates as investors demand returns on trillion-dollar infrastructure bets.

Enterprise Adoption

The grassroots approach to AI adoption has probably gone as far as it’s going to go.

Point solutions are impressive—but rarely scale. In-house pilots generate strong early results, only for performance to deteriorate for lack of consistent data.

As for copilots, people generally appreciate tools that draft emails, summarize documents, or eliminate busywork. But enthusiasm tends to wane when the tool stops assisting and starts deciding. Handing approval authority to a model can feel indistinguishable from handing over your badge and desk.

That's not irrational. Nobody organizes a grassroots campaign to accelerate their own obsolescence.

The next big push in enterprise AI, when it comes—and I suspect it will come sooner rather than later—will come from above: top down, through the capital structure.

Trillions of dollars are being invested in the infrastructure required to power the AI economy. The institutions providing that capital aren't investing on faith. They have underwritten a thesis: that vast investments in computing, data centers, power generation, networking and models will produce vast economic returns.

For that thesis to work, somebody has to create the demand.

Consider who is financing the AI buildout. BlackRock, Blackstone, Apollo, KKR, Goldman Sachs and other institutions that manage or deploy trillions of dollars are helping finance hundreds of billions of dollars in AI infrastructure. Many of those same institutions are among the largest shareholders of America's public companies, including insurers.

At Travelers, for example, Vanguard, BlackRock, State Street and Fidelity together account for roughly one-third of the company's shares. The financial system is simultaneously financing the supply of AI infrastructure and owning the enterprises whose adoption of that infrastructure will be necessary to justify the investment.

There's an almost poetic financial loop here worth noting: Blackstone's AI infrastructure investments are partly financed with insurance capital. Blackstone now manages $290 billion in insurance capital, while its infrastructure and data-center strategy explicitly connects digital infrastructure with its insurance-capital platform.

All of this means the capital funding AI infrastructure and the capital owning the companies expected to use it increasingly overlap.

Put more plainly: the same capital on your shareholder register may also be financing the infrastructure that needs you to become an AI customer.

The pressure will run downhill. Capital markets will lean on boards. Boards will lean on CEOs. CEOs will hang targets on business units. And eventually the questions will get very specific: What percentage of your workforce is AI-enabled? What's the productivity delta? Where's the ROI? What are your competitors doing with AI that you aren't? What is stopping you from moving faster?

Delivering solid business results is, today, enough. In the near future, how those results are delivered—through what combination of human effort, automation, and AI—will increasingly factor into executive evaluation.

Insurance leaders can prepare now. That does not mean recklessly deploying AI everywhere. It means creating the conditions under which AI can produce durable, defensible business results.

Governance is part of that infrastructure. Done badly, governance becomes an institutional “no.” Done well, it becomes a mechanism for saying “maybe” or “yes,” depending on the use case, the risk, and the evidence.

There is also substantial work between an AI pilot and a legitimate business result. Enterprise information must become usable by machines that can reason and act on it. That means building ontologies, pipelines, object models, knowledge graphs and relational data stores; connecting systems never designed to work together; and establishing the controls that make machine decisions auditable.

None of that is especially glamorous. All of it takes time.

Which is why waiting for questions from investors, analysts, and boards may be the wrong strategy. By the time those questions arrive, you do not want to be explaining why you haven't started. You want to be showing what you're building, what it does, and what it's worth.

The AI infrastructure industry needs demand. Build your own AI infrastructure to create demand for theirs. Build before they ask.


Riv Arthur

Profile picture for user RivArthur

Riv Arthur

Riv Arthur is a business leader and technologist working in insurance, healthcare, and private equity.

Insurance Industry Faces Growing Trust Crisis

The insurance industry has always had a trust problem. What is new is the intensity — and the number of forces converging to make it harder to ignore.

Trust

There is an uncomfortable question confronting the property and casualty insurance industry:

Are we experiencing a temporary backlash, or is insurance entering a new era of fundamental distrust?

Insurance has never been an easy product to love. Consumers pay premiums for something they hope they never need, governed by contracts that can be difficult to understand and fully appreciated only when a loss occurs. The relationship can change dramatically in a single claim. But something feels different today.

Distrust is broader, louder and increasingly connected to public frustration over rising costs, corporate power, artificial intelligence, data collection, climate risk and the perceived behavior of large institutions.

For an industry whose fundamental product is a promise—we will be there when something goes wrong—trust is paramount.

A warning we wrote about before

In December 2024, Stephen Applebaum and I wrote Broken Trust, Insurance Industry Included.Our premise was straightforward: the public reaction following the killing of UnitedHealthcare CEO Brian Thompson was an alarm bell for the entire insurance industry, not simply the health insurance sector. We pointed to rising premiums, coverage withdrawals, privacy concerns, widening protection gaps and growing skepticism toward technology as evidence of a broader erosion of confidence.

Nearly two years later, that warning appears increasingly relevant.

The issue is no longer simply whether consumers trust their insurance company. It is whether the public increasingly distrusts the insurance system itself.

The symbol of a much larger problem

The December 2024 killing of Brian Thompson was horrifying. Yet the public reaction to the alleged perpetrator, Luigi Mangione, revealed something the insurance industry should not dismiss as simply an isolated social phenomenon.

Polling following the killing showed unusually strong sympathy for Mangione among younger Americans. The reaction was not really about one individual. It reflected anger toward a system that many people believe has become too powerful, too complicated and too disconnected from the people it serves.

UnitedHealthcare operates primarily in health insurance, not P&C. But to the public, “insurance company” can be a much more important category than the distinctions between health, auto, homeowners or commercial insurance.

That should concern every P&C executive.

Then came the claims controversies

The industry’s claim function has increasingly become the center of the conversation.

In 2025, a U.S. Senate hearing examined insurance claims practices following natural disasters, with executives from Allstate and State Farm appearing alongside policyholders, adjusters and consumer advocates. Allegations that claim evaluations had been manipulated or unfairly reduced received significant attention, although the insurers disputed them.

In June 2026, Oklahoma Attorney General Gentner Drummond filed another lawsuit against State Farm alleging that the insurer’s “Hail Focus Initiative” used undisclosed standards and other practices to reduce payments on hail and wind claims. State Farm disputes the allegations.

Just this week, Los Angeles County announced a lawsuit against State Farm over its handling of claims following the January 2025 Southern California wildfires, alleging delays, underestimation of losses and other improper claims practices. State Farm has disputed the allegations and pointed to billions of dollars in wildfire claims it has paid.

These cases have not established that the insurers acted improperly. Lawsuits contain allegations, not findings of fact. But public trust is rarely determined by the final disposition of a lawsuit – many of which are dismissed, in favor of the insurer or most often amicably settled. Either way, the narrative gets there first.

Profitability makes the narrative more difficult

The industry’s financial performance adds another complication.

P&C insurers have experienced a substantial improvement in profitability as premium growth, stronger underwriting results and investment income have combined to produce record-setting earnings.

Strong insurer profitability is not inherently evidence of consumer mistreatment, yet broad-brushing narratives paint a negative picture to make a point.

Insurance is a capital-intensive business. Insurers need adequate returns to support capital, absorb catastrophe losses, pay claims, invest in technology and remain capable of writing business through difficult cycles.

But consumers don’t necessarily see that complexity. Instead, the narrative can become:

My premium went up. My deductible went up. My claim was denied. In all cases, the insurer made more money.

Whether that conclusion is actuarially accurate is almost beside the point. It is emotionally powerful. And when consumers are already frustrated by inflation and the cost of housing, automobiles and repairs, insurance profitability becomes an easy target.

The “closed without payment” problem

A recent Wall Street Journal analysis of auto insurance claims illustrates the challenge.

The Journal reported that the percentage of certain auto liability and medical claims closed without payment had increased materially over the past decade. Analysis of NAIC data showed that 45% of such claims were closed without payment in 2025, compared with 35% in 2016. That is an important statistic.

But it is also an example of how a technically accurate statistic can create a broader impression that may not tell the whole story.

“Closed without payment” (CWP) does not equate to “wrongfully denied.” Claims can close without payment for numerous reasons, including coverage issues, duplicate claims, fraud, liability determinations or other factors. In fact, CWP rates are a singular gauge for purposes such as monitoring claim productivity and should not be isolated from average claim payments, reserve accuracy, re-open rates and other metrics to assess payments. Certainly not to accurately judge claim settlement fairness.

The industry’s response made an important distinction: the increase identified by the Journal was concentrated in liability and medical claims, while physical-damage claims were being paid at essentially the same rate as a decade ago.

A technically correct defense can still fail as a trust strategy.

If consumers hear “nearly half of claims aren’t being paid,” a subsequent explanation about claim categories, coverage triggers and statistical methodology may never overcome the initial impression.

The industry needs to communicate in a way that makes the underlying economics and claims experience understandable—not simply defensible.

Insurance has always had a trust problem

None of this is entirely new.

Insurance has several structural characteristics that make trust difficult. It is intangible, complex and often mandatory. The customer pays first and receives value later—sometimes years later. And when the customer most needs the product, the insurer must determine whether and how much it will pay, which can easily create friction.

A policyholder sees a damaged roof. An insurer sees a contract, causation, exclusions, depreciation, replacement cost, engineering evidence, estimating methodology, fraud indicators and applicable regulation. Both may believe they are acting reasonably. But one side has generally spent decades learning how the system works. That asymmetry creates distrust.

Four forces amplifying the problem

Affordability: Consumers have experienced dramatic increases in home and auto premiums in many markets. Those increases have legitimate drivers—repair costs, medical costs, litigation, catastrophe losses, reinsurance, inflation and changing risk. But consumers experience one part of the equation: the bill.

Claims: The claim is the industry’s moment of truth. Every difficult claim creates a potential advocate—or detractor. Social media can now turn an individual dispute into a national story almost instantly.

AI and data: AI can improve claims accuracy, detect fraud, accelerate settlement and reduce administrative expense. But from a consumer’s perspective, AI can also sound like: a computer decided not to pay me. The broader public debate over AI, privacy, data centers and technology companies suggests this skepticism will grow.

Distrust of institutions: Insurance is not operating in isolation. Banks, pharmaceutical companies, technology companies, healthcare organizations and other large institutions are experiencing versions of the same credibility challenge. Insurance is particularly vulnerable because its product is fundamentally built on trust.

The industry’s response

There are reasons for optimism. Some insurers recognize that restoring trust requires more than advertising.

Farmers has introduced a Coverage Review initiative designed to help consumers better understand what their policies do and don’t cover. Importantly, the service is available even to consumers insured elsewhere. This attacks the trust problem upstream by not waiting for a claim to explain the policy. Time will tell if this is simply clever marketing or possibly a new way to encourage discussions that consumers tend to avoid.

State Farm has also taken steps to return value to customers, including a $5 billion cash-back dividend for qualifying auto customers, while reducing auto rates in several markets. Progressive has returned excess profits to eligible Florida personal auto policyholders, while USAA has also reduced Florida auto rates and returned value to its members.

Rate increases are easing in several markets after several years of extraordinary increases. These actions matter. But trust is not restored by one dividend, one advertising campaign or one rate decrease. It is restored through repeated evidence that the organization behaves consistently with the promise it makes.

The ecosystem has a role to play

This is not solely a carrier problem.

Solution providers, claims technology companies, TPAs, adjusters, brokers, agents, consultants and analysts all influence the customer’s perception of insurance. Every automated decision and claims estimate. Every AI recommendation and vendor interaction. And each confusing communication. They all become part of the insurance brand.

That means the industry’s technology agenda cannot simply be about doing things faster and cheaper.

It also has to be about doing things in a way customers perceive as fair, understandable and trustworthy.

Instead of asking only, Can AI make this decision?

We should ask, Can the customer understand why this decision was made?

Instead of asking, Can we automate this claims process?

We should ask, Where does a human being add trust and judgment?

And instead of asking only, Can we reduce claims expense?

We should ask, Can we reduce expense without damaging the customer’s perception of fairness?

The uncomfortable opportunity

The industry should not respond to today’s distrust by simply defending itself more aggressively.

Some criticism is unfair, and some statistics are presented without sufficient context. Some claims disputes are considerably more complicated than the headlines suggest. And insurers are confronting genuine challenges from catastrophe risk, inflation, litigation, repair costs and capital requirements.

All of that is true. But another truth is equally important:

People don’t trust institutions simply because the institution can prove it is technically correct.

Trust comes from transparency, consistency, empathy and evidence. The industry has an opportunity to use the same technology driving transformation to address the trust problem. AI can make insurance more automated—but also more transparent.

Data can make underwriting more sophisticated—but also help consumers understand their risk.

Claims analytics can reduce leakage—but also identify where customers experience unnecessary friction.

And stronger profitability can provide the capital to invest in better products, better experiences and better claims operations.

The real question

Insurance does not need to become universally loved.

It needs to remain credible.

When someone buys homeowners insurance, auto insurance or commercial coverage, they are not really buying a policy document. They are buying confidence that when something goes wrong, someone will stand behind the promise.

That promise is the product.

The insurance industry has a trust deficit. The question is whether carriers and the broader ecosystem will treat that deficit as a public-relations problem—or recognize it as a structural business problem, a technology problem, a claims problem and ultimately a product problem.

The industry has spent enormous amounts of money making insurance more sophisticated. Perhaps the next investment should be making it easier to believe.

The policy isn’t the product. Trust is.


Alan Demers

Profile picture for user AlanDemers

Alan Demers

Alan Demers is founder of InsurTech Consulting, with 30 years of P&C insurance claims experience, providing consultative services focused on innovating claims.

The 6 Months That Redefined Insurtech

Venture capital investing in insurtech in the first half of 2026 shows it taking a very different path than many expected just a few years ago. 

Image
Random Design

Sabine VanderLinden, a keen observer of venture capital in insurance, recently wrote a startling sentence: "50% of every insurtech dollar invested in the first six months of 2026 went to companies that will never sell you a policy."

That number is a far cry from what proponents expected when the insurtech wave began a decade-plus ago. At that point, predictions were rife that some Big Tech company such as Google or Amazon would do a cannonball into insurance and change the game entirely or at least that some startup would figure out a way to leapfrog incumbent carriers and make them play catch-up. 

But VanderLinden's analysis provides a guidepost about where investment in insurtechs is today and where I think it's going.

Let's have a look. 

Artificial intelligence still takes up the vast majority of the headspace for most incumbents as they try to innovate. They're spending enormous effort to look for efficiencies in processing claims, in underwriting, in sales, and so on. They're also experimenting with ways to set up autonomous agents and to coordinate their actions while staying within crucial guardrails.

VanderLinden's analysis found significant funding for AI-based insurance startups, too, but they were just the third biggest category in the first half of the year. First was: "risk data. Satellites, sensors, and driving behavior.... This is happening because proprietary risk data has become the scarcest asset in the value chain. Models are abundant. Compute is abundant. Ground truth is not. The ventures that own a persistent, hard-to-replicate view of physical risk are commanding late-stage checks."

She highlights ICEYE, which raised a $500 million Series F "to expand its radar satellite constellation for natural catastrophe monitoring," and Cambridge Mobile Telematics, which raised $350 million for its insights into driving behavior. She also mentions mea platform ($50M), Fulcrum ($25M) and Axle ($17.5M).

Her observation certainly dovetails with what I'm seeing. I've long argued that the surest insurtech winners would be what we called "arms dealers" during the early internet days. Just as Sun Microsystems made bank by selling servers to startups, whether they thrived or, more likely, crashed and burned, companies that developed important, proprietary data sources were always likely to thrive. 

And there have been impressive advances in risk data, as evidenced by any number of articles we've published recently at ITL. This interview I did with Eagleview lays out a vision for how aerial views of properties will enable continual monitoring of property risks. This piece, from Nearmap, describes how the condition of roofs and other aspects of properties can be tracked long before a claim surfaces. This describes advances in "hyperlocal" weather intelligence. This explains how catastrophe modeling is moving beyond static pictures of disasters and toward images that show how floods, wildfires, etc. develop over time. We've also published on new ways to track maintenance records of commercial properties to better understand the likelihood of a claim, to monitor for the next pandemic, and so on. 

VanderLinden says the second biggest category of venture investment was in digital-first insurers and MGAs and offers a key insight: "Not one of them is a generalist." She writes:

"Alan raised $116M for digital health in France. Corgi closed a $106M Series B insuring technology companies. Counterpart took $50M for small-business liability, Shepherd $42M for construction, Lassie $75M for pet, Zego $28M for gig drivers. Stoïk and Mitigata both raised for cyber, on two different continents.... The funded insurance provider of 2026 is specific, defensible, and priced for its niche."

Third was AI: "$216M went to AI-led claims, underwriting, and operations automation.... These ventures do not compete with insurers. They sell digital labor to them. Claims handling, prior authorizations, underwriting triage, document verification: the workflows where a human-agent ratio can shift fastest and the savings land on the P&L within quarters, not years."

The insurtechs that went after incumbents head-on -- notably Lemonade, Hippo and Root -- are still around and seem to have stabilized after years of struggle but are way down from their peaks in early 2021. Lemonade shares are off some 65%, Root is down 85%, and Hippo has fallen 90% even as the S&P 500 has nearly doubled. So I continue to believe that the sorts of "arms merchants" VanderLinden describes are the future of insurtech.

Cheers,

Paul

P.S. If you'll permit me a proud papa moment....

My older daughter made her debut in the Wall Street Journal over the weekend. She trekked the 500-mile Camino de Santiago in Spain this spring and wrote an essay [free link] about the trip that has generated some 500 comments and emails and spent some time on the "most popular" list. It's a splendid piece. I'm delighted for her.

I also love that the Carroll family is now on its third generation at what we joke is the family business. My father spent a year at the WSJ. My younger brother and I combined for 59 years. Now Shannon....

From reactive to proactive: How Westfield is helping homeowners prevent catastrophic losses before they occur

Smart sensors in the home provide water-leak and fire alerts. Westfield is piloting these sensors in multiple states, bolstering agents’ loss-prevention services to homeowners.

Westfield

The average consumer views insurance as a reactive product. A pipe bursts. A fire starts. They file a claim, and their carrier helps them to recover and rebuild.

That captures the core of the insurance value proposition, but it overlooks a key element: the role insurers play in preventing losses before they happen. This is critically important. Few homeowners realize there are simple, effective steps they can take to protect their homes from these losses.

As customer expectations evolve and preventable losses continue to impact homeowners, insurers across the industry are beginning to rethink their role — not simply as organizations that pay covered claims but as organizations that help customers avoid losses altogether.

Recognizing this shift, we’ve expanded our portfolio of risk management tools and resources — including two smart sensors, Ting (electrical fire prevention) and LeakBot (leak detection) — to help policyholders[1] identify hidden risks and intervene before losses occur. 

“Helping customers recover after a loss will always be at the heart of what we do,” says Corey Vigliucci, AVP of sales and underwriting for Westfield Personal Lines. “But if we can help prevent that loss from happening in the first place, that’s an even better outcome. That’s why we’re investing in practical solutions that help homeowners and farm owners identify hidden risks before they become losses. It’s another way we’re helping protect what matters most.[2]

Here’s what that looks like in action.

Ting: Preventing electrical fires

Every 10 minutes, a family in the United States is impacted by an electrical fire. The average electrical fire claim costs approximately $215,000, according to Triple-I, and that’s only the financial damage. The emotional devastation homeowners face when losing their home to a fire is immeasurable.

To help homeowners mitigate the risk of devastating electrical fires, we worked with Ting Labs to offer Ting, its electrical fire prevention system, to all its eligible personal lines and farm insurance policyholders.

Ting detects hidden electrical hazards before they escalate into fires. The system combines a smart sensor, a mobile app, an advanced signal analysis and a fire safety team that works with homeowners in real time to help identify and mitigate risks.

Simple by design, the smart sensor plugs into any standard outlet and uses advanced technology to identify electrical arcing, faulty wiring, failing outlets and other hidden hazards that homeowners might never detect.

On average, Ting sends fire hazard alerts to approximately one in 60 homeowners each year. About one in 27 of those alerts would have resulted in a fire if the hazard had remained undetected.

The value extends beyond homeowners. These tools also help equip agents to have more proactive risk management conversations with customers.

“This investment also creates meaningful value for our agents by equipping them to have more proactive risk management conversations with customers,” said Dave Ruppel, AVP of sales and underwriting for Westfield Agribusiness. “By identifying potential issues before a loss occurs, agencies can reinforce their role as trusted advisors, deepen customer relationships and help improve long-term customer retention.”

Matthew Boyert, CEO and founder of Boyert Insurance Group, experienced the benefits of Ting firsthand. One day, while meeting with a client, Boyert received a Ting alert on his phone that read, “Fire detected!” 

“I rushed home with my heart beating at 100 miles an hour,” he recalls. He immediately called the Ting support team and learned the alert was for a potential fire hazard.

When Boyert arrived home, a Ting representative helped him isolate the issue, which turned out to be an electrical outlet with loose wiring that was actively arcing.

“If I didn’t have that device, I would not have known there was arcing that could have caused a catastrophic fire,” Boyert reflects. “We could have lost our house, our memories, everything.”

Stories like this resonate with homeowners and help reinforce the importance of proactive risk management.

Matthew Mangus, president of Miller’s Insurance Agency, has seen what happens when electrical fire hazards go undetected. In the past two years, he has seen two clients lose their homes in fires caused by electrical failures.

“I’ve met with clients two days after their homes burned down,” he reflects. “Seeing their mindset as they figure out what to do next is heartbreaking.”

Since launching its Ting offering in May 2024, we’ve enrolled more than 21,000 Westfield customers in the program. During that time, we’ve identified nearly 200 potential “saves” across both electrical and utility fire hazards, including panel failures, faulty outlets and wiring issues.

LeakBot: Tackling hidden water losses

Although fire presents one of the most disastrous risks, water damage is among the most common and costly. Non-weather water damage, such as plumbing failures, appliance leaks or burst pipes, is the second leading cause of homeowners insurance claims in the U.S., accounting for approximately 23%-28% of all claims, according to Consumer Affairs.

Triple-I reports the average non-weather water damage claim is approximately $15,400, with hidden leaks behind walls or beneath floors often triggering the worst losses.

That’s where LeakBot, a smart water leak detection solution, comes in. The technology helps homeowners identify non-weather-related leaks, often before any visible signs of damage emerge. Earlier this year, we began offering LeakBot to eligible policyholders in Ohio, Indiana and Pennsylvania. In just a short time, more than 5,000 homeowners have enrolled.

When a leak is detected, homeowners gain access to a support team and specially trained plumbers who help diagnose and resolve the problem before it escalates into a major claim.

The technology’s simplicity is part of its appeal. LeakBot installs in minutes by clipping onto a home’s main water pipe, with no tools or plumbing expertise needed. Once installed, it quietly monitors the home in the background.

For agents, that simplicity is a major advantage. It makes it easier to introduce homeowners to risk prevention and demonstrate added value beyond the policy itself.

According to Consumer Affairs, fewer than 20% of homeowners take steps to avoid leaks, such as plumbing inspections or installing leak detection systems, despite approximately 65% of water damage incidents being considered preventable. By offering a simple tool like LeakBot, agents are well positioned to help change those statistics.

“I’m telling my Westfield customers about LeakBot, and there’s a lot of interest,” says Boyert. “There are not many carriers that offer one, let alone two, preventive risk management devices free of charge to their insureds. Kudos to Westfield for that.”

The agent opportunity: Moving beyond the policy

For independent agents, preemptive risk management tools like Ting and LeakBot transform the conversation from transactional to advisory, creating more frequent, meaningful touchpoints with customers, and reshape how they deliver value.

Data plays an important role in making those risks tangible. When customers understand how common and costly these losses are, prevention becomes easier to appreciate.

“Insurance is an intangible product. You’re basically selling a promise,” says Boyert. “Tools like this give us something tangible that we can offer to clients to give them additional peace of mind.”

Agencies can strengthen relationships and build trust over time by introducing solutions that actively help protect customers. By equipping agencies with carrier-backed risk management solutions, insurers are enabling agents to go beyond transactional interactions and position themselves as long-term advisors.

“It’s a great retention tool,” says Mangus. “As an agency owner, I’m always interested in two elements. Can this help our clients, and will it help with retention? With both, that’s a win-win.”

Customers who embrace risk protection often become more loyal to both the agency and the carrier. “The customers who recognize the value these solutions provide — and understand that Westfield introduced them to the concept — often become more loyal to both Westfield and, by extension, Miller’s Insurance Agency,” Mangus explains.

By equipping agents with practical risk-prevention tools and resources, we’re helping redefine the role agents play — from policy providers to trusted risk advisors. As personal lines continue to evolve, carriers that help customers prevent losses, not just recover from them, will help define the next generation of insurance value.

[1] Customers must have an eligible homeowners, WesPak®, WesPak Estate®, or farmowners policy with an owner-occupied dwelling to claim Ting. LeakBot devices are only available for homeowners policyholders in Ohio, Indiana and Pennsylvania.

[1] Please see footnote 1.

About the author:

Author

Casey Burke is Director of Standard Lines Marketing at Westfield, where he helps shape marketing strategies that support customers, independent agents and the evolving needs of the insurance marketplace. He brings more than 20 years of marketing and sales experience, including more than a decade in the insurance industry. Throughout his career, Casey has focused on connecting customer insights, business strategy and practical solutions to drive growth, strengthen relationships and deliver meaningful value

 


Westfield

Profile picture for user Westfield

Westfield

Founded in 1848, Westfield is a global leader in property and casualty insurance, delivering superior risk insights and innovative solutions to customers through a portfolio of insurance products. Westfield underwrites commercial, personal, surety and specialty lines of coverage through a network of leading independent agents and brokers in the United States and specialty products through Lloyd's of London Syndicate 1200. As a mutual insurance company with a workforce of more than 4,000, Westfield has revenues in excess of $4 billion and more than $11 billion in assets. Learn more at www.westfieldinsurance.com

Why Human Audits of AI Decisions Fail

As AI scales, insurers relying on sampling to audit AI decisions may be kidding themselves.

Human in the Loop

“Human in the loop” has become one of the most reassuring phrases in artificial intelligence.

Ask an organization how it governs an AI-assisted process and, sooner or later, someone will say that a human reviews the decisions.

That sounds responsible. It can also be almost meaningless.

Consider an insurer that introduces AI into a workflow that previously produced 1,000 decisions or recommendations a week. With AI, the same operation can suddenly produce 5,000. The review team does not become five times larger.

So the organization samples. Perhaps humans review 10% of outputs. As volume increases, maybe that becomes 5%. Eventually, the organization can point to a documented human-review process while the overwhelming majority of AI-assisted decisions pass through without meaningful scrutiny.

The problem is not sampling itself. The problem is confusing a sample of decisions with a system for governing decisions.

That distinction matters as insurers put AI deeper into underwriting, claims, servicing, fraud detection and other consequential workflows. The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers contemplates AI across these activities while emphasizing that existing legal obligations continue to apply regardless of the technology used.

The denominator changed

Traditional quality-assurance programs were designed around human-scale production. A supervisor could review a meaningful portion of an employee's work. Patterns emerged. Coaching followed. Exceptions could be investigated.

AI changes the denominator. It can increase the number of recommendations, drafts, classifications and decisions far faster than an organization can increase the number of people available to inspect them.

More automated decisions + the same review capacity = less meaningful human oversight per decision.

NIST's 2026 work on monitoring deployed AI systems identifies scaling human-driven monitoring alongside rapid rollouts as a barrier to effective AI monitoring. NIST also notes that post-deployment monitoring is necessary because systems operate under changing real-world conditions that controlled pre-deployment testing cannot fully reproduce.

An organization can therefore technically maintain a human audit while steadily reducing the actual strength of the control. That is why I have argued that “human in the loop” is not, by itself, a governance model. The presence of a person somewhere in a workflow tells us very little about whether that person has the authority, information, capacity or responsibility necessary to exercise judgment.

The more important question is not: Did a human review some of the AI's work? It is: What decisions are we allowing AI to influence or make, what could happen if it is wrong, and what evidence tells us the control system is working?

Start with decision rights, not audit percentages

Many AI governance programs begin in the wrong place. They start by choosing an audit percentage: 5%, 10%, 20%. But there is no universally meaningful percentage divorced from the decision being audited.

The NAIC's framework points in a different direction. It says an insurer's controls should be commensurate with the nature of the decision, the potential harm to consumers, the extent of human involvement, the transparency and explainability of the outcome, and reliance on third-party systems or data. Controls for a particular use case should align with the degree of potential consumer harm.

That is fundamentally a risk-based approach.

Before deciding how often humans should review AI decisions, an organization should decide which decisions AI is allowed to make in the first place.

In my work on Decision Debt, I use a three-tier Decision Rights Charter:

  • Delegate. The machine may make the decision because the pattern is stable and the consequence of error is sufficiently controlled.
  • Augment. AI can analyze, recommend, draft or challenge, but a named human owns the decision.
  • Reserve. The decision remains human because it involves values, precedent, people, significant consequences or judgment the organization has deliberately chosen not to delegate.

The audit strategy should follow that decision architecture, not substitute for it.

The NAIC bulletin similarly calls for governance structures that establish scope of authority, chains of command, decisional hierarchies, independence of decision-makers and lines of defense, as well as monitoring, auditing, escalation and reporting protocols.

The question isn't simply whether a human appeared somewhere in the process. It is who had authority to decide.

Audit the control system, not just the outputs

Once decision rights are explicit, sampling becomes much more useful. But an effective audit should test more than whether an individual output was “right.”

An insurer should be able to answer:

  • What type of decision was the AI supporting?
  • Who owned the decision?
  • Which model and version produced the recommendation?
  • What information was available to the system and the human reviewer?
  • How often did humans override the AI?
  • Were errors concentrated around particular products, populations or circumstances?
  • Did complaint patterns change?
  • Did performance change following a model, data or workflow change?
  • What happened when performance moved outside acceptable boundaries?

The NAIC bulletin says regulators examining an insurer's AI use may request inventories and descriptions of AI systems and predictive models, information about data provenance and lineage, measurements and thresholds used in oversight, and documentation of validation, testing and auditing, including evaluation of model drift.

NIST's AI Risk Management Framework Playbook points in a similar direction. Its monitoring guidance recommends documenting the degree of human oversight, maintaining statistics on human overrides, tracking reported errors and complaints, recording adjudication activity, and documenting exceptions and escalation decisions.

That changes auditing from spot-checking answers into testing a control system.

Cadence should follow risk

There is another problem with traditional audit models: cadence is often calendar-driven. Teams review a fixed percentage every week or conduct a larger review every quarter. AI systems do not necessarily change on that schedule.

NIST's current work on deployed AI identifies questions such as what the right monitoring cadence is, whether monitoring should be risk-based, and how automated and human-validated monitoring should interact as important unresolved issues.

That means there isn't a regulatory magic number. There shouldn't be.

A more defensible approach is to establish a baseline review cadence appropriate to the risk and then define conditions that automatically increase scrutiny:

  • A material model change.
  • A meaningful change in underlying data.
  • A spike in human overrides.
  • Unexpected differences across customer populations.
  • Complaints or adverse outcomes.
  • A new product, jurisdiction or use case.
  • Evidence of model drift.
  • Performance outside established tolerances.

Human oversight should expand when uncertainty or potential harm expands.

The reverse matters, too. If an organization reduces review because an AI-supported process has demonstrated reliable performance, it should be able to show the evidence that justified that decision. Trust should be earned by the task, not granted permanently to the technology.

That is the Calibrate portion of the A.R.C. Protocol I use in Decisive AI: continuously measure where AI performs well, expand delegation where performance earns it, and reclaim decision authority when it does not.

What will an examiner actually ask?

We should be careful about predicting the exact questions of a future examination. Regulatory procedures vary by jurisdiction and circumstance. But we do not have to guess about the kinds of evidence regulators are preparing to examine.

The NAIC Model Bulletin says insurers should expect inquiries into their AI governance framework, risk management and internal controls. It identifies documentation regulators may request concerning AI-program implementation, monitoring and audit activities, model inventories, data practices, measurements and thresholds, testing, validation, auditing and model drift.

As of 2026, the NAIC is also developing an AI Systems Evaluation Tool to help regulators gather information in market-conduct, financial-analysis and financial-examination contexts. The NAIC reports that 12 states were piloting the tool as of March 2026, with adoption anticipated at the 2026 Fall National Meeting. The Market Conduct Examination Guidelines Working Group also has an explicit charge to develop examiner guidance for oversight of regulated entities' use of consumer data and models involving algorithms and AI.

So imagine an examiner asks a deceptively simple question: How do you know this is working?

“We have humans review 10%” is unlikely to tell the whole story.

A stronger answer is: We know which decisions AI may make. We know which decisions require human judgment. We know who owns those decisions. We know what we measure. We know where the system fails. We know when humans override it. We know what conditions increase scrutiny. We know what thresholds require escalation. And we can produce evidence showing what we did when those thresholds were crossed.

That is the difference between having humans somewhere in the loop and having an actual governance system.

Build the evidence before you need it

Don't wait for an examination request to reconstruct this story. For every consequential AI use case, an insurer should be able to produce a coherent evidence package showing:

  • Decision authority: what AI can decide, what it can recommend, and what remains reserved for humans.
  • Accountability: the named business and technical owners and the governance body responsible for oversight.
  • Risk classification: why the use case receives the level of oversight it does.
  • Performance: the metrics, thresholds and tolerances used to determine whether the system remains trustworthy.
  • Human interaction: overrides, exceptions, escalations and relevant adjudications.
  • Consumer signals: complaints, adverse outcomes and other evidence that may reveal problems aggregate performance metrics miss.
  • Change history: material changes to models, data, workflows and third-party components.
  • Audit history: what was sampled, why it was sampled, what was found and what changed as a result.
  • Escalation triggers: the conditions under which additional human review, remediation or suspension becomes necessary.

That list isn't intended as a substitute for a company's legal, compliance or regulatory obligations. It is an operating model for making those obligations demonstrable.

Documentation shouldn't be created because an examiner might eventually ask for it. It should exist because the organization itself should already be asking those questions.

The Hidden Decision Debt

There is a final risk in weak AI auditing that may be harder to see.

The decisions appear finished. The claim moved. The underwriting recommendation was accepted. The transaction completed. The dashboard stayed green.

However, if nobody can explain who really owned the decision, why the organization trusted the system, whether the audit cadence was appropriate, or what would cause that trust to be withdrawn, the organization has not eliminated the decision. It has delegated it by accident.

That is Decision Debt: the accumulated cost of decisions that were deferred, degraded or allowed to migrate away from clear human ownership.

AI can reduce that debt. It can also compound it at machine speed.

The difference will not be whether organizations put humans in the loop. It will be whether they deliberately design which decisions remain human, which can be delegated, what evidence earns that delegation, and what evidence takes it away.

Sources / Regulatory References

[1] NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023). https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf

[2] NIST, Challenges in Monitoring Deployed AI Systems (2026). https://www.nist.gov/publications/challenges-monitoring-deployed-ai-systems-center-ai-standards-and-innovation

[3] NIST AI Risk Management Framework Playbook — Measure. https://airc.nist.gov/airmf-resources/playbook/measure/

[4] NAIC, Artificial Intelligence — current regulatory work and AI Systems Evaluation Tool. https://content.naic.org/insurance-topics/artificial-intelligence

[5] NAIC, Market Conduct Examination Guidelines Working Group. https://content.naic.org/committees/d/market-conduct-examination-guidelines-wg


Matthew Arthurs

Profile picture for user MatthewArthurs

Matthew Arthurs

Matthew Arthurs is a lieutenant colonel in the U.S. Army National Guard and a program-delivery executive who has governed large engineering and operations portfolios in regulated industries, including insurtech. 

He is the author of the Decisive Edge series, including "Decisive AI: Reducing Decision Debt and Preserving Human Judgment in the Age of Artificial Intelligence."

Ransomware Trends in 2026 for Cyber Insurers

Ransomware losses now extend beyond file encryption to stolen credentials, cloud compromise and shared dependencies that can accumulate hidden risk.

Ransomware

The file encryptor is becoming the least interesting part of a ransomware loss.

The biggest ransomware trends in 2026 are the shift from file encryption toward data theft, stolen credentials, cloud and infrastructure compromise, AI-assisted activity and cyber insurance accumulation risk. For insurers, this means ransomware increasingly needs to be evaluated as a complete chain of financial loss rather than simply an encryption event.

By the time a ransom note appears, an attacker may already have stolen credentials, explored cloud storage, copied sensitive information and mapped the systems an organization depends on for recovery.

For cyber insurers, that changes the nature of the risk.

Ransomware is increasingly better understood as a chain of connected economic losses. Malware may be only one component. Stolen access, data theft, compromised infrastructure, business interruption, legal obligations and shared dependencies can determine how large an insured loss ultimately becomes.

The insurance question is therefore shifting from simply asking which ransomware variant caused the attack to understanding how access was obtained, what the attacker reached, which dependencies were exposed and where the financial consequences appeared.

What Are the Biggest Ransomware Trends in 2026?

The most important ransomware trends in 2026 involve attackers moving beyond file encryption and targeting the identities, data, infrastructure and shared systems that organizations depend on to operate and recover.

The six major trends are:

  • Data theft can continue creating losses even when files are successfully restored.
  • Stolen credentials and remote-access systems are becoming important parts of the ransomware attack chain.
  • Cloud, virtualization and recovery infrastructure can increase the scale of disruption.
  • AI may increase the speed and scale of reconnaissance, social engineering and vulnerability exploitation.
  • Shared access routes can create accumulation risk across multiple insured organizations.
  • Ransomware recovery increasingly means rebuilding trusted control—not simply restoring files.

For cyber insurers, these developments make the complete loss chain increasingly important when assessing ransomware insurance claims, underwriting exposure and portfolio accumulation.

1. Why May Reported Ransomware Losses Understate the Insurance Risk?

Reported ransomware losses can understate the potential insurance impact because headline figures may exclude business interruption, employee time, remediation and other costs that can become significant components of an insured loss.

According to the FBI Internet Crime Complaint Center's 2025 Annual Report, the FBI received 3,611 ransomware complaints in 2025, with reported direct losses of $32.3 million.

The FBI also identified 63 new ransomware variants, an average of more than five per month.

The top 10 variants accounted for 57% of reported incidents and 50% of reported ransomware losses.

That difference matters.

The variants represented a greater share of incidents than of reported losses, illustrating why ransomware frequency alone cannot determine the financial severity of a particular variant.

There is also a broader measurement problem.

The FBI states that its ransomware loss figure normally excludes categories such as lost business, employee time, wages, files, equipment and third-party remediation. Some organizations provide no loss amount, while incidents reported directly to FBI field offices may not appear in the Internet Crime Complaint Center total.

Threat statistics can count attacks and ransomware variants.

Cyber insurers need to understand something different: which attacks generate covered financial losses, how long those losses continue to develop and whether apparently separate claims share the same underlying cause.

What Does This Mean for Cyber Insurers?

Headline ransomware loss figures should not automatically be treated as estimates of total insured loss.

Business interruption, incident response, privacy liability, data restoration and other covered costs can materially change the financial consequences of an event.

2. Why Is Ransomware Moving Beyond File Encryption?

Ransomware is moving beyond file encryption because attackers increasingly seek access to credentials, cloud environments, virtual infrastructure and sensitive data before or alongside deploying encryption.

One of the most important ransomware trends in 2026 is this expansion beyond traditional endpoint encryption.

A joint advisory from CISA, the FBI and the Australian Signals Directorate states that the ransomware operation known as Play, or Playcrypt, had allegedly affected approximately 900 entities known to the FBI by May 2025.

According to the advisory, the group gained access through methods including stolen or misused credentials, vulnerabilities in Internet-facing systems and tools designed for remote access and technical support.

After entry, the operation combined data theft, file encryption and telephone calls threatening publication of company information.

Play also developed a version capable of disrupting multiple virtual servers rather than attacking files on only one computer.

Separately, a government advisory concerning Interlock ransomware described activity involving searches of cloud storage during data theft and targeting of less commonly monitored systems.

The potential loss is therefore expanding from individual devices toward infrastructure that may support multiple business applications, workloads and recovery systems.

What Does This Mean for Cyber Insurers?

Ransomware is increasingly an access, identity and infrastructure problem as well as an encryption problem.

Controls focused primarily on endpoint protection and backups may therefore provide only a partial picture of potential insured loss.

3. Can Ransomware Data Theft Create Losses After Recovery?

Yes. Ransomware losses can continue after systems are restored because stolen data can still generate legal, regulatory, liability, incident-response and extortion costs.

A working backup may reduce the cost of restoring encrypted files.

It does not necessarily reduce the consequences of ransomware data theft.

Once sensitive information has been copied, an organization may still face:

  • breach-notification obligations;
  • regulatory investigations;
  • legal and incident-response costs;
  • customer claims;
  • potential penalties whose insurability varies by jurisdiction; and
  • continuing extortion pressure.

Restoring information is therefore no longer necessarily the same as ending the financial, legal or insured loss.

An organization may restore every encrypted file while still facing substantial costs because the attacker retains sensitive information.

What Is Data Extortion?

Data extortion occurs when an attacker threatens to publish, sell or otherwise misuse stolen information to pressure an organization into making a payment, even when files have not been encrypted.

This distinction matters because data-only extortion can create notification and liability costs without traditional ransomware encryption.

What Does This Mean for Cyber Insurers?

One ransomware campaign may generate several categories of loss, including:

  • cyber-extortion expense;
  • data restoration;
  • privacy liability;
  • incident response;
  • business interruption; and
  • dependent business interruption.

The key distinction is increasingly between system recovery and financial recovery.

4. Why Are Stolen Credentials Important in Ransomware Attacks?

Stolen credentials matter because they can give attackers legitimate-looking access to systems before ransomware software is ever deployed.

Modern ransomware attacks can begin well before a ransom demand appears.

Attackers may obtain initial access through compromised credentials, vulnerable Internet-facing infrastructure, remote-access tools or access obtained through criminal supply chains.

The ransomware event eventually visible to an insurer may therefore represent only one stage of a longer compromise.

For insurers and risk managers, understanding how access was obtained is becoming increasingly important.

If multiple organizations rely on the same remote-access technology, identity environment, managed service or support infrastructure, one compromised route may potentially expose more than one insured organization.

What Does This Mean for Cyber Insurers?

The relevant ransomware exposure can extend beyond an individual policyholder's security controls.

Insurers may also need to consider the access relationships and technology dependencies connecting insured organizations to external systems and providers.

That becomes particularly important when evaluating portfolio-level cyber accumulation.

5. How Is AI Changing Ransomware Attacks in 2026?

AI may make ransomware operations faster and more scalable by assisting reconnaissance, vulnerability research, social engineering and analysis of stolen information, although current government assessments do not suggest that advanced attacks are becoming fully autonomous.

Artificial intelligence also presents a measurement challenge.

According to the FBI's 2025 Internet Crime Complaint Center report, the agency received 22,364 complaints containing AI-related information across all crime categories, with reported losses exceeding $893 million.

Yet only 16 ransomware complaints carried an AI reference, and those references recorded no adjusted ransomware loss.

That does not establish that AI is absent from ransomware activity.

In the FBI reporting framework, AI is an additional descriptor applied when reported information includes a reference to artificial intelligence. Each complaint still receives one primary crime category.

An AI-assisted attack that eventually results in ransomware may therefore be recorded primarily as ransomware, making AI's contribution difficult to isolate from the available complaint data.

The UK National Cyber Security Centre (NCSC) expects AI to strengthen activities including:

  • reconnaissance;
  • vulnerability research;
  • social engineering;
  • basic malware creation; and
  • analysis of stolen information.

The NCSC also expects AI to reduce the already narrow period between vulnerability disclosure and exploitation.

However, it assesses that fully automated advanced cyberattacks are unlikely through 2027, with skilled human involvement expected to remain important.

What Does This Mean for Cyber Insurers?

The near-term insurance concern is more likely to be human-machine collaboration than fully autonomous ransomware attacks.

AI could allow the same criminal workforce to evaluate more potential targets, process information more efficiently and move through parts of the attack chain faster.

From an insurance perspective, AI may consequently operate as a frequency and velocity multiplier even when it does not appear as a separately identifiable cause of loss.

6. How Can Ransomware Create a Cyber Catastrophe Through Ordinary Claims?

Ransomware can create a catastrophe gradually when multiple organizations are compromised through the same underlying access route but the resulting claims appear on different dates, in different industries and under different ransomware names.

Traditional catastrophe thinking looks for one event producing many claims at approximately the same time.

Ransomware can accumulate differently.

A criminal may break into numerous organizations through one weak remote-support product and then sell that access to different ransomware groups.

Those groups can attack different industries on different dates and use different ransomware names.

Europol's Operation Endgame targeted services used to open these routes into victims, illustrating the criminal supply chain that can sit before the ransom demand.

A joint government warning about Play highlights another complication: the group can modify its ransomware for each target, causing attacks from the same operation to appear technically different.

What Is a Serial Cyber Catastrophe?

A serial cyber catastrophe is an insurance interpretation in which a shared underlying cyber-access event produces multiple losses gradually rather than creating all claims at the same time.

This is an analytical description rather than a formal government classification.

The common cause may occur when access is first established, while the resulting insured losses emerge gradually, affect different organizations and appear under different ransomware identities.

The portfolio question therefore becomes:

How many insured organizations could be reached through the same access route before that route is identified and closed?

That is different from simply asking how many insureds use the same technology provider.

The U.S. Government Accountability Office (GAO) has warned that private cyber insurance and the federal terrorism insurance backstop may both have limited ability to absorb catastrophic losses from a widespread cyberattack.

A series of apparently ordinary ransomware claims can therefore carry a larger accumulation problem.

7. Why Is Ransomware an Accumulation Risk for Cyber Insurers?

Ransomware creates accumulation risk when multiple insured organizations can suffer losses because they share a common vulnerability, technology dependency, provider, identity system or access route.

What Is Ransomware Accumulation Risk?

Ransomware accumulation risk is the possibility that one underlying cyber weakness or dependency contributes to losses across multiple insured organizations.

One vulnerability, service provider, identity system, access broker or technical dependency could potentially contribute to losses across multiple organizations.

Yet those losses may not occur simultaneously.

This can make cyber accumulation more difficult to identify than a traditional physical catastrophe, where geographic concentration and the timing of losses may be more immediately visible.

What Does This Mean for Cyber Insurers?

A collection of apparently ordinary ransomware insurance claims could conceal a larger portfolio-level accumulation problem.

Insurers may therefore need to examine not only individual insured controls but also:

  • shared access mechanisms;
  • common technology dependencies;
  • identity infrastructure;
  • managed service relationships; and
  • concentration across critical providers.

This is where ransomware begins to move from an individual claims problem toward a portfolio risk-management problem.

8. How Does Ransomware Affect the U.S. Cyber Insurance Market?

Ransomware can produce different insured outcomes in the United States because cyber coverage is distributed across endorsements, primary policies and excess policies with different structures and attachment points.

Cyber insurance coverage is not delivered through one uniform policy structure.

According to the National Association of Insurance Commissioners' 2025 Report on the Cybersecurity Insurance Market, among U.S.-domiciled insurers, endorsements represented 55% of cyber policies in force during 2024 but only 4% of direct written premium.

Primary policies represented 42% of policies and 65% of premium, while excess policies represented 3.3% of policies but 31% of premium.

Ransomware losses therefore enter the U.S. insurance system through materially different policy structures.

A single campaign may potentially produce losses involving:

  • cyber-extortion expenses;
  • data restoration;
  • privacy liability;
  • business interruption;
  • dependent business interruption; and
  • disputed crime losses.

Data-only extortion can also generate notification, legal and liability costs even when encryption never occurs.

What Does This Mean for Cyber Insurers?

The same ransomware event can create materially different insurance outcomes depending on policy structure and the categories of loss triggered.

The financial outcome can vary depending on:

  • policy wording;
  • attachment point;
  • coverage structure;
  • organization type;
  • nature of the compromise; and
  • resulting loss categories.

Understanding the cyber event alone may therefore be insufficient without understanding how that event interacts with the insured's coverage.

9. How Can International Regulation Affect Ransomware Losses?

International regulation can change ransomware loss development by affecting reporting deadlines, ransom-payment options, legal exposure and incident-response obligations for multinational organizations.

Regulatory developments outside the United States are therefore relevant to insurers covering multinational organizations.

Under proposed UK cyber-resilience legislation, certain essential, managed and digital service providers would be required to alert regulators within one day and provide a more detailed account within three days.

The proposed scope also reaches some pre-positioning activity that has not yet caused direct damage but could produce serious consequences.

The UK has separately considered a targeted ransomware payment ban for public-sector and regulated critical-infrastructure organizations, although no final decision had been announced in the government's latest formal response cited in this analysis.

Updated UK sanctions guidance also warns that facilitating payment to a designated party may create civil or criminal exposure.

What Does This Mean for U.S. Cyber Insurers?

These UK developments do not represent U.S. regulatory requirements, but they can still affect U.S. insurers covering multinational organizations.

A single ransomware campaign can create different:

  • reporting timelines;
  • payment options;
  • response obligations;
  • legal costs; and
  • insured outcomes

depending on the affected organization's jurisdiction and sector.

10. Why Are Backups No Longer Enough for Ransomware Recovery?

Backups are no longer enough on their own because restoring files does not guarantee that credentials, cloud environments, administrator accounts and recovery systems can be trusted again.

Another major ransomware trend in 2026 is therefore the changing meaning of recovery.

Backups may exist but remain reachable through the same compromised identity system.

Files may be restored while an attacker retains valid credentials.

Virtual machines may return while cloud access, administrator accounts or transaction records remain untrusted.

UK ransomware guidance notes that ransom payment does not guarantee restoration.

The guidance also describes circumstances in which organizations recovered after payment only to experience another infection because another actor was able to exploit the same underlying vulnerability.

What Is Trusted Recovery?

Trusted recovery means restoring operations while also establishing confidence that compromised access, identities and infrastructure have been removed or secured.

Cyber resilience therefore involves more than restoring files.

Organizations may need to rebuild a trusted operating environment while simultaneously managing:

  • business interruption;
  • stolen data;
  • legal obligations;
  • compromised credentials;
  • continuing extortion pressure; and
  • incident-response costs.

What Does This Mean for Cyber Insurers?

Two organizations with similar backup and security controls can still experience materially different ransomware losses if attackers reached different levels of identity, infrastructure or recovery access.

The difference may depend on how deeply attackers penetrated systems and how confidently the organization can re-establish trusted control.

What Do Ransomware Trends in 2026 Mean for Cyber Insurers?

For cyber insurers, ransomware trends in 2026 mean that risk assessment needs to move beyond malware variants and ransom payments toward the complete chain of access, data theft, infrastructure compromise, interruption and portfolio dependency.

The defining change in ransomware is its expansion into a modular system connecting:

  • initial access;
  • stolen credentials;
  • access brokers;
  • cloud data;
  • infrastructure control;
  • AI-assisted activity;
  • business interruption; and
  • financial coercion.

For cyber insurers, the meaningful unit of analysis is no longer simply the ransomware variant.

It is the complete loss chain.

Insurers increasingly need to understand:

How was access obtained?

What level of authority did the attacker reach?

Which infrastructure and recovery systems were exposed?

Which dependencies were shared with other organizations?

What information was removed?

Where did the financial consequences emerge?

Could the same access route produce additional claims elsewhere in the portfolio?

Until that chain becomes visible, ransomware may look manageable one policy at a time while accumulation develops quietly across the portfolio.

For insurers assessing ransomware trends in 2026, that may be the most important change of all.

Frequently Asked Questions About Ransomware Trends 2026

Which Cyber Insurance Coverages Can a Ransomware Attack Trigger?

A ransomware attack can potentially trigger cyber extortion, incident response, data restoration, privacy liability, business interruption and dependent business interruption coverage, depending on the policy wording and the nature of the loss.

Why Can Two Companies Experience Different Ransomware Losses?

Two companies can experience different ransomware losses because attackers may reach different systems, identities, data and recovery environments, even when both organizations have similar security controls.

Why Can Ransomware Statistics Differ From Actual Insured Losses?

Ransomware statistics may not reflect the full insured loss because reported figures can exclude business interruption, employee time, remediation and other financial consequences.

How Can Shared Technology Increase Ransomware Exposure?

Shared technology can increase ransomware exposure when multiple organizations rely on the same provider, identity system, remote-access technology or infrastructure that attackers can compromise through a common access route.

Can a Ransomware Claim Continue After Systems Are Restored?

Yes. A ransomware claim can continue after systems are restored because stolen data, regulatory obligations, legal costs, customer claims and extortion pressure may still remain.

What Should Cyber Insurers Examine Beyond the Ransomware Variant?

Cyber insurers should examine how attackers gained access, what authority they obtained, which systems and data were reached, which dependencies were involved and where the financial consequences appeared.

Why Does the Initial Access Route Matter to Cyber Insurers?

The initial access route matters because one compromised credential, remote-access product or shared service can potentially expose multiple insured organizations and create connected claims.

Research Methodology and Editorial Approach

This article prioritizes primary government, regulatory, supervisory and law-enforcement evidence and clearly separates source-reported facts from insurance analysis.

Primary sources include material from:

  • the FBI Internet Crime Complaint Center;
  • the Cybersecurity and Infrastructure Security Agency (CISA);
  • the National Association of Insurance Commissioners (NAIC);
  • the U.S. Government Accountability Office (GAO);
  • the UK National Cyber Security Centre (NCSC);
  • Europol; and
  • the UK Government.

Quantitative claims are traced to original or primary sources wherever possible.

Vendor-produced ransomware telemetry and vendor-produced market research were not used as the basis for the quantitative claims in this article.

Where the article moves beyond reported facts to discuss implications for insurance claims, underwriting or portfolio accumulation, those conclusions are presented as insurance analysis rather than as findings attributed to the underlying government source.

International evidence is identified separately where relevant and is not presented as though it represents U.S. law or regulation.

Sources

FBI Internet Crime Complaint Center — 2025 Annual Report

https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

Used for ransomware complaint volume, reported ransomware losses, ransomware variant data, AI-related complaint statistics and limitations in reported ransomware loss figures.

CISA, FBI and Australian Signals Directorate — Play Ransomware Advisory

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a

Used for Play/Playcrypt ransomware activity, compromised credentials, remote-access exploitation, data theft, encryption and victim-specific ransomware behavior.

CISA, FBI and Partners — Interlock Ransomware Advisory

https://www.cisa.gov/sites/default/files/2025-07/aa25-203a-stopransomware-interlock-072225.pdf

Used for Interlock ransomware activity, cloud-storage access, data theft and targeting of less commonly monitored systems.

CISA — StopRansomware Guide

https://www.cisa.gov/stopransomware/ransomware-guide

Used for ransomware prevention, response and recovery context.

UK National Cyber Security Centre — Impact of AI on Cyber Threat to 2027

https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027

Used for AI-assisted reconnaissance, vulnerability research, social engineering, malware development, stolen-data analysis and the expected role of humans alongside AI.

Europol — Operation Endgame Targets the Ransomware Supply Chain

https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source

Used for criminal access infrastructure, ransomware supply-chain activity and access routes used before ransomware deployment.

National Association of Insurance Commissioners — 2025 Report on the Cybersecurity Insurance Market

https://content.naic.org/sites/default/files/inline-files/2025_Cybersecurity_Insurance%20Report.pdf

Used for U.S. cyber insurance policy structure, endorsements, primary and excess cyber policies and direct written premium distribution.

U.S. Government Accountability Office — Federal Response to Catastrophic Cyberattacks

https://www.gao.gov/products/gao-22-104256

Used for catastrophic cyber-loss considerations, private cyber insurance capacity and potential limitations of federal and private-sector mechanisms for widespread cyber events.

UK Government — Cyber Security and Resilience Bill: Incident Reporting

https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/incident-reporting

Used for proposed cyber incident-reporting requirements, reporting timelines and regulatory developments affecting cyber-loss response.

UK Government — Financial Sanctions Guidance for Ransomware

https://www.gov.uk/government/publications/financial-sanctions-guidance-for-ransomware/financial-sanctions-guidance-for-ransomware

Used for ransomware-payment sanctions considerations and potential legal exposure when dealing with designated parties.

UK Government — Government Response to Ransomware Legislative Proposals

https://www.gov.uk/government/consultations/ransomware-proposals-to-increase-incident-reporting-and-reduce-payments-to-criminals/outcome/government-response-to-ransomware-legislative-proposals-reducing-payments-to-cyber-criminals-and-increasing-incident-reporting-accessible

Used for proposed ransomware-payment restrictions, incident-reporting policy and government positions on ransomware-payment regulation.

UK National Cyber Security Centre — Recovering from a Highly Disruptive Cyberattack

https://www.ncsc.gov.uk/collection/what-to-do-when-cyber-attacks-disrupt-your-organisation/recovering/recovering-ongoing-investigations

Used for cyber recovery, rebuilding trusted systems, continuing investigation after disruption and risks that remain after systems are restored.

Insurance's Gap in Identity Security

Partner ecosystems are the identity security gap that most financial institutions, including insurers, have yet to close. 

Third-Party and Partner Access in Banking: Can FIDO Scale Beyond Employees?

Insurers and banks have invested significant effort in securing internal employee and customer access. Internal access now uses phishing-resistant multi-factor authentication (MFA), whereas consumer and policyholder-facing applications have shifted toward passkeys and passwordless access. It is usually the middle of this stack that is weak: MGAs, brokers, reinsurers, claims vendors, auditors, consultants, and external contractors all log into carrier and bank infrastructure under significantly less stringent conditions.

There are numerous examples of third-party access to financial services infrastructure based on outdated authentication methods, common passwords, manual user creation, and a general lack of governance controls. The exposure to that risk increases rapidly as partner ecosystems grow and cloud integration deepens, and insurance carriers, with their dense networks of agents, brokers, and claims partners, are as exposed as any bank.

That gap is becoming harder to ignore because the identity surface itself is expanding rapidly. Research from Enterprise Strategy Group (ESG), commissioned by Thales, found that 74% of BFSI organizations, spanning banking, insurance, and financial services, report third-party identities growing faster than employee identities, with third-party identity volumes projected to grow 37% over the next 12 months. At the same time, 89% say they already have a prioritized strategy to modernize identity solutions used by contractors and partners.

The question is: what standard should financial institutions adopt?

The Partner Access Model is Already Failing at Scale

The operational signals emerging from partner identity environments increasingly look like security warnings.

The 2026 Thales Digital Trust Index found that 92% of partner users experienced access issues with external partner systems during the last 12 months. Only 22% received login access immediately when starting with a new partner relationship. More concerning, 66% admitted to sharing or borrowing credentials, with 53% blaming slow official access processes.

These figures are often viewed as productivity issues. In reality, they highlight an identity control model under operational stress. Shared credentials eliminate traceability, making it difficult to distinguish between legitimate and compromised activity.

The same report found that 71% of partner users were worried about maintaining access they no longer needed, and only 19% said access changes were implemented as soon as responsibilities changed. This joiner-mover-leaver problem extends beyond the enterprise perimeter.

ESG’s BFSI research reinforces the point. Lifecycle management across disconnected systems, compliance reporting across identity boundaries, and deprovisioning identities when no longer needed were all ranked among the top third-party identity and access management (IAM) challenges by respondents.

Governance gaps are operational, structural, and currently exist at scale.

Third-Party Access Now Maps Directly to the Attack Surface

When the identity trends map to attack data, the security concerns become more evident. The 2026 Thales Data Threat Report: Financial Services Edition found that, according to 70% of those surveyed, the top emerging attack technique targeting cloud infrastructure in the financial sector is credential theft and the misuse of secrets.

Vulnerabilities originating from third parties, including external code and APIs, ranked second at 65%. Third-party vendor networks also ranked among the top attack targets for financial services organizations. Businesses are building connected SaaS ecosystems, fintech integrations, outsourced capabilities, and cloud processes even as credential-based attacks continue to skyrocket.

Yet the authentication layer protecting many of those external connections is inconsistent, which fuels risk because attackers don’t distinguish between employee and partner credentials.

The threat environment further complicates the issue. According to the Thales Bad Bot Report for 2026, the financial services sector accounted for 46% of account takeovers in 2025, even though it makes up just 24% of all bot attacks worldwide. In addition, there has been a 70% increase in account takeovers from July 2024 to July 2025.

Banks understand they need phishing-resistant authentication internally, and the same logic should apply to partner ecosystems.

Why FIDO Fits the Partner Authentication Problem

The value of fast identity online (FIDO) in partner access scenarios is not simply stronger MFA. It is the removal of the shared secret itself.

Passwords, OTPs, and reusable credentials create a transferable authentication artifact that can be stolen, replayed, borrowed, or phished. FIDO-based authentication replaces that with cryptographic key pairs tied to the user, device, and relying party domain. There is nothing to steal, share, or replay.

For banks that rarely control the identity infrastructure their partners use, FIDO's open standard design means strong authentication can extend beyond the corporate IAM perimeter without requiring partners to adopt the bank's full identity stack.

Not Every Partner Requires the Same Assurance Level

Partner authentication is not a single-tier problem. The right credential depends on what the partner can access and the consequences of a compromise.

For lower-risk external relationships, such as broad partner networks, suppliers, and fintech integrations where the priority is reducing friction and eliminating shared passwords, synced passkeys operating at AAL2 are a practical starting point. They raise the authentication bar without imposing hardware requirements across a diverse and distributed partner base.

For higher-risk access, device-bound hardware security keys at AAL3 are the appropriate standard. Auditors in controlled environments, privileged contractors, external administrators, and partners with direct access to regulated financial data are scenarios in which the bank's compliance posture is contingent on the partner's authentication holding. Synced passkeys, which can move between devices, do not provide that assurance.

Matching credential strength to access risk is not a novel principle. NIST SP 800-63B formalizes it through the AAL2 and AAL3 assurance levels that already underpin most phishing-resistant MFA frameworks.

Authentication Alone Will Not Solve the Governance Problem

Deploying FIDO in partner ecosystems without addressing lifecycle management extends the existing vulnerabilities rather than closing them. Delayed provisioning increases the likelihood of credential reuse; absent deprovisioning, access remains in place long after it is needed. The 2026 Thales Digital Trust Index found that only 19% of partner users see access changes implemented immediately after responsibilities change, and 66% retain access they no longer need.

Banks still need automated provisioning, entitlement management, and revocation across siloed systems — and the regulatory pressure to get this right is building. DORA, NIS2, and PSD2 all treat third-party access management as an institutional liability, not a partner problem. The ESG research found compliance and regulatory mandates were the primary driver of third-party identity modernization for 46% of BFSI respondents.

Choosing the Right FIDO Enrollment Model

Large-scale FIDO key enrollment typically follows one of three models.

In admin-driven enrollment, IT centrally configures and issues security keys before delivery, giving full control over credentials and setup policies. This is well-suited to large, time-sensitive deployments.

Self-service enrollment lets users configure their own key through a portal within defined policy parameters, reducing IT overhead but requiring a well-designed process and investment in user communications.

Vendor-managed enrollment goes furthest: keys are pre-registered before shipping, so recipients receive a device that is already enrolled and ready to use, with no IT involvement at the point of receipt.

A large automotive organization used this third model to deploy FIDO security keys to employees and contractors at scale. Using a centralized authenticator lifecycle management platform, it bulk-enrolled security keys into its internal identity providers before distribution, then shipped pre-registered keys directly to contractors and partners. The result was a faster rollout and a consistent authentication experience across a distributed user base, without placing the enrollment burden on internal IT teams.

The Next Step in Identity Security

FInancial institutions that treat partner authentication as a downstream problem will find it becomes an immediate one. Credential data theft, access failure rates, and the regulatory trajectory all point in the same direction. Phishing-resistant authentication is already the standard for employees. Extending it to partner ecosystems completes the strategy.

How Convective Storms Are Changing Insurance

Hyperlocal weather intelligence is helping insurers respond faster, improve claims accuracy, and better serve policyholders in an era of increasingly severe storms.

Why Severe Convective Storms Are Changing Insurance

Two homes on the same street can experience completely different outcomes from the same storm. One loses its roof and siding to wind-driven hail, while another just blocks away escapes with little more than cosmetic damage. For insurers, those stark differences create one of the industry's most difficult operational challenges: determining exactly what happened at a specific property, often within hours of the storm.

Unlike hurricanes that leave broad swaths of destruction, or floods that generally follow predictable topography, severe convective storms — including tornadoes, hail, damaging straight-line winds, and severe thunderstorms — produce highly localized, rapidly evolving damage that defies broad assumptions. Every claim requires a more precise understanding of where a storm struck, how it behaved, and what conditions a particular property actually experienced.

As another active tornado season comes to a close, insurers are confronting a reality that extends well beyond this year's losses. While severe convective storm losses exceeded $20 billion for the 11th consecutive year, they remained below both the five- and 10-year averages. At the same time, states like Illinois experienced a record-breaking season, with a preliminary estimate of 220 tornadoes so far in 2026, reinforcing widespread media coverage and a heightened perception of risk among homeowners and businesses alike.

As severe convective storms become an increasingly persistent source of insured losses, competitive advantage will depend less on understanding regional weather patterns and more on translating property-level weather intelligence into faster decisions, smarter claims handling, and stronger customer trust.

From Regional Forecasts to Property-Level Intelligence

Severe convective storms often produce remarkably uneven damage, and those sharp variations complicate nearly every stage of the insurance lifecycle.

Underwriters need to evaluate risk with greater geographic precision. Claims teams must determine exactly which properties experienced effects like damaging winds, hail, or tornado impacts. Catastrophe response teams have to deploy adjusters where they're actually needed instead of relying on county-wide assumptions. Even customer communications become more nuanced when two policyholders living minutes apart experience dramatically different outcomes.

Traditional catastrophe models remain essential, but they weren't built to answer property-level questions on their own. Meeting that challenge requires a more granular view of the weather.

Advances in radar, satellite imagery, lightning detection, and high-density weather observation networks now give insurers a far more detailed picture of developing storms than was possible only a few years ago. Combined with convective-allowing models capable of forecasting storms at kilometer-scale resolution, these technologies help insurers move beyond generalized forecasts to understand how a storm is likely to affect individual communities down to the street.

This level of precision transforms insurers’ operational decision-making.

Instead of waiting on claims to arrive, carriers can identify areas most likely to experience significant hail or tornado damage, position field adjusters in advance, prepare call centers for increased demand, and communicate with policyholders before the first inspection is scheduled.

The advantage is faster, more informed action.

Why Every Minute Matters

During severe convective storm outbreaks, timing can significantly influence both operational costs and customer experience.

Receiving reliable weather intelligence just 30 minutes before a major hail event can give insurers enough time to staff call centers, mobilize claims personnel, and begin communicating with policyholders before call volumes surge.

That kind of lead time can make a meaningful difference during events like the record-breaking 6-inch hailstones that struck the heavily populated Kankakee, Ill., area on March 10, 2026, when insurers can become inundated with claim spikes and overwhelmed call queues within minutes. Near-real-time radar updates and rapidly refreshing weather observations allow operational teams to adjust as storms evolve, reducing delays and improving response times when customers need support most.

Because warnings often involve life-threatening situations, insurers appropriately rely on official warnings issued by the National Weather Service rather than issuing independent alerts. Their opportunity lies elsewhere: helping policyholders understand changing conditions in the hours leading up to severe weather and rapidly mapping paths afterward to prioritize claims response and inspection resources.

The objective isn't replacing public safety messaging. That is still very much a fundamental part of the equation. Instead, it's to deliver faster, more informed service when every minute counts.

Smarter Claims Through Better Weather Intelligence

The true value of hyperlocal weather intelligence becomes clear after the storm passes.

Historically, claims investigations often relied on manual inspections across entire affected areas. Today, combining hyperlocal weather intelligence with policyholder data allows insurers to prioritize inspections where uncertainty is highest while accelerating straightforward claims supported by high-confidence weather evidence.

This targeted approach improves efficiency without sacrificing accuracy. Instead of dispatching adjusters to every reported loss, insurers can focus experienced personnel on the most complex claims while using verified weather intelligence to streamline simpler cases. The result is faster settlements, lower operational costs, and a better experience for policyholders recovering from severe weather.

The same intelligence also strengthens claims verification and fraud detection by providing objective evidence of conditions at a specific location. When weather observations, radar signatures, and storm reports align with reported damage, insurers gain greater confidence in claims decisions. When they don't, insurers can investigate further before making unnecessary payments.

Artificial intelligence is making these insights even more actionable. Instead of relying on broad alerts, insurers can tailor communication based on individual property characteristics and prior customer interactions.

A homeowner with outdoor furniture, solar panels, or trees close enough to threaten nearby houses may receive different preparedness guidance than another policyholder nearby. By making communication more relevant, insurers can encourage risk reduction, reduce alert fatigue, and strengthen trust before severe weather strikes.

Building Trust in an Era of Localized Risk

This year's tornado season shows a broader transformation taking place across the insurance industry.

Although severe convective storm losses remained below recent averages, public attention surrounding tornado outbreaks reinforced a heightened sense of risk. That creates both a challenge and an opportunity for insurers.

Policyholders expect faster communication, quicker claims decisions, and greater transparency about how coverage decisions are made. Meeting those expectations requires more than better catastrophe models. It requires turning property-level weather intelligence into faster operations, clearer communication, and more confident decision-making.

As severe convective storms continue to reshape the insurance landscape, competitive advantage will belong to carriers that combine scientific precision with operational agility. Every storm creates thousands of property-level decisions, and the ability to make them quickly, accurately, and confidently is becoming one of the defining capabilities of modern insurance.

Good Recruiting Can't Fix Broken Onboarding

Most new insurance producers fail within two years, not from poor recruiting but from inadequate onboarding and operational support.

Good Recruiting Can't Fix Broken Onboarding

Some insurance insiders estimate that 70% to 80% of new producers fail within their first one to two years. That failure rate has mostly held steady over the years, through cycle after cycle of agencies adjusting their approach to recruitment. Too often, the industry's response has been to focus on attracting more candidates or increasing commissions and bonuses to keep them. But most new agents don't leave because the pay isn't competitive. They leave before they've developed the confidence, skills, and understanding of the opportunity that would allow them to succeed in the first place.

I've spent my career trying to solve this challenge, first managing operations at a large HR software company and now in the insurance industry. Across both experiences, I've seen the industry continue to treat a development problem as a recruiting problem. As long as the focus remains on getting people through the door instead of equipping them to thrive once they're there, the outcome is unlikely to change.

What Breaks in the First Few Weeks

In many industries, day one begins with familiar employment paperwork, basic systems access, and a clearly defined orientation. For a new insurance agent, it can begin with state licensing requirements, carrier appointments, product training, compliance rules and several unfamiliar technology platforms. Product knowledge in this business spans a wide range of technical topics demanding extreme attention to detail. Producers have to know availability information by state, pre-existing condition details, coverage limitations, and exception clauses. For someone who walked in energized about building a career helping people, those first few weeks can feel like drinking from a firehose with no clear end in sight.

That's usually where the breakdown begins, and it's almost always rooted in the same gap between what agents were recruited to do versus how they're actually spending their time. Instead of helping clients and building a book, they're chasing down answers to basic process questions, hunting for the right form, trying to decode systems nobody walked them through. Operational friction drains their energy fast, and most agency leadership doesn't see it happening until it’s too late.

I've watched this play out in a specific, recurring way. A new agent is three weeks in, eager, starting to build a real pipeline. A prospect asks a question they don't know the answer to. They go looking for a resource that should exist and can't find it. They ask around, and it's unclear who actually owns the answer, so the question bounces from person to person without resolution. By the time they track down the right information, the follow-up window has closed, and the client has moved on. In one fell swoop, that agent lost a sale and lost confidence that the agency was built for them to succeed.

String a few of those together, and new agents’ mentality shifts. Staying starts to feel more costly than leaving. Over and over, the industry loses people with genuine potential because the infrastructure around them failed at a critical moment.

Why We Keep Solving the Wrong Problem

In my previous position, I observed onboarding processes while running them internally for a workforce of around 1,600 people, and also while delivering onboarding technology to tens of thousands of businesses across other industries. That dual view made it clear to me that onboarding gets treated as an administrative task only by organizations that haven't yet connected it to their own retention and productivity numbers. Well-advised companies, on the other hand, treat it as a business-critical function, with role-specific training tracks, clear 30-, 60-, 90-day expectations, and feedback loops built to surface problems before they lead to attrition.

Insurance largely hasn't made that connection yet. When I moved into this industry, the product complexity didn't surprise me, but what did was the cultural assumption that new agents would simply figure it out on their own — that hunger alone was enough to carry someone through. To be fair, some people do find their own way. But when an industry designs onboarding around the few people who can succeed with little guidance, it quietly writes off many others who could have become strong producers with the right support.

That gap explains why the industry's default response to turnover -- higher commissions and signing bonuses -- keeps underperforming. Compensation matters, but it cannot overcome a chaotic daily experience. Higher commissions do not help an agent locate the correct form, understand a carrier requirement or get a timely answer for a client. Without the training and accountability to support quality production, aggressive compensation can also encourage volume before competence. Without accountability to quality or continuing education, high earning potential is a short-sighted trade. If agents aren't grounded in the value they're supposed to deliver, agencies risk building a culture that rewards volume over outcomes, and that damages clients and agency reputation alike.

If you talk to agents who left in that first year, compensation is rarely what they emphasize. What comes up instead is a distinct lack of early support. “I didn't know what I was supposed to be doing.” “I felt like I was on my own by week two.” A signing bonus doesn't change someone’s daily experience when they can't get an answer and nobody is around to help. It just means they were paid a little more in the short time before they left.

Insurance Can't Afford to Keep Getting This Wrong

The industry cannot keep absorbing this problem. Insurance's workforce skews older than almost any comparable field: 1.4 million professionals are 55 or older, while only 214,000 fall between 20 and 24. Every new agent lost to friction that a better first 90 days would have prevented is more consequential than ever.

Luckily, we have a solution proven across other industries. It's mapping a new agent's experience with the same rigor agencies already apply to a client's journey. It is paying attention to touchpoints, handoffs, and moments that build or erode trust, and closing whatever gaps surface. Fortunately, agencies don't have to invent a new model. Other industries have already demonstrated what effective onboarding looks like. The most successful programs don't overwhelm new hires with information. They create structure, reinforce learning, and remove unnecessary friction before it becomes frustration.

For insurance agencies, that means focusing on a handful of operational priorities during the first 90 days:

  • Clarify ownership. Every new producer should know exactly where to go for product questions, carrier issues, licensing concerns, and technology support. Back that structure with a centralized knowledge base and dedicated training resources that provide consistent guidance, reinforce best practices, and help producers build the skills they need to succeed.
  • Reduce the time spent searching. Forms, carrier guides, compliance resources, and process documentation should be organized so agents can find answers without relying on tribal knowledge. AI-powered search tools can further streamline access by surfacing relevant answers and resources without requiring producers to know exactly where to look.
  • Build confidence before independence. New producers need a defined path to competency, supported by formal check-ins, structured coaching, regular feedback, and opportunities to practice. Clear milestones help ensure they're ready to operate independently rather than being expected to figure it out on their own.
  • Measure the onboarding experience. Agencies routinely track sales metrics but rarely measure how efficiently new producers progress through these stages or where they encounter friction. The first 90 days should be managed and evaluated with the same discipline as any other business process.

The goal isn't to eliminate complexity. Insurance will always be a complex business. The goal is to ensure that operational complexity doesn't become an unnecessary barrier between motivated new agents and the careers they came to build.