Download

From reactive to proactive: How Westfield is helping homeowners prevent catastrophic losses before they occur

Smart sensors in the home provide water-leak and fire alerts. Westfield is piloting these sensors in multiple states, bolstering agents’ loss-prevention services to homeowners.

Westfield

The average consumer views insurance as a reactive product. A pipe bursts. A fire starts. They file a claim, and their carrier helps them to recover and rebuild.

That captures the core of the insurance value proposition, but it overlooks a key element: the role insurers play in preventing losses before they happen. This is critically important. Few homeowners realize there are simple, effective steps they can take to protect their homes from these losses.

As customer expectations evolve and preventable losses continue to impact homeowners, insurers across the industry are beginning to rethink their role — not simply as organizations that pay covered claims but as organizations that help customers avoid losses altogether.

Recognizing this shift, we’ve expanded our portfolio of risk management tools and resources — including two smart sensors, Ting (electrical fire prevention) and LeakBot (leak detection) — to help policyholders[1] identify hidden risks and intervene before losses occur. 

“Helping customers recover after a loss will always be at the heart of what we do,” says Corey Vigliucci, AVP of sales and underwriting for Westfield Personal Lines. “But if we can help prevent that loss from happening in the first place, that’s an even better outcome. That’s why we’re investing in practical solutions that help homeowners and farm owners identify hidden risks before they become losses. It’s another way we’re helping protect what matters most.[2]”

Here’s what that looks like in action.

Ting: Preventing electrical fires

Every 10 minutes, a family in the United States is impacted by an electrical fire. The average electrical fire claim costs approximately $215,000, according to Triple-I, and that’s only the financial damage. The emotional devastation homeowners face when losing their home to a fire is immeasurable.

To help homeowners mitigate the risk of devastating electrical fires, we worked with Ting Labs to offer Ting, its electrical fire prevention system, to all its eligible personal lines and farm insurance policyholders.

Ting detects hidden electrical hazards before they escalate into fires. The system combines a smart sensor, a mobile app, an advanced signal analysis and a fire safety team that works with homeowners in real time to help identify and mitigate risks.

Simple by design, the smart sensor plugs into any standard outlet and uses advanced technology to identify electrical arcing, faulty wiring, failing outlets and other hidden hazards that homeowners might never detect.

On average, Ting sends fire hazard alerts to approximately one in 60 homeowners each year. About one in 27 of those alerts would have resulted in a fire if the hazard had remained undetected.

The value extends beyond homeowners. These tools also help equip agents to have more proactive risk management conversations with customers.

“This investment also creates meaningful value for our agents by equipping them to have more proactive risk management conversations with customers,” said Dave Ruppel, AVP of sales and underwriting for Westfield Agribusiness. “By identifying potential issues before a loss occurs, agencies can reinforce their role as trusted advisors, deepen customer relationships and help improve long-term customer retention.”

Matthew Boyert, CEO and founder of Boyert Insurance Group, experienced the benefits of Ting firsthand. One day, while meeting with a client, Boyert received a Ting alert on his phone that read, “Fire detected!” 

“I rushed home with my heart beating at 100 miles an hour,” he recalls. He immediately called the Ting support team and learned the alert was for a potential fire hazard.

When Boyert arrived home, a Ting representative helped him isolate the issue, which turned out to be an electrical outlet with loose wiring that was actively arcing.

“If I didn’t have that device, I would not have known there was arcing that could have caused a catastrophic fire,” Boyert reflects. “We could have lost our house, our memories, everything.”

Stories like this resonate with homeowners and help reinforce the importance of proactive risk management.

Matthew Mangus, president of Miller’s Insurance Agency, has seen what happens when electrical fire hazards go undetected. In the past two years, he has seen two clients lose their homes in fires caused by electrical failures.

“I’ve met with clients two days after their homes burned down,” he reflects. “Seeing their mindset as they figure out what to do next is heartbreaking.”

Since launching its Ting offering in May 2024, we’ve enrolled more than 21,000 Westfield customers in the program. During that time, we’ve identified nearly 200 potential “saves” across both electrical and utility fire hazards, including panel failures, faulty outlets and wiring issues.

LeakBot: Tackling hidden water losses

Although fire presents one of the most disastrous risks, water damage is among the most common and costly. Non-weather water damage, such as plumbing failures, appliance leaks or burst pipes, is the second leading cause of homeowners insurance claims in the U.S., accounting for approximately 23%-28% of all claims, according to Consumer Affairs.

Triple-I reports the average non-weather water damage claim is approximately $15,400, with hidden leaks behind walls or beneath floors often triggering the worst losses.

That’s where LeakBot, a smart water leak detection solution, comes in. The technology helps homeowners identify non-weather-related leaks, often before any visible signs of damage emerge. Earlier this year, we began offering LeakBot to eligible policyholders in Ohio, Indiana and Pennsylvania. In just a short time, more than 5,000 homeowners have enrolled.

When a leak is detected, homeowners gain access to a support team and specially trained plumbers who help diagnose and resolve the problem before it escalates into a major claim.

The technology’s simplicity is part of its appeal. LeakBot installs in minutes by clipping onto a home’s main water pipe, with no tools or plumbing expertise needed. Once installed, it quietly monitors the home in the background.

For agents, that simplicity is a major advantage. It makes it easier to introduce homeowners to risk prevention and demonstrate added value beyond the policy itself.

According to Consumer Affairs, fewer than 20% of homeowners take steps to avoid leaks, such as plumbing inspections or installing leak detection systems, despite approximately 65% of water damage incidents being considered preventable. By offering a simple tool like LeakBot, agents are well positioned to help change those statistics.

“I’m telling my Westfield customers about LeakBot, and there’s a lot of interest,” says Boyert. “There are not many carriers that offer one, let alone two, preventive risk management devices free of charge to their insureds. Kudos to Westfield for that.”

The agent opportunity: Moving beyond the policy

For independent agents, preemptive risk management tools like Ting and LeakBot transform the conversation from transactional to advisory, creating more frequent, meaningful touchpoints with customers, and reshape how they deliver value.

Data plays an important role in making those risks tangible. When customers understand how common and costly these losses are, prevention becomes easier to appreciate.

“Insurance is an intangible product. You’re basically selling a promise,” says Boyert. “Tools like this give us something tangible that we can offer to clients to give them additional peace of mind.”

Agencies can strengthen relationships and build trust over time by introducing solutions that actively help protect customers. By equipping agencies with carrier-backed risk management solutions, insurers are enabling agents to go beyond transactional interactions and position themselves as long-term advisors.

“It’s a great retention tool,” says Mangus. “As an agency owner, I’m always interested in two elements. Can this help our clients, and will it help with retention? With both, that’s a win-win.”

Customers who embrace risk protection often become more loyal to both the agency and the carrier. “The customers who recognize the value these solutions provide — and understand that Westfield introduced them to the concept — often become more loyal to both Westfield and, by extension, Miller’s Insurance Agency,” Mangus explains.

By equipping agents with practical risk-prevention tools and resources, we’re helping redefine the role agents play — from policy providers to trusted risk advisors. As personal lines continue to evolve, carriers that help customers prevent losses, not just recover from them, will help define the next generation of insurance value.

[1] Customers must have an eligible homeowners, WesPak®, WesPak Estate®, or farmowners policy with an owner-occupied dwelling to claim Ting. LeakBot devices are only available for homeowners policyholders in Ohio, Indiana and Pennsylvania.

[1] Please see footnote 1.

About the author:

Author

Casey Burke is Director of Standard Lines Marketing at Westfield, where he helps shape marketing strategies that support customers, independent agents and the evolving needs of the insurance marketplace. He brings more than 20 years of marketing and sales experience, including more than a decade in the insurance industry. Throughout his career, Casey has focused on connecting customer insights, business strategy and practical solutions to drive growth, strengthen relationships and deliver meaningful value

 

 

Sponsored by Westfield


Westfield

Profile picture for user Westfield

Westfield

Founded in 1848, Westfield is a global leader in property and casualty insurance, delivering superior risk insights and innovative solutions to customers through a portfolio of insurance products. Westfield underwrites commercial, personal, surety and specialty lines of coverage through a network of leading independent agents and brokers in the United States and specialty products through Lloyd's of London Syndicate 1200. As a mutual insurance company with a workforce of more than 4,000, Westfield has revenues in excess of $4 billion and more than $11 billion in assets. Learn more at www.westfieldinsurance.com. 

New AI Cybersecurity Threat Exploits Coding

"Slopsquatting" exploits AI coding hallucinations by planting malicious packages with fictitious names that automated tools may inadvertently import into software.

Cybersecurity

You may never have heard of the term “slopsquatting,” but as AI continues to rapidly expand, it’s likely to be a term you’ll become very familiar with in the not-too-distant future.

AI capabilities continue to improve at a rapid pace, and one sector feeling the profound impact is software engineering. With a few prompts, AI can write code automatically, in a fraction of the time it would have taken a human coder. A recent survey found that 45% of organizations have launched AI-generated code. Some companies are even using AI to write as much as 75% of their code. Microsoft’s CTO predicted that 95% of code is going to be AI-generated within five years.

While there are clear productivity gains to be realized, using AI to generate code comes with potentially serious risks. “Slopsquatting”  is one such security risk. In a slopsquatting attack, a malicious software package with a fictitious but plausible name is uploaded to online repositories. These packages contain pre-written code that developers commonly import into their own programs to accomplish certain tasks, rather than writing everything from scratch.

Here’s where it gets tricky. If an AI coding tool hallucinates the same package name as the malicious package instead of the authentic one, malware can be executed onto the users’ systems when the code is run. Like so much when it comes to malicious online activity, since the packages have seemingly legitimate names, it is difficult to detect, and the possibility exists to trick tens of thousands of unsuspecting software developers and vibe coders.

Academic researchers have found that between 5.2% and 22% of package names generated by AI are hallucinated, depending on the AI model.

As software code becomes more complex, with increased dependence on imported code libraries and packages, the attack surface grows, and software supply chains become more vulnerable. This is an example of a more general “third party risk.” Third-party risk refers to risk that an organization faces due to its relationships with its vendors, including software providers. An organization may have strong cybersecurity measures in place, but if an attacker finds and exploits a weakness of one of its vendors, the attacker may be able to use that entry point as a way to damage the target organization, resulting in negative impacts to cybersecurity, operations, finances, or reputation. Even though the risk wasn’t the target organization’s fault, they may still end up shouldering the consequences.

When it comes to risk management, four strategies are typically proposed: avoid, mitigate, transfer, and accept.

  • Avoiding the risk of AI-generated code vulnerabilities would mean not using AI to generate code. Given the prevalence and growth of AI tools in the software engineering space, this may be an impractical risk management strategy.
  • Mitigating a risk generally involves decreasing the probability of a risk’s occurrence, decreasing the consequences if it does occur, or both. Using automated tools for code quality analysis and code review can reduce the likelihood that malicious code is published. Self-healing, resilient systems that bounce back after disruption can help reduce system downtime, as well as fast incident response capabilities.
  • Transferring risk may be achieved through contractual agreements that specify third-party responsibilities and expectations before and after a potential cyber incident. Cyber insurance, a rapidly evolving financial instrument, is another potential avenue, but policies may not cover every scenario.
  • Accepting a risk does not mean inaction. Even when risks are retained, approaches like anomaly detection and continuous monitoring are used to scan systems for anything that could cause harm.

AI continues to make an impact across the economic landscape. In many cases, these impacts are mixed, and managers need to balance the pros and cons of AI implementation within their organization and across the supply chain. Guidance is beginning to emerge, such as the NIST AI Risk Management Framework, that provides a standardized structure and process for thinking about and managing the downsides associated with AI. Implementing strong risk management practices will help organizations adopting AI coding tools, and AI tools more broadly, to capture the upside benefits while minimizing the negative impacts of slop.


Zachary Collier

Profile picture for user ZacharyCollier

Zachary Collier

Zachary A. Collier is assistant professor of management and director of the Center for Applied Analytics at Radford University.

He is also a visiting scholar at the Center for Hardware and Embedded Systems Security and Trust (CHEST) and a member of the Institute for Operations Research and the Management Sciences (INFORMS).

Go Through Your Own Claims Process

Policy administration systems can open claims, but you'll find that managing the full journey requires purpose-built tools that reduce manual friction.

Colorful

Almost every carrier technology conversation eventually gets to the same question: doesn’t our policy administration system (PAS) already do claims? It’s a fair question because most PAS do include claims functionality. They can open a claim, hold the policy record, track basic activity, and support payment records or trigger the next step in the process.

The problem is that touching claims and managing the full claims journey aren’t the same thing, especially in life insurance, annuities and long-term care.

A PAS is one of the most important systems inside a carrier as the system of record, managing the operational backbone of the business. However, claims aren’t just records. They’re the moment when the promise of the policy becomes real, the moment when the carrier’s internal complexity becomes visible to the person on the other side of the transaction.

A beneficiary, policyholder or family member doesn’t care which system holds the policy record or which department owns a certain step. They care about what happens next, what’s missing, why they haven’t heard back yet, when a decision will be made, and when the benefit will be paid.

That’s where the gap usually shows up. Most systems can help a carrier receive a claim and record a payment. The harder part is everything in between where claims professionals spend their day. That could be document collection, beneficiary verification, eligibility review, medical or provider coordination, state-specific requirements, interest calculations, correspondence, payment approvals, tax questions, audit documentation, exception handling, claimant communication, or any number of things. Each one of those steps has rules around it and can create delays. Those steps can also introduce risk if they live in a spreadsheet, an inbox, a sticky note or someone’s memory.

I’ve sat with claims professionals with multiple monitors open and more applications than anyone should have to manage just to process one file. Policy administration, correspondence, document, payment, reporting systems and more, all separated and open in a multitude of windows across monitors. Claims work is complex and typically grows around systems built for different primary jobs.

This is where leaders can misunderstand the problem. From a distance, the process may look functional. Claims are opened and payments made, but the day-to-day experience of examiners tells a different story. The work may be getting done because good people are compensating for the gaps, not because the process is actually designed well. Claims teams are fantastic at finding a way to get the right claim paid to the right person. Claims professionals want to pay claims and protect families. They ultimately want to make the right decision in a thorough, fair and compliant way.

The friction often comes from the fact that we have made them carry too much of the process manually. That creates a problem for the claimant, but it also creates a problem for the carrier. Manual work affects cycle time. Cycle time affects interest obligations, customer experience and staffing pressure. Manual calculations create room for error. Undocumented decisions create audit risk. Tribal knowledge becomes dangerous when experienced examiners retire or move on. And when a claimant has to call for basic status updates, that’s not just a service issue. It’s a signal that the process is not giving people visibility when they need it most.

This is why I think carriers need to separate two questions that often get treated as one. The first question is, can our policy administration system (PAS) do claims? The second question is, can our current claims environment manage the actual work our claims team handles every day?

Those are different questions. It makes sense for a carrier to store its policy record in its PAS. A carrier may also decide that claims need a system of work around the record. It’s not a knock on the PAS. It’s simply an acknowledgment that policy administration and claims operations have different jobs.

The PAS should be trusted for what it was built to do. But claims teams need a place where the work can be orchestrated from submission through payout, where rules are visible, calculations are consistent, correspondence is triggered at the right time, documents are tracked, claimants can see what is happening, and leaders can spot bottlenecks before they turn into backlogs.

That kind of architecture isn’t about adding technology for the sake of technology. It’s about reducing friction for the people already doing the work. It’s about designing around the reality of the claim, not just the data attached to the policy.

One of the simplest exercises I recommend to executives is this: go through your own claims process. Put a policy in place with a small internal team that knows what you are doing, and then file the claim. As you fill out the forms and wait for the correspondence, you’ll see how many times you’re asked to re-fill information the company already has and where the process slows down. Most leaders who do that will see something they want to change.

Change isn’t needed because the team did something wrong. It generally becomes clear just how much the team is holding together. They will see where a PAS is doing its job and where the claims operation has outgrown the tools around it. They will see that the real question was never whether the PAS “does claims.” The real question is whether the claims process is designed well enough for the people depending on it. And that claim process flowing smoothly is vital; it’s the reason the policy exists in the first place.

Why Human Audits of AI Decisions Fail

As AI scales, insurers relying on sampling to audit AI decisions may be kidding themselves.

Human in the Loop

“Human in the loop” has become one of the most reassuring phrases in artificial intelligence.

Ask an organization how it governs an AI-assisted process and, sooner or later, someone will say that a human reviews the decisions.

That sounds responsible. It can also be almost meaningless.

Consider an insurer that introduces AI into a workflow that previously produced 1,000 decisions or recommendations a week. With AI, the same operation can suddenly produce 5,000. The review team does not become five times larger.

So the organization samples. Perhaps humans review 10% of outputs. As volume increases, maybe that becomes 5%. Eventually, the organization can point to a documented human-review process while the overwhelming majority of AI-assisted decisions pass through without meaningful scrutiny.

The problem is not sampling itself. The problem is confusing a sample of decisions with a system for governing decisions.

That distinction matters as insurers put AI deeper into underwriting, claims, servicing, fraud detection and other consequential workflows. The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers contemplates AI across these activities while emphasizing that existing legal obligations continue to apply regardless of the technology used.

The denominator changed

Traditional quality-assurance programs were designed around human-scale production. A supervisor could review a meaningful portion of an employee's work. Patterns emerged. Coaching followed. Exceptions could be investigated.

AI changes the denominator. It can increase the number of recommendations, drafts, classifications and decisions far faster than an organization can increase the number of people available to inspect them.

More automated decisions + the same review capacity = less meaningful human oversight per decision.

NIST's 2026 work on monitoring deployed AI systems identifies scaling human-driven monitoring alongside rapid rollouts as a barrier to effective AI monitoring. NIST also notes that post-deployment monitoring is necessary because systems operate under changing real-world conditions that controlled pre-deployment testing cannot fully reproduce.

An organization can therefore technically maintain a human audit while steadily reducing the actual strength of the control. That is why I have argued that “human in the loop” is not, by itself, a governance model. The presence of a person somewhere in a workflow tells us very little about whether that person has the authority, information, capacity or responsibility necessary to exercise judgment.

The more important question is not: Did a human review some of the AI's work? It is: What decisions are we allowing AI to influence or make, what could happen if it is wrong, and what evidence tells us the control system is working?

Start with decision rights, not audit percentages

Many AI governance programs begin in the wrong place. They start by choosing an audit percentage: 5%, 10%, 20%. But there is no universally meaningful percentage divorced from the decision being audited.

The NAIC's framework points in a different direction. It says an insurer's controls should be commensurate with the nature of the decision, the potential harm to consumers, the extent of human involvement, the transparency and explainability of the outcome, and reliance on third-party systems or data. Controls for a particular use case should align with the degree of potential consumer harm.

That is fundamentally a risk-based approach.

Before deciding how often humans should review AI decisions, an organization should decide which decisions AI is allowed to make in the first place.

In my work on Decision Debt, I use a three-tier Decision Rights Charter:

  • Delegate. The machine may make the decision because the pattern is stable and the consequence of error is sufficiently controlled.
  • Augment. AI can analyze, recommend, draft or challenge, but a named human owns the decision.
  • Reserve. The decision remains human because it involves values, precedent, people, significant consequences or judgment the organization has deliberately chosen not to delegate.

The audit strategy should follow that decision architecture, not substitute for it.

The NAIC bulletin similarly calls for governance structures that establish scope of authority, chains of command, decisional hierarchies, independence of decision-makers and lines of defense, as well as monitoring, auditing, escalation and reporting protocols.

The question isn't simply whether a human appeared somewhere in the process. It is who had authority to decide.

Audit the control system, not just the outputs

Once decision rights are explicit, sampling becomes much more useful. But an effective audit should test more than whether an individual output was “right.”

An insurer should be able to answer:

  • What type of decision was the AI supporting?
  • Who owned the decision?
  • Which model and version produced the recommendation?
  • What information was available to the system and the human reviewer?
  • How often did humans override the AI?
  • Were errors concentrated around particular products, populations or circumstances?
  • Did complaint patterns change?
  • Did performance change following a model, data or workflow change?
  • What happened when performance moved outside acceptable boundaries?

The NAIC bulletin says regulators examining an insurer's AI use may request inventories and descriptions of AI systems and predictive models, information about data provenance and lineage, measurements and thresholds used in oversight, and documentation of validation, testing and auditing, including evaluation of model drift.

NIST's AI Risk Management Framework Playbook points in a similar direction. Its monitoring guidance recommends documenting the degree of human oversight, maintaining statistics on human overrides, tracking reported errors and complaints, recording adjudication activity, and documenting exceptions and escalation decisions.

That changes auditing from spot-checking answers into testing a control system.

Cadence should follow risk

There is another problem with traditional audit models: cadence is often calendar-driven. Teams review a fixed percentage every week or conduct a larger review every quarter. AI systems do not necessarily change on that schedule.

NIST's current work on deployed AI identifies questions such as what the right monitoring cadence is, whether monitoring should be risk-based, and how automated and human-validated monitoring should interact as important unresolved issues.

That means there isn't a regulatory magic number. There shouldn't be.

A more defensible approach is to establish a baseline review cadence appropriate to the risk and then define conditions that automatically increase scrutiny:

  • A material model change.
  • A meaningful change in underlying data.
  • A spike in human overrides.
  • Unexpected differences across customer populations.
  • Complaints or adverse outcomes.
  • A new product, jurisdiction or use case.
  • Evidence of model drift.
  • Performance outside established tolerances.

Human oversight should expand when uncertainty or potential harm expands.

The reverse matters, too. If an organization reduces review because an AI-supported process has demonstrated reliable performance, it should be able to show the evidence that justified that decision. Trust should be earned by the task, not granted permanently to the technology.

That is the Calibrate portion of the A.R.C. Protocol I use in Decisive AI: continuously measure where AI performs well, expand delegation where performance earns it, and reclaim decision authority when it does not.

What will an examiner actually ask?

We should be careful about predicting the exact questions of a future examination. Regulatory procedures vary by jurisdiction and circumstance. But we do not have to guess about the kinds of evidence regulators are preparing to examine.

The NAIC Model Bulletin says insurers should expect inquiries into their AI governance framework, risk management and internal controls. It identifies documentation regulators may request concerning AI-program implementation, monitoring and audit activities, model inventories, data practices, measurements and thresholds, testing, validation, auditing and model drift.

As of 2026, the NAIC is also developing an AI Systems Evaluation Tool to help regulators gather information in market-conduct, financial-analysis and financial-examination contexts. The NAIC reports that 12 states were piloting the tool as of March 2026, with adoption anticipated at the 2026 Fall National Meeting. The Market Conduct Examination Guidelines Working Group also has an explicit charge to develop examiner guidance for oversight of regulated entities' use of consumer data and models involving algorithms and AI.

So imagine an examiner asks a deceptively simple question: How do you know this is working?

“We have humans review 10%” is unlikely to tell the whole story.

A stronger answer is: We know which decisions AI may make. We know which decisions require human judgment. We know who owns those decisions. We know what we measure. We know where the system fails. We know when humans override it. We know what conditions increase scrutiny. We know what thresholds require escalation. And we can produce evidence showing what we did when those thresholds were crossed.

That is the difference between having humans somewhere in the loop and having an actual governance system.

Build the evidence before you need it

Don't wait for an examination request to reconstruct this story. For every consequential AI use case, an insurer should be able to produce a coherent evidence package showing:

  • Decision authority: what AI can decide, what it can recommend, and what remains reserved for humans.
  • Accountability: the named business and technical owners and the governance body responsible for oversight.
  • Risk classification: why the use case receives the level of oversight it does.
  • Performance: the metrics, thresholds and tolerances used to determine whether the system remains trustworthy.
  • Human interaction: overrides, exceptions, escalations and relevant adjudications.
  • Consumer signals: complaints, adverse outcomes and other evidence that may reveal problems aggregate performance metrics miss.
  • Change history: material changes to models, data, workflows and third-party components.
  • Audit history: what was sampled, why it was sampled, what was found and what changed as a result.
  • Escalation triggers: the conditions under which additional human review, remediation or suspension becomes necessary.

That list isn't intended as a substitute for a company's legal, compliance or regulatory obligations. It is an operating model for making those obligations demonstrable.

Documentation shouldn't be created because an examiner might eventually ask for it. It should exist because the organization itself should already be asking those questions.

The Hidden Decision Debt

There is a final risk in weak AI auditing that may be harder to see.

The decisions appear finished. The claim moved. The underwriting recommendation was accepted. The transaction completed. The dashboard stayed green.

However, if nobody can explain who really owned the decision, why the organization trusted the system, whether the audit cadence was appropriate, or what would cause that trust to be withdrawn, the organization has not eliminated the decision. It has delegated it by accident.

That is Decision Debt: the accumulated cost of decisions that were deferred, degraded or allowed to migrate away from clear human ownership.

AI can reduce that debt. It can also compound it at machine speed.

The difference will not be whether organizations put humans in the loop. It will be whether they deliberately design which decisions remain human, which can be delegated, what evidence earns that delegation, and what evidence takes it away.

Sources / Regulatory References

[1] NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023). https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf

[2] NIST, Challenges in Monitoring Deployed AI Systems (2026). https://www.nist.gov/publications/challenges-monitoring-deployed-ai-systems-center-ai-standards-and-innovation

[3] NIST AI Risk Management Framework Playbook — Measure. https://airc.nist.gov/airmf-resources/playbook/measure/

[4] NAIC, Artificial Intelligence — current regulatory work and AI Systems Evaluation Tool. https://content.naic.org/insurance-topics/artificial-intelligence

[5] NAIC, Market Conduct Examination Guidelines Working Group. https://content.naic.org/committees/d/market-conduct-examination-guidelines-wg


Matthew Arthurs

Profile picture for user MatthewArthurs

Matthew Arthurs

Matthew Arthurs is a lieutenant colonel in the U.S. Army National Guard and a program-delivery strategist who has governed large engineering and operations portfolios in regulated industries, including insurtech. 

He is the author of the Decisive Edge series, including "Decisive AI: Reducing Decision Debt and Preserving Human Judgment in the Age of Artificial Intelligence."

Ransomware Trends in 2026 for Cyber Insurers

Ransomware losses now extend beyond file encryption to stolen credentials, cloud compromise and shared dependencies that can accumulate hidden risk.

Ransomware

The file encryptor is becoming the least interesting part of a ransomware loss.

The biggest ransomware trends in 2026 are the shift from file encryption toward data theft, stolen credentials, cloud and infrastructure compromise, AI-assisted activity and cyber insurance accumulation risk. For insurers, this means ransomware increasingly needs to be evaluated as a complete chain of financial loss rather than simply an encryption event.

By the time a ransom note appears, an attacker may already have stolen credentials, explored cloud storage, copied sensitive information and mapped the systems an organization depends on for recovery.

For cyber insurers, that changes the nature of the risk.

Ransomware is increasingly better understood as a chain of connected economic losses. Malware may be only one component. Stolen access, data theft, compromised infrastructure, business interruption, legal obligations and shared dependencies can determine how large an insured loss ultimately becomes.

The insurance question is therefore shifting from simply asking which ransomware variant caused the attack to understanding how access was obtained, what the attacker reached, which dependencies were exposed and where the financial consequences appeared.

What Are the Biggest Ransomware Trends in 2026?

The most important ransomware trends in 2026 involve attackers moving beyond file encryption and targeting the identities, data, infrastructure and shared systems that organizations depend on to operate and recover.

The six major trends are:

  • Data theft can continue creating losses even when files are successfully restored.
  • Stolen credentials and remote-access systems are becoming important parts of the ransomware attack chain.
  • Cloud, virtualization and recovery infrastructure can increase the scale of disruption.
  • AI may increase the speed and scale of reconnaissance, social engineering and vulnerability exploitation.
  • Shared access routes can create accumulation risk across multiple insured organizations.
  • Ransomware recovery increasingly means rebuilding trusted control—not simply restoring files.

For cyber insurers, these developments make the complete loss chain increasingly important when assessing ransomware insurance claims, underwriting exposure and portfolio accumulation.

1. Why May Reported Ransomware Losses Understate the Insurance Risk?

Reported ransomware losses can understate the potential insurance impact because headline figures may exclude business interruption, employee time, remediation and other costs that can become significant components of an insured loss.

According to the FBI Internet Crime Complaint Center's 2025 Annual Report, the FBI received 3,611 ransomware complaints in 2025, with reported direct losses of $32.3 million.

The FBI also identified 63 new ransomware variants, an average of more than five per month.

The top 10 variants accounted for 57% of reported incidents and 50% of reported ransomware losses.

That difference matters.

The variants represented a greater share of incidents than of reported losses, illustrating why ransomware frequency alone cannot determine the financial severity of a particular variant.

There is also a broader measurement problem.

The FBI states that its ransomware loss figure normally excludes categories such as lost business, employee time, wages, files, equipment and third-party remediation. Some organizations provide no loss amount, while incidents reported directly to FBI field offices may not appear in the Internet Crime Complaint Center total.

Threat statistics can count attacks and ransomware variants.

Cyber insurers need to understand something different: which attacks generate covered financial losses, how long those losses continue to develop and whether apparently separate claims share the same underlying cause.

What Does This Mean for Cyber Insurers?

Headline ransomware loss figures should not automatically be treated as estimates of total insured loss.

Business interruption, incident response, privacy liability, data restoration and other covered costs can materially change the financial consequences of an event.

2. Why Is Ransomware Moving Beyond File Encryption?

Ransomware is moving beyond file encryption because attackers increasingly seek access to credentials, cloud environments, virtual infrastructure and sensitive data before or alongside deploying encryption.

One of the most important ransomware trends in 2026 is this expansion beyond traditional endpoint encryption.

A joint advisory from CISA, the FBI and the Australian Signals Directorate states that the ransomware operation known as Play, or Playcrypt, had allegedly affected approximately 900 entities known to the FBI by May 2025.

According to the advisory, the group gained access through methods including stolen or misused credentials, vulnerabilities in Internet-facing systems and tools designed for remote access and technical support.

After entry, the operation combined data theft, file encryption and telephone calls threatening publication of company information.

Play also developed a version capable of disrupting multiple virtual servers rather than attacking files on only one computer.

Separately, a government advisory concerning Interlock ransomware described activity involving searches of cloud storage during data theft and targeting of less commonly monitored systems.

The potential loss is therefore expanding from individual devices toward infrastructure that may support multiple business applications, workloads and recovery systems.

What Does This Mean for Cyber Insurers?

Ransomware is increasingly an access, identity and infrastructure problem as well as an encryption problem.

Controls focused primarily on endpoint protection and backups may therefore provide only a partial picture of potential insured loss.

3. Can Ransomware Data Theft Create Losses After Recovery?

Yes. Ransomware losses can continue after systems are restored because stolen data can still generate legal, regulatory, liability, incident-response and extortion costs.

A working backup may reduce the cost of restoring encrypted files.

It does not necessarily reduce the consequences of ransomware data theft.

Once sensitive information has been copied, an organization may still face:

  • breach-notification obligations;
  • regulatory investigations;
  • legal and incident-response costs;
  • customer claims;
  • potential penalties whose insurability varies by jurisdiction; and
  • continuing extortion pressure.

Restoring information is therefore no longer necessarily the same as ending the financial, legal or insured loss.

An organization may restore every encrypted file while still facing substantial costs because the attacker retains sensitive information.

What Is Data Extortion?

Data extortion occurs when an attacker threatens to publish, sell or otherwise misuse stolen information to pressure an organization into making a payment, even when files have not been encrypted.

This distinction matters because data-only extortion can create notification and liability costs without traditional ransomware encryption.

What Does This Mean for Cyber Insurers?

One ransomware campaign may generate several categories of loss, including:

  • cyber-extortion expense;
  • data restoration;
  • privacy liability;
  • incident response;
  • business interruption; and
  • dependent business interruption.

The key distinction is increasingly between system recovery and financial recovery.

4. Why Are Stolen Credentials Important in Ransomware Attacks?

Stolen credentials matter because they can give attackers legitimate-looking access to systems before ransomware software is ever deployed.

Modern ransomware attacks can begin well before a ransom demand appears.

Attackers may obtain initial access through compromised credentials, vulnerable Internet-facing infrastructure, remote-access tools or access obtained through criminal supply chains.

The ransomware event eventually visible to an insurer may therefore represent only one stage of a longer compromise.

For insurers and risk managers, understanding how access was obtained is becoming increasingly important.

If multiple organizations rely on the same remote-access technology, identity environment, managed service or support infrastructure, one compromised route may potentially expose more than one insured organization.

What Does This Mean for Cyber Insurers?

The relevant ransomware exposure can extend beyond an individual policyholder's security controls.

Insurers may also need to consider the access relationships and technology dependencies connecting insured organizations to external systems and providers.

That becomes particularly important when evaluating portfolio-level cyber accumulation.

5. How Is AI Changing Ransomware Attacks in 2026?

AI may make ransomware operations faster and more scalable by assisting reconnaissance, vulnerability research, social engineering and analysis of stolen information, although current government assessments do not suggest that advanced attacks are becoming fully autonomous.

Artificial intelligence also presents a measurement challenge.

According to the FBI's 2025 Internet Crime Complaint Center report, the agency received 22,364 complaints containing AI-related information across all crime categories, with reported losses exceeding $893 million.

Yet only 16 ransomware complaints carried an AI reference, and those references recorded no adjusted ransomware loss.

That does not establish that AI is absent from ransomware activity.

In the FBI reporting framework, AI is an additional descriptor applied when reported information includes a reference to artificial intelligence. Each complaint still receives one primary crime category.

An AI-assisted attack that eventually results in ransomware may therefore be recorded primarily as ransomware, making AI's contribution difficult to isolate from the available complaint data.

The UK National Cyber Security Centre (NCSC) expects AI to strengthen activities including:

  • reconnaissance;
  • vulnerability research;
  • social engineering;
  • basic malware creation; and
  • analysis of stolen information.

The NCSC also expects AI to reduce the already narrow period between vulnerability disclosure and exploitation.

However, it assesses that fully automated advanced cyberattacks are unlikely through 2027, with skilled human involvement expected to remain important.

What Does This Mean for Cyber Insurers?

The near-term insurance concern is more likely to be human-machine collaboration than fully autonomous ransomware attacks.

AI could allow the same criminal workforce to evaluate more potential targets, process information more efficiently and move through parts of the attack chain faster.

From an insurance perspective, AI may consequently operate as a frequency and velocity multiplier even when it does not appear as a separately identifiable cause of loss.

6. How Can Ransomware Create a Cyber Catastrophe Through Ordinary Claims?

Ransomware can create a catastrophe gradually when multiple organizations are compromised through the same underlying access route but the resulting claims appear on different dates, in different industries and under different ransomware names.

Traditional catastrophe thinking looks for one event producing many claims at approximately the same time.

Ransomware can accumulate differently.

A criminal may break into numerous organizations through one weak remote-support product and then sell that access to different ransomware groups.

Those groups can attack different industries on different dates and use different ransomware names.

Europol's Operation Endgame targeted services used to open these routes into victims, illustrating the criminal supply chain that can sit before the ransom demand.

A joint government warning about Play highlights another complication: the group can modify its ransomware for each target, causing attacks from the same operation to appear technically different.

What Is a Serial Cyber Catastrophe?

A serial cyber catastrophe is an insurance interpretation in which a shared underlying cyber-access event produces multiple losses gradually rather than creating all claims at the same time.

This is an analytical description rather than a formal government classification.

The common cause may occur when access is first established, while the resulting insured losses emerge gradually, affect different organizations and appear under different ransomware identities.

The portfolio question therefore becomes:

How many insured organizations could be reached through the same access route before that route is identified and closed?

That is different from simply asking how many insureds use the same technology provider.

The U.S. Government Accountability Office (GAO) has warned that private cyber insurance and the federal terrorism insurance backstop may both have limited ability to absorb catastrophic losses from a widespread cyberattack.

A series of apparently ordinary ransomware claims can therefore carry a larger accumulation problem.

7. Why Is Ransomware an Accumulation Risk for Cyber Insurers?

Ransomware creates accumulation risk when multiple insured organizations can suffer losses because they share a common vulnerability, technology dependency, provider, identity system or access route.

What Is Ransomware Accumulation Risk?

Ransomware accumulation risk is the possibility that one underlying cyber weakness or dependency contributes to losses across multiple insured organizations.

One vulnerability, service provider, identity system, access broker or technical dependency could potentially contribute to losses across multiple organizations.

Yet those losses may not occur simultaneously.

This can make cyber accumulation more difficult to identify than a traditional physical catastrophe, where geographic concentration and the timing of losses may be more immediately visible.

What Does This Mean for Cyber Insurers?

A collection of apparently ordinary ransomware insurance claims could conceal a larger portfolio-level accumulation problem.

Insurers may therefore need to examine not only individual insured controls but also:

  • shared access mechanisms;
  • common technology dependencies;
  • identity infrastructure;
  • managed service relationships; and
  • concentration across critical providers.

This is where ransomware begins to move from an individual claims problem toward a portfolio risk-management problem.

8. How Does Ransomware Affect the U.S. Cyber Insurance Market?

Ransomware can produce different insured outcomes in the United States because cyber coverage is distributed across endorsements, primary policies and excess policies with different structures and attachment points.

Cyber insurance coverage is not delivered through one uniform policy structure.

According to the National Association of Insurance Commissioners' 2025 Report on the Cybersecurity Insurance Market, among U.S.-domiciled insurers, endorsements represented 55% of cyber policies in force during 2024 but only 4% of direct written premium.

Primary policies represented 42% of policies and 65% of premium, while excess policies represented 3.3% of policies but 31% of premium.

Ransomware losses therefore enter the U.S. insurance system through materially different policy structures.

A single campaign may potentially produce losses involving:

  • cyber-extortion expenses;
  • data restoration;
  • privacy liability;
  • business interruption;
  • dependent business interruption; and
  • disputed crime losses.

Data-only extortion can also generate notification, legal and liability costs even when encryption never occurs.

What Does This Mean for Cyber Insurers?

The same ransomware event can create materially different insurance outcomes depending on policy structure and the categories of loss triggered.

The financial outcome can vary depending on:

  • policy wording;
  • attachment point;
  • coverage structure;
  • organization type;
  • nature of the compromise; and
  • resulting loss categories.

Understanding the cyber event alone may therefore be insufficient without understanding how that event interacts with the insured's coverage.

9. How Can International Regulation Affect Ransomware Losses?

International regulation can change ransomware loss development by affecting reporting deadlines, ransom-payment options, legal exposure and incident-response obligations for multinational organizations.

Regulatory developments outside the United States are therefore relevant to insurers covering multinational organizations.

Under proposed UK cyber-resilience legislation, certain essential, managed and digital service providers would be required to alert regulators within one day and provide a more detailed account within three days.

The proposed scope also reaches some pre-positioning activity that has not yet caused direct damage but could produce serious consequences.

The UK has separately considered a targeted ransomware payment ban for public-sector and regulated critical-infrastructure organizations, although no final decision had been announced in the government's latest formal response cited in this analysis.

Updated UK sanctions guidance also warns that facilitating payment to a designated party may create civil or criminal exposure.

What Does This Mean for U.S. Cyber Insurers?

These UK developments do not represent U.S. regulatory requirements, but they can still affect U.S. insurers covering multinational organizations.

A single ransomware campaign can create different:

  • reporting timelines;
  • payment options;
  • response obligations;
  • legal costs; and
  • insured outcomes

depending on the affected organization's jurisdiction and sector.

10. Why Are Backups No Longer Enough for Ransomware Recovery?

Backups are no longer enough on their own because restoring files does not guarantee that credentials, cloud environments, administrator accounts and recovery systems can be trusted again.

Another major ransomware trend in 2026 is therefore the changing meaning of recovery.

Backups may exist but remain reachable through the same compromised identity system.

Files may be restored while an attacker retains valid credentials.

Virtual machines may return while cloud access, administrator accounts or transaction records remain untrusted.

UK ransomware guidance notes that ransom payment does not guarantee restoration.

The guidance also describes circumstances in which organizations recovered after payment only to experience another infection because another actor was able to exploit the same underlying vulnerability.

What Is Trusted Recovery?

Trusted recovery means restoring operations while also establishing confidence that compromised access, identities and infrastructure have been removed or secured.

Cyber resilience therefore involves more than restoring files.

Organizations may need to rebuild a trusted operating environment while simultaneously managing:

  • business interruption;
  • stolen data;
  • legal obligations;
  • compromised credentials;
  • continuing extortion pressure; and
  • incident-response costs.

What Does This Mean for Cyber Insurers?

Two organizations with similar backup and security controls can still experience materially different ransomware losses if attackers reached different levels of identity, infrastructure or recovery access.

The difference may depend on how deeply attackers penetrated systems and how confidently the organization can re-establish trusted control.

What Do Ransomware Trends in 2026 Mean for Cyber Insurers?

For cyber insurers, ransomware trends in 2026 mean that risk assessment needs to move beyond malware variants and ransom payments toward the complete chain of access, data theft, infrastructure compromise, interruption and portfolio dependency.

The defining change in ransomware is its expansion into a modular system connecting:

  • initial access;
  • stolen credentials;
  • access brokers;
  • cloud data;
  • infrastructure control;
  • AI-assisted activity;
  • business interruption; and
  • financial coercion.

For cyber insurers, the meaningful unit of analysis is no longer simply the ransomware variant.

It is the complete loss chain.

Insurers increasingly need to understand:

How was access obtained?

What level of authority did the attacker reach?

Which infrastructure and recovery systems were exposed?

Which dependencies were shared with other organizations?

What information was removed?

Where did the financial consequences emerge?

Could the same access route produce additional claims elsewhere in the portfolio?

Until that chain becomes visible, ransomware may look manageable one policy at a time while accumulation develops quietly across the portfolio.

For insurers assessing ransomware trends in 2026, that may be the most important change of all.

Frequently Asked Questions About Ransomware Trends 2026

Which Cyber Insurance Coverages Can a Ransomware Attack Trigger?

A ransomware attack can potentially trigger cyber extortion, incident response, data restoration, privacy liability, business interruption and dependent business interruption coverage, depending on the policy wording and the nature of the loss.

Why Can Two Companies Experience Different Ransomware Losses?

Two companies can experience different ransomware losses because attackers may reach different systems, identities, data and recovery environments, even when both organizations have similar security controls.

Why Can Ransomware Statistics Differ From Actual Insured Losses?

Ransomware statistics may not reflect the full insured loss because reported figures can exclude business interruption, employee time, remediation and other financial consequences.

How Can Shared Technology Increase Ransomware Exposure?

Shared technology can increase ransomware exposure when multiple organizations rely on the same provider, identity system, remote-access technology or infrastructure that attackers can compromise through a common access route.

Can a Ransomware Claim Continue After Systems Are Restored?

Yes. A ransomware claim can continue after systems are restored because stolen data, regulatory obligations, legal costs, customer claims and extortion pressure may still remain.

What Should Cyber Insurers Examine Beyond the Ransomware Variant?

Cyber insurers should examine how attackers gained access, what authority they obtained, which systems and data were reached, which dependencies were involved and where the financial consequences appeared.

Why Does the Initial Access Route Matter to Cyber Insurers?

The initial access route matters because one compromised credential, remote-access product or shared service can potentially expose multiple insured organizations and create connected claims.

Research Methodology and Editorial Approach

This article prioritizes primary government, regulatory, supervisory and law-enforcement evidence and clearly separates source-reported facts from insurance analysis.

Primary sources include material from:

  • the FBI Internet Crime Complaint Center;
  • the Cybersecurity and Infrastructure Security Agency (CISA);
  • the National Association of Insurance Commissioners (NAIC);
  • the U.S. Government Accountability Office (GAO);
  • the UK National Cyber Security Centre (NCSC);
  • Europol; and
  • the UK Government.

Quantitative claims are traced to original or primary sources wherever possible.

Vendor-produced ransomware telemetry and vendor-produced market research were not used as the basis for the quantitative claims in this article.

Where the article moves beyond reported facts to discuss implications for insurance claims, underwriting or portfolio accumulation, those conclusions are presented as insurance analysis rather than as findings attributed to the underlying government source.

International evidence is identified separately where relevant and is not presented as though it represents U.S. law or regulation.

Sources

FBI Internet Crime Complaint Center — 2025 Annual Report

https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

Used for ransomware complaint volume, reported ransomware losses, ransomware variant data, AI-related complaint statistics and limitations in reported ransomware loss figures.

CISA, FBI and Australian Signals Directorate — Play Ransomware Advisory

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a

Used for Play/Playcrypt ransomware activity, compromised credentials, remote-access exploitation, data theft, encryption and victim-specific ransomware behavior.

CISA, FBI and Partners — Interlock Ransomware Advisory

https://www.cisa.gov/sites/default/files/2025-07/aa25-203a-stopransomware-interlock-072225.pdf

Used for Interlock ransomware activity, cloud-storage access, data theft and targeting of less commonly monitored systems.

CISA — StopRansomware Guide

https://www.cisa.gov/stopransomware/ransomware-guide

Used for ransomware prevention, response and recovery context.

UK National Cyber Security Centre — Impact of AI on Cyber Threat to 2027

https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027

Used for AI-assisted reconnaissance, vulnerability research, social engineering, malware development, stolen-data analysis and the expected role of humans alongside AI.

Europol — Operation Endgame Targets the Ransomware Supply Chain

https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source

Used for criminal access infrastructure, ransomware supply-chain activity and access routes used before ransomware deployment.

National Association of Insurance Commissioners — 2025 Report on the Cybersecurity Insurance Market

https://content.naic.org/sites/default/files/inline-files/2025_Cybersecurity_Insurance%20Report.pdf

Used for U.S. cyber insurance policy structure, endorsements, primary and excess cyber policies and direct written premium distribution.

U.S. Government Accountability Office — Federal Response to Catastrophic Cyberattacks

https://www.gao.gov/products/gao-22-104256

Used for catastrophic cyber-loss considerations, private cyber insurance capacity and potential limitations of federal and private-sector mechanisms for widespread cyber events.

UK Government — Cyber Security and Resilience Bill: Incident Reporting

https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/incident-reporting

Used for proposed cyber incident-reporting requirements, reporting timelines and regulatory developments affecting cyber-loss response.

UK Government — Financial Sanctions Guidance for Ransomware

https://www.gov.uk/government/publications/financial-sanctions-guidance-for-ransomware/financial-sanctions-guidance-for-ransomware

Used for ransomware-payment sanctions considerations and potential legal exposure when dealing with designated parties.

UK Government — Government Response to Ransomware Legislative Proposals

https://www.gov.uk/government/consultations/ransomware-proposals-to-increase-incident-reporting-and-reduce-payments-to-criminals/outcome/government-response-to-ransomware-legislative-proposals-reducing-payments-to-cyber-criminals-and-increasing-incident-reporting-accessible

Used for proposed ransomware-payment restrictions, incident-reporting policy and government positions on ransomware-payment regulation.

UK National Cyber Security Centre — Recovering from a Highly Disruptive Cyberattack

https://www.ncsc.gov.uk/collection/what-to-do-when-cyber-attacks-disrupt-your-organisation/recovering/recovering-ongoing-investigations

Used for cyber recovery, rebuilding trusted systems, continuing investigation after disruption and risks that remain after systems are restored.

Insurance's Gap in Identity Security

Partner ecosystems are the identity security gap that most financial institutions, including insurers, have yet to close. 

Third-Party and Partner Access in Banking: Can FIDO Scale Beyond Employees?

Insurers and banks have invested significant effort in securing internal employee and customer access. Internal access now uses phishing-resistant multi-factor authentication (MFA), whereas consumer and policyholder-facing applications have shifted toward passkeys and passwordless access. It is usually the middle of this stack that is weak: MGAs, brokers, reinsurers, claims vendors, auditors, consultants, and external contractors all log into carrier and bank infrastructure under significantly less stringent conditions.

There are numerous examples of third-party access to financial services infrastructure based on outdated authentication methods, common passwords, manual user creation, and a general lack of governance controls. The exposure to that risk increases rapidly as partner ecosystems grow and cloud integration deepens, and insurance carriers, with their dense networks of agents, brokers, and claims partners, are as exposed as any bank.

That gap is becoming harder to ignore because the identity surface itself is expanding rapidly. Research from Enterprise Strategy Group (ESG), commissioned by Thales, found that 74% of BFSI organizations, spanning banking, insurance, and financial services, report third-party identities growing faster than employee identities, with third-party identity volumes projected to grow 37% over the next 12 months. At the same time, 89% say they already have a prioritized strategy to modernize identity solutions used by contractors and partners.

The question is: what standard should financial institutions adopt?

The Partner Access Model is Already Failing at Scale

The operational signals emerging from partner identity environments increasingly look like security warnings.

The 2026 Thales Digital Trust Index found that 92% of partner users experienced access issues with external partner systems during the last 12 months. Only 22% received login access immediately when starting with a new partner relationship. More concerning, 66% admitted to sharing or borrowing credentials, with 53% blaming slow official access processes.

These figures are often viewed as productivity issues. In reality, they highlight an identity control model under operational stress. Shared credentials eliminate traceability, making it difficult to distinguish between legitimate and compromised activity.

The same report found that 71% of partner users were worried about maintaining access they no longer needed, and only 19% said access changes were implemented as soon as responsibilities changed. This joiner-mover-leaver problem extends beyond the enterprise perimeter.

ESG’s BFSI research reinforces the point. Lifecycle management across disconnected systems, compliance reporting across identity boundaries, and deprovisioning identities when no longer needed were all ranked among the top third-party identity and access management (IAM) challenges by respondents.

Governance gaps are operational, structural, and currently exist at scale.

Third-Party Access Now Maps Directly to the Attack Surface

When the identity trends map to attack data, the security concerns become more evident. The 2026 Thales Data Threat Report: Financial Services Edition found that, according to 70% of those surveyed, the top emerging attack technique targeting cloud infrastructure in the financial sector is credential theft and the misuse of secrets.

Vulnerabilities originating from third parties, including external code and APIs, ranked second at 65%. Third-party vendor networks also ranked among the top attack targets for financial services organizations. Businesses are building connected SaaS ecosystems, fintech integrations, outsourced capabilities, and cloud processes even as credential-based attacks continue to skyrocket.

Yet the authentication layer protecting many of those external connections is inconsistent, which fuels risk because attackers don’t distinguish between employee and partner credentials.

The threat environment further complicates the issue. According to the Thales Bad Bot Report for 2026, the financial services sector accounted for 46% of account takeovers in 2025, even though it makes up just 24% of all bot attacks worldwide. In addition, there has been a 70% increase in account takeovers from July 2024 to July 2025.

Banks understand they need phishing-resistant authentication internally, and the same logic should apply to partner ecosystems.

Why FIDO Fits the Partner Authentication Problem

The value of fast identity online (FIDO) in partner access scenarios is not simply stronger MFA. It is the removal of the shared secret itself.

Passwords, OTPs, and reusable credentials create a transferable authentication artifact that can be stolen, replayed, borrowed, or phished. FIDO-based authentication replaces that with cryptographic key pairs tied to the user, device, and relying party domain. There is nothing to steal, share, or replay.

For banks that rarely control the identity infrastructure their partners use, FIDO's open standard design means strong authentication can extend beyond the corporate IAM perimeter without requiring partners to adopt the bank's full identity stack.

Not Every Partner Requires the Same Assurance Level

Partner authentication is not a single-tier problem. The right credential depends on what the partner can access and the consequences of a compromise.

For lower-risk external relationships, such as broad partner networks, suppliers, and fintech integrations where the priority is reducing friction and eliminating shared passwords, synced passkeys operating at AAL2 are a practical starting point. They raise the authentication bar without imposing hardware requirements across a diverse and distributed partner base.

For higher-risk access, device-bound hardware security keys at AAL3 are the appropriate standard. Auditors in controlled environments, privileged contractors, external administrators, and partners with direct access to regulated financial data are scenarios in which the bank's compliance posture is contingent on the partner's authentication holding. Synced passkeys, which can move between devices, do not provide that assurance.

Matching credential strength to access risk is not a novel principle. NIST SP 800-63B formalizes it through the AAL2 and AAL3 assurance levels that already underpin most phishing-resistant MFA frameworks.

Authentication Alone Will Not Solve the Governance Problem

Deploying FIDO in partner ecosystems without addressing lifecycle management extends the existing vulnerabilities rather than closing them. Delayed provisioning increases the likelihood of credential reuse; absent deprovisioning, access remains in place long after it is needed. The 2026 Thales Digital Trust Index found that only 19% of partner users see access changes implemented immediately after responsibilities change, and 66% retain access they no longer need.

Banks still need automated provisioning, entitlement management, and revocation across siloed systems — and the regulatory pressure to get this right is building. DORA, NIS2, and PSD2 all treat third-party access management as an institutional liability, not a partner problem. The ESG research found compliance and regulatory mandates were the primary driver of third-party identity modernization for 46% of BFSI respondents.

Choosing the Right FIDO Enrollment Model

Large-scale FIDO key enrollment typically follows one of three models.

In admin-driven enrollment, IT centrally configures and issues security keys before delivery, giving full control over credentials and setup policies. This is well-suited to large, time-sensitive deployments.

Self-service enrollment lets users configure their own key through a portal within defined policy parameters, reducing IT overhead but requiring a well-designed process and investment in user communications.

Vendor-managed enrollment goes furthest: keys are pre-registered before shipping, so recipients receive a device that is already enrolled and ready to use, with no IT involvement at the point of receipt.

A large automotive organization used this third model to deploy FIDO security keys to employees and contractors at scale. Using a centralized authenticator lifecycle management platform, it bulk-enrolled security keys into its internal identity providers before distribution, then shipped pre-registered keys directly to contractors and partners. The result was a faster rollout and a consistent authentication experience across a distributed user base, without placing the enrollment burden on internal IT teams.

The Next Step in Identity Security

FInancial institutions that treat partner authentication as a downstream problem will find it becomes an immediate one. Credential data theft, access failure rates, and the regulatory trajectory all point in the same direction. Phishing-resistant authentication is already the standard for employees. Extending it to partner ecosystems completes the strategy.

Insurers Need Authority Layers for AI Agents

As agentic AI moves from recommending actions to executing them, insurers need an authority layer that defines who an agent acts for, what it may do and where its power must stop.

Who Gave Your AI Agent Permission to Act?

For many years, insurance governance has asked whether the outputs of an AI system are reliable, explainable, and auditable. Those issues will continue to be relevant. But agentic AI opens a more fundamental question: Who gave the system the authority to act?

A preview layer can prevent an AI-generated output of questionable quality from reaching a customer. A reconstruction record can reflect on how something happened after the fact. On its own, neither of those controls can demonstrate whether an AI agent had proper authority to take specific action.

This raises an important distinction, as insurance companies begin to move toward systems that don’t merely summarize documents or recommend next steps to agents, but systems that can extract documents, direct cases, initiate workflows, create communications, or call out to other systems. The ability to perform an action at a technical level does not translate automatically into the ability to perform that action at an organizational level.

The governance question changes when AI can act

Regarding the claim, an AI agent may be expected, depending on the context, to research policies, compare documents presented, and provide a recommendation to send the claim to an additional reviewer. It is different for the AI agent to approve a change of claim status or pay the claim, understand and change the reserve, or send any communication to the customer that has a potential effect.

It may be technically possible to perform all those actions via connected devices. It should not be equally permissible to do all those actions.

That gap, however, in my opinion, needs an authority layer to be produced by insurers: an authoritative policy and enforcement layer between what the agent can do and what the enterprise allows it to do for a specific context.

The world of bureaucracy harbors an authority layer—and this layer must answer the following five questions, in practical terms, before some action is to be executed: Who is this agent? On whose behalf is it acting? What specific action is it entitled to execute? Under what conditions is it entitled to execute the action? When shall its authority cease or get annulled?

Capability is not authority

Access is often the first control for a given application security area: can this service access that database or call that API? Instead of focusing on access to spaces, agentic systems require a tighter granularity for the access question: should this agent be permitted to take this action, on this customer, in this workflow, and at this time?

But this goes well beyond authentication. An authenticated principal could still be subject to over-authorization.

In 2026, NIST began to make this distinction explicit. As part of its AI Agent Standards Initiative, it lists agent authentication and identity infrastructure as a research priority enabling secure human-agent and multi-agent interactions. Meanwhile, a separate project at the NIST National Cybersecurity Center of Excellence looks at standards-based means to identify agents and authorize what they are permitted to access and do as organizations evolve from generative content production to generative autonomous decision-making and action.

The practical implication for insurers is clear-cut. Agent authorizations should adhere to the business need rather than being an entitlement derived from the application or employee account that linked the agent to a resource.

If an agent assisting a service representative can create and edit work items within a policy, as well as generate a response, that should not automatically allow for the entirety of changes the service representative is able to make to the beneficiary of the policy, remove coverage, or issue disbursements.

Build an authority envelope around each agent

The most effective operational definition requires establishing an authority envelope for each production agent.

The envelope should identify the nature of the agent; the person, role, or workflow for which it is acting; the systems and data to which it has access; the actions it is allowed to take; any limits on transactions or value; any conditions that require human consent; whether it can pass authority to another agent; and a time or event after which its authority ceases.

Meanwhile, three levels are to be designed that are usually confused as a singularity:

  • Recommendation: The agent proposes an action.
  • Decision: The workflow determines what should happen.
  • Execution: A system of record is changed, money moves, coverage is affected or a customer is contacted.

A given insurer can have extensive automation at the appropriate recommendation and slightly more robust control at the decision and execution nodes. More robust control should follow the action and not be related to the complexity of the model.

This suggestion aligns with the increasing attention given by insurance regulators to the agentic risk. The documents presented at the NAIC's August 2026 Big Data and Artificial Intelligence Working Group meeting identified the agentic AI failure pattern as "Unauthorized or poorly bounded agentic behavior affecting coverage, claims, or service." The documents also say that defined action boundaries, override authority, tested kill switches, rollback, and full action logging are all signs the insurer's controls are effective in practice.

Multi-agent systems create a second authority problem

The issue becomes harder when one agent can call another.

Agent-to-agent interoperability is developing rapidly. By April 2026, the A2A protocol was formally supported by more than 150 organizations, as reported by the Linux Foundation. It was in production across financial services, insurance, and many other industries. The objective of these protocols is to enable agents to discover, communicate, and coordinate with one another across tools, vendors, and environments.

Overlapping. Therein lies value, too; however, the greater concern of governance is for the insurance industry to accomplish before multi-agent systems are able to mature – does the permission travel with necessity?

It should not.

The mere ability to communicate between agents should not result in transitive authority. For example, if agent A has permission to read a claim and requests that agent B perform a specialized action on their behalf, agent B should not be able to inherit the entirety of agent A's permissions, and agent A should not gain the transitive permissions from agent B through that delegation.

Handoffs must also be evaluated against the business purpose for which they were created, the identity of the party requesting the handoff, the action authorized by the handoff, and the risks associated with the transaction. In other words, an agent should not be able to do indirectly what it is not able to do directly.

Human oversight needs an authority trigger

“Human in the loop” is still valuable jargon, but more clarity is necessary for agentic systems. Human review should be contextually relevant, based on constraints of powers, rather than an arbitrary addition into all workflows.

An action may require a qualified tool if it can change a legal or financial situation, it is above a certain threshold, it represents an exception, it uses a new tool, it crosses a domain boundary, or it is outside normal operations for this agent.

Routine behavior can be kept automatic, provided that the conditions for automaticity are met. The intention is not to ‘put a human on the loop’ in front of every agent’s action. The intention is to make human authority exist precisely in those instances where the organization’s authority should not be delegated to software.

Finally, authority should be easily revocable by the insurer. Organizations may need to revoke a model even when it is predicting accurately and the agent is doing what it's been trained to do. Changes in data sources, downstream systems that did not operate as expected, vendor upgrades which modified workflows, or simply the appearance of a new risk that was not considered before are all scenarios where revocation may be necessary. Containment and revocation are therefore part of the authority design and not exclusively of the incident response design.

Six questions insurance leaders should ask now

Before allowing an AI agent to execute production actions, insurance leaders should be able to answer six questions:

  1. Can we identify the agent and the business principal on whose behalf it is acting?
  2. Can we distinguish what the agent may read, recommend, decide, and execute?
  3. Do high-impact actions have explicit limits or approval requirements?
  4. Does delegated work preserve the original authority boundary rather than silently expanding it?
  5. Can we revoke an agent's authority quickly without disabling the entire business process?
  6. Can we prove which authority rule permitted or blocked a consequential action?

If those answers are unclear, the organization may have agent access, but it does not yet have agent governance.

From controlled AI to authorized AI

The third step of AI governance in the insurance industry is not a more improved model or more descriptive logs; instead, it should be control over agency in black and white.

In other words, the insurer wants to know whether the AI was correct, whether the decision-making process is traceable, and whether a human being took part in it somewhere, and additionally, whether the AI was enabled to act, within a specified remit, on behalf of a particular identifiable business party.

What distinguishes an AI agent from an AI system is whether there is the authorization to act.

Similarly, it is essential to ensure that AI interventions are endowed with appropriate authority as they become more prevalent in claims, underwriting, policy servicing, and customer operations. Allow every agent to have an identity; bestow only the authority necessary to accomplish its function; make delegation explicit (but not entirely transparent); require authorization for any increase in consequences; create temporary permissions where appropriate; and immediately revoke where possible.

Agentic AI can provide much more that will result in better insurance governance. The insurance governance will provide the organization with the ability to show as clearly as possible where that ends.


Bhargavi Vepuri

Profile picture for user BhargaviVepuri

Bhargavi Vepuri

Bhargavi Vepuri is a director in the insurtech and fintech field and an independent researcher with more than 10 years of experience in enterprise technology, AI-driven systems and cloud architecture. 

She holds a master’s degree in computer science from the University of Missouri-Kansas City and is currently pursuing a second master’s degree in artificial intelligence and an executive MBA at the University of Texas at Dallas. 

She is also an author, speaker, peer reviewer and technology community contributor.

Best Practices for Cyber Resilience

Insurers now view clean, tested backups as essential proof of cyber resilience and a key factor in coverage eligibility.

 Clean, Tested Backups Are the Key To More Affordable Cyber Insurance

When insurers assess a company’s cyber readiness, they aren’t just looking for firewalls and multi-factor authentication (MFA). They want evidence that an organization can get back on its feet quickly after an incident. That’s where backups come in. A reliable, well-tested backup strategy can make the difference between a short disruption and a multimillion-dollar loss.

A Simple, But Effective, Best Practice

The 3-2-1 rule remains one of the simplest ways to build the resilience insurers need to see. It calls for keeping three copies of data, stored on two types of media, with one copy encrypted and offline or offsite. This encrypted copy helps ensure that if it is lost or stolen, sensitive data is not exposed. U.S. cybersecurity authorities such as CISA and NIST endorse this approach because it limits data loss when a cyber incident takes place.

Encryption, too, is gaining traction. Apricorn’s 2024 Annual Survey of IT Decision Makers found that 35% of organizations encrypt stored data and 39% encrypt data in transit. That helps protect backups from unauthorized use if they are lost, stolen, or mishandled. Meanwhile, isolating backups from the network is what prevents attackers from tampering with them during a ransomware event.

A Wake-Up Call for the Cyber Insurance Industry

This heightened focus on resilience is no coincidence. Only a few years ago, the cyber insurance market was reeling from massive ransomware losses. Premiums soared, coverage narrowed, and some carriers withdrew entirely. The 2021 Colonial Pipeline breach, where a $4.4 million ransom was paid within hours, underscored how exposed U.S. infrastructure had become.

According to Swiss Re, global cyber insurance premiums doubled between 2017 and 2020, and doubled again by 2022. By 2023, about one in five insurers had dropped ransomware coverage altogether. The market has since cooled slightly, with premiums falling around 6% over the last three quarters of 2024, but the message from underwriters is clear: coverage depends on proof of preparedness.

What Insurers Are Looking For

Today, insurers expect detailed evidence that clients can respond effectively when an attack hits. That includes documentation of incident response plans, MFA implementation, and vulnerability testing. But clean, tested backups are often what determine whether a company can get coverage, or afford it.

In Apricorn’s 2024 survey, 46% of respondents said that a robust backup policy is the single most important factor in meeting cyber insurance requirements, up from 28% the prior year. That jump reflects how deeply insurers now view backups as a measure of operational and financial resilience.

When Backups Fail, So Does Recovery

Unfortunately, not all backup strategies are created equal. Apricorn’s research shows that half of IT decision-makers had to restore from backups in the last year. Of those, 25% recovered only part of their data, and 8% couldn’t recover at all. Attackers know this, which is why 89% of organizations had their backup repositories targeted in 2025, according to the Ransomware Report.

Poorly designed or untested backups don’t just slow recovery. They can void coverage or drive premiums higher. Insurers increasingly require regular backup testing and isolation controls to confirm recoverability, along with encryption and even multi-factor authentication on backup systems to confirm their integrity. These controls give underwriters confidence that the company won’t suffer a total loss, which directly affects payout risk and pricing.

The Financial Logic of Resilience

For insurers, backups are an actuarial consideration as much as a technical one. Every minute of downtime adds to potential claims, so a proven recovery process can drastically reduce financial exposure. For businesses, that translates into leverage: companies that can show resilience often qualify for better terms and lower premiums.

On the flip side, weak or outdated backup strategies leave companies paying more for less coverage. Worse, paying a ransom doesn’t guarantee success: a 2025 report found that 26.5% of companies that paid attackers never got their data back. That statistic alone makes the case for self-sufficiency through strong backups.

Looking Ahead

Cyber insurers are not just risk absorbers; they’re risk auditors. They want to see measurable proof that insureds can bounce back, not just stay safe. A multilayered backup system that includes offsite and offline copies, routine testing to verify recoverability, and encryption to protect sensitive data provides the proof they need to see. It demonstrates diligence, limits losses, and reinforces a company’s credibility in renewal discussions.

Cyberattacks will continue to evolve, but recovery is one area where businesses can stay ahead. The best time to test your backups is now, not after an attack. In the eyes of both underwriters and attackers, a verified, offline copy of your data may be the most valuable asset you have.


Kurt Markley

Profile picture for user KurtMarkley

Kurt Markley

Kurt Markley is managing director at Apricorn, which develops and provides software-free, hardware-encrypted storage platforms. 

He is a 20-year technology veteran.


 

Flood Risk Beyond Traditional Zones

Pluvial flooding (when intense rainfall overwhelms drainage capacity) can happen almost anywhere and has become the fastest-increasing driver of risk. 

Flood risk in a changing climate: What risk managers need to know

This year’s floods illustrate the accelerating trend driven by global warming. A preliminary review shows extreme and often record-breaking rainfall on every continent, with many events producing exceptional sub-daily intensities. Crucially, severe flooding is increasingly occurring in locations not historically classified as high risk, prompting renewed scrutiny of exposure and preparedness.

Recent flooding illustrates how "once-in-a-lifetime" events are now occurring in rapid succession. The United States’ Texas Hill Country floods, with more than 500 millimeters of rainfall in two days, exemplified this shift, resulting in substantial loss of life and revealing gaps in emergency response and insurance coverage. Further evidence of this intensification has been seen in Pakistan, Spain and elsewhere. The persistence and clustering of such extremes align with trends clearly established in 2023 and 2024. Climate change is increasing rainfall intensity and expanding flood hazard footprints, while societal exposure continues to outpace preparedness.

Flood impacts arise from three principal mechanisms: 1) fluvial flooding, when rivers exceed capacity and inundate surrounding land; 2) coastal flooding, when tides, low-pressure systems and wind-driven surge raise sea levels; and 3) pluvial flooding, when intense rainfall overwhelms drainage capacity.

Pluvial flooding: The hidden driver

While riverine and coastal floods dominate public perception, pluvial floods are a major and growing source of damage. In Britain, 6.3 million homes are thought to be at risk of flooding from all sources. Of these, 4.6 million or 73% are at risk from pluvial flooding. According to the Federal Emergency Management Agency (FEMA), in the United States, the proportions at risk from the three main flood mechanisms are very similar. In continental Europe, France, Germany, and Poland are dominated by fluvial flood risk, but pluvial flooding is the fastest-rising driver.

In the U.S., FEMA produces flood maps, which are used to underpin many risk management activities including administration of the National Flood Insurance Program (NFIP). One of the mapped flood extents is the Special Flood Hazard Area (SFHA), which delineates the 1-in-100-year flood outline. However, all but the most recent versions of these maps do not account for pluvial flooding.

Pluvial flood risk is more difficult to map than fluvial or coastal flooding because it can occur far from rivers or coastlines and requires precise elevation data and knowledge of drainage capacity. The largest uncertainty stems from estimating intense rainfall: long-term rainfall records on which this assessment is based are often limited, and climate change makes the problem a moving target. Consequently, many countries have been slow to develop or publish pluvial flood maps, leaving significant gaps in risk assessment and planning.

According to a recent study led by the University of Michigan, in the United States, pluvial claims typically result in smaller individual payouts than catastrophic river floods (median damage is about $9,500 per claim versus $51,000 for major events), but their sheer frequency makes them costly in aggregate. In lower-risk areas outside SFHAs, pluvial flooding accounts for most claims and casualties. The same study reported that 87% of claims from properties outside FEMA’s SFHAs were due to pluvial flooding. Between 1978 and 2021, the NFIP paid $4 billion for pluvial flood claims outside of the SFHA, compared to $2.3 billion for major river floods in the same zones. These figures exclude uninsured losses, which are likely several times higher.

Action for risk managers

Extreme weather is not just a future concern — it is today’s operational reality. Businesses that fail to adapt will face escalating losses, supply chain disruptions and reputational damage. Here are practical steps to strengthen resilience:

  • Assess exposure by using government tools like the Environment Agency’s flood risk map or FEMA’s Flood Map Service Center. Do not assume flood risk is zero outside of formal flood zones. Evaluate surface-water risk, especially in urban areas. Consider upstream and downstream dependencies: suppliers, logistics hubs and critical infrastructure.
  • Where possible, register for flood warnings (river and coastal) and explore local alert systems for surface-water flooding. Develop a comprehensive flood plan that assigns clear responsibilities, identifies vulnerable assets and plans to relocate critical equipment above likely flood levels. Establish communication and evacuation protocols. Test and update plans regularly: treat them with the same rigor as fire safety drills. In England, for properties within the 100-year floodplain, a flood is five times more likely than a home fire.
  • Prepare for recovery. In the home, this might mean resilient construction but also simple measures like keeping important papers safe and moving key belongings to safety. In business, this might also mean preparation for five key loss types: premises, people, equipment, IT systems and suppliers.
  • Make sure that insurance coverage is adequate and covers the correct risks including property damage. Be certain that business interruption policies include flooding as a covered peril. Check limits, sub-limits, deductibles and occurrence clauses — flood events often span multiple days, complicating claims.
Looking ahead

Climate projections indicate that hydrological extremes will intensify, with convective storms delivering rainfall rates far beyond historical norms even in areas with no historical flood record. A new partnership including Willis and Newcastle University, the Extreme Futures initiative, will combine advanced climate science and AI to improve forecasting and resilience strategies. In the interim, businesses cannot afford complacency. Risk managers must recognize that pluvial flooding now accounts for much of the flood risk in many regions — and that traditional flood maps do not always capture this threat.

How Convective Storms Are Changing Insurance

Hyperlocal weather intelligence is helping insurers respond faster, improve claims accuracy, and better serve policyholders in an era of increasingly severe storms.

Why Severe Convective Storms Are Changing Insurance

Two homes on the same street can experience completely different outcomes from the same storm. One loses its roof and siding to wind-driven hail, while another just blocks away escapes with little more than cosmetic damage. For insurers, those stark differences create one of the industry's most difficult operational challenges: determining exactly what happened at a specific property, often within hours of the storm.

Unlike hurricanes that leave broad swaths of destruction, or floods that generally follow predictable topography, severe convective storms — including tornadoes, hail, damaging straight-line winds, and severe thunderstorms — produce highly localized, rapidly evolving damage that defies broad assumptions. Every claim requires a more precise understanding of where a storm struck, how it behaved, and what conditions a particular property actually experienced.

As another active tornado season comes to a close, insurers are confronting a reality that extends well beyond this year's losses. While severe convective storm losses exceeded $20 billion for the 11th consecutive year, they remained below both the five- and 10-year averages. At the same time, states like Illinois experienced a record-breaking season, with a preliminary estimate of 220 tornadoes so far in 2026, reinforcing widespread media coverage and a heightened perception of risk among homeowners and businesses alike.

As severe convective storms become an increasingly persistent source of insured losses, competitive advantage will depend less on understanding regional weather patterns and more on translating property-level weather intelligence into faster decisions, smarter claims handling, and stronger customer trust.

From Regional Forecasts to Property-Level Intelligence

Severe convective storms often produce remarkably uneven damage, and those sharp variations complicate nearly every stage of the insurance lifecycle.

Underwriters need to evaluate risk with greater geographic precision. Claims teams must determine exactly which properties experienced effects like damaging winds, hail, or tornado impacts. Catastrophe response teams have to deploy adjusters where they're actually needed instead of relying on county-wide assumptions. Even customer communications become more nuanced when two policyholders living minutes apart experience dramatically different outcomes.

Traditional catastrophe models remain essential, but they weren't built to answer property-level questions on their own. Meeting that challenge requires a more granular view of the weather.

Advances in radar, satellite imagery, lightning detection, and high-density weather observation networks now give insurers a far more detailed picture of developing storms than was possible only a few years ago. Combined with convective-allowing models capable of forecasting storms at kilometer-scale resolution, these technologies help insurers move beyond generalized forecasts to understand how a storm is likely to affect individual communities down to the street.

This level of precision transforms insurers’ operational decision-making.

Instead of waiting on claims to arrive, carriers can identify areas most likely to experience significant hail or tornado damage, position field adjusters in advance, prepare call centers for increased demand, and communicate with policyholders before the first inspection is scheduled.

The advantage is faster, more informed action.

Why Every Minute Matters

During severe convective storm outbreaks, timing can significantly influence both operational costs and customer experience.

Receiving reliable weather intelligence just 30 minutes before a major hail event can give insurers enough time to staff call centers, mobilize claims personnel, and begin communicating with policyholders before call volumes surge.

That kind of lead time can make a meaningful difference during events like the record-breaking 6-inch hailstones that struck the heavily populated Kankakee, Ill., area on March 10, 2026, when insurers can become inundated with claim spikes and overwhelmed call queues within minutes. Near-real-time radar updates and rapidly refreshing weather observations allow operational teams to adjust as storms evolve, reducing delays and improving response times when customers need support most.

Because warnings often involve life-threatening situations, insurers appropriately rely on official warnings issued by the National Weather Service rather than issuing independent alerts. Their opportunity lies elsewhere: helping policyholders understand changing conditions in the hours leading up to severe weather and rapidly mapping paths afterward to prioritize claims response and inspection resources.

The objective isn't replacing public safety messaging. That is still very much a fundamental part of the equation. Instead, it's to deliver faster, more informed service when every minute counts.

Smarter Claims Through Better Weather Intelligence

The true value of hyperlocal weather intelligence becomes clear after the storm passes.

Historically, claims investigations often relied on manual inspections across entire affected areas. Today, combining hyperlocal weather intelligence with policyholder data allows insurers to prioritize inspections where uncertainty is highest while accelerating straightforward claims supported by high-confidence weather evidence.

This targeted approach improves efficiency without sacrificing accuracy. Instead of dispatching adjusters to every reported loss, insurers can focus experienced personnel on the most complex claims while using verified weather intelligence to streamline simpler cases. The result is faster settlements, lower operational costs, and a better experience for policyholders recovering from severe weather.

The same intelligence also strengthens claims verification and fraud detection by providing objective evidence of conditions at a specific location. When weather observations, radar signatures, and storm reports align with reported damage, insurers gain greater confidence in claims decisions. When they don't, insurers can investigate further before making unnecessary payments.

Artificial intelligence is making these insights even more actionable. Instead of relying on broad alerts, insurers can tailor communication based on individual property characteristics and prior customer interactions.

A homeowner with outdoor furniture, solar panels, or trees close enough to threaten nearby houses may receive different preparedness guidance than another policyholder nearby. By making communication more relevant, insurers can encourage risk reduction, reduce alert fatigue, and strengthen trust before severe weather strikes.

Building Trust in an Era of Localized Risk

This year's tornado season shows a broader transformation taking place across the insurance industry.

Although severe convective storm losses remained below recent averages, public attention surrounding tornado outbreaks reinforced a heightened sense of risk. That creates both a challenge and an opportunity for insurers.

Policyholders expect faster communication, quicker claims decisions, and greater transparency about how coverage decisions are made. Meeting those expectations requires more than better catastrophe models. It requires turning property-level weather intelligence into faster operations, clearer communication, and more confident decision-making.

As severe convective storms continue to reshape the insurance landscape, competitive advantage will belong to carriers that combine scientific precision with operational agility. Every storm creates thousands of property-level decisions, and the ability to make them quickly, accurately, and confidently is becoming one of the defining capabilities of modern insurance.