Download

Women, Wealth Reshape Advisory Relationships

Women will control $34 trillion in assets by 2030, yet many feel underserved by traditional advisory models.

Women and Wealth

For years, conversations around wealth management and personal risk planning often centered on a traditional household structure, where financial and insurance discussions were directed to one primary decision-maker. That reality has changed.

Women are projected to control an estimated $34 trillion in assets by 2030, according to recent McKinsey research, representing one of the largest wealth shifts the advisory industry has seen in decades. At the same time, women are increasingly leading businesses, managing multigenerational wealth, overseeing family offices and making independent decisions around long-term financial protection.

Despite these changes, many affluent women still say they feel underserved or misunderstood by traditional advisory models.

The challenge isn’t simply about offering more products or creating “women-focused” messaging. Expectations around advice, communication, trust and long-term planning are evolving, and for insurance and risk advisors, this shift carries important implications.

Wealth Conversations Are Becoming More Personal

Today’s high-net-worth households are more complex than ever. Widowhood, entrepreneurship, second marriages, blended families, caregiving responsibilities, independent wealth creation and longer life expectancy are all reshaping how affluent clients think about financial security and risk.

Many women are no longer participating in these conversations as secondaries. They are leading them. That changes how advisors must approach discussions around property protection, liability planning, collections, business exposures, trusts, succession planning and lifestyle continuity.

It also changes how relationships are built.

Research highlighted during PRMA’s Women & Wealth discussions emphasized that many women value advisors who prioritize listening, context, education and long-term partnership over transactional conversations.

In many cases, trust is shaped less by technical expertise alone and more by whether the advisor understands the client’s priorities, family dynamics and long-term concerns.

Where Advisors Sometimes Get It Wrong

Many of the disconnects women describe are not apparent. They are subtle behaviors that unintentionally create distance in the relationship.

There are several recurring themes, including:

  • Defaulting attention to the person the advisor has historically worked with
  • Making assumptions about financial roles within a household
  • Over-explaining without understanding the client’s baseline knowledge
  • And jumping to solutions before understanding priorities

These moments may seem minor, but they shape whether clients feel heard and respected.

The broader issue is that women are not a single client type. Recent research introducing multiple behavioral profiles of women investors reinforces that affluent women approach financial decisions differently based on life stage, personality, experience, family structure and personal priorities.

Some clients want detailed education and collaboration. Others expect concise strategic guidance. Some are highly involved in every decision. Others prioritize delegation and efficiency. The strongest advisors recognize the importance of adapting their communication style rather than relying on assumptions.

Insurance Is Increasingly Part of the Broader Wealth Conversation

As wealth becomes more complex, insurance conversations are becoming more integrated into broader financial planning discussions.

For affluent women navigating major life transitions, agents should be prepared to ask questions that extend beyond premiums and policies.

They include:

  • How will lifestyle continuity be maintained after a loss?
  • Are trusts, LLCs and ownership structures properly aligned?
  • Is valuable property documented correctly?
  • Are liability protections sufficient as wealth grows?
  • Are family members adequately protected across multiple residences, vehicles or recreational assets?

Even in situations involving divorce or estate restructuring, insurance frequently becomes a foundational piece of rebuilding financial independence and protecting future stability. The growing importance of reviewing ownership structures, umbrella liability protection, valuables coverage, trusts and long-term lifestyle considerations during transitional life stages requires technical expertise, but it also requires emotional intelligence.

The Advisors Who Will Win in This Market

Much of this evolving conversation around women and wealth has also been explored by Steph Wagner, National Director of Women & Wealth at Northern Trust and author of Fly! A Woman’s Guide to Financial Freedom and Building a Life You Love, which examines how financial confidence, life transitions and long-term planning intersect for many women today. While written primarily for women, Wagner’s work also offers a valuable perspective for advisors who want to better understand the emotional and practical realities that shape many client conversations.

The growing influence of women in wealth creation, wealth transfer and financial decision-making is one of the defining shifts changing the advisory landscape.

Advisors who invest the time to understand individual priorities, communication preferences and life circumstances will be better equipped to build lasting relationships. Those relying on assumptions about who makes decisions, how trust is built or what clients value risk overlooking an important segment of the market.

Ultimately, this is a conversation about serving women more thoughtfully. The advisors who embrace that mindset will be the ones best positioned for the next generation of wealth.

Operational Gaps Hinder Insurance AI Implementation

Insurance AI implementations fail not from poor models but from organizational gaps in infrastructure, governance, and operational readiness.

TEchy

The models are ready. The infrastructure often isn't. And the gap between the two is where most AI investments go quiet.

Not long ago, I was in a discussion where everyone agreed the AI was working. The model accuracy was where we expected it to be. The pilot results looked promising. Yet nobody wanted to expand the program. 

In insurance, AI rarely fails because the technology doesn't work. It fails because the organization around it isn't ready for what the technology requires.

The issue wasn't the algorithm. It was everything around it.

The Operational Intelligence Gap

The insurance industry has spent the last several years building AI competence at the model level. Carriers have invested in underwriting algorithms, fraud detection engines, claims triage tools, and customer-facing automation. Much of that work is technically sound.

But technical soundness isn't the same as operational readiness. And in insurance, where decisions carry regulatory weight, customer relationships, and actuarial accountability, the operational layer is where value is either realized or lost.

The failure mode I keep seeing isn't model accuracy. Over the years, I've started thinking about this as an operational intelligence gap: the difference between a model that performs well in testing and a business capability that can be trusted, governed, and sustained in production. That gap has four dimensions. In my experience, most organizations focus on only a few of them.

Places Where AI Loses Its Value

Part of that gap is data.

Insurance organizations rarely operate from a single source of truth. Policy systems, claims platforms, CRM environments, external feeds—each evolves at its own pace. AI doesn't break when those systems disagree. That's the problem. It continues to produce answers. Some of them are even convincing.

But data isn't where most projects get stuck. More often, the problem appears later, when AI has to fit into an existing workflow.

A claims adjuster receives a recommendation. An underwriter receives a score.

The model may be right. Yet if the recommendation arrives too late, or in a format nobody actually uses, the value evaporates surprisingly fast.

What This Looks Like in Practice

A few years ago, I led the technology architecture for a communications platform at a major insurance enterprise. The system eventually handled roughly 80 million customer communications annually across digital and traditional channels. The core AI components performed well in testing. The models did what models do.

What nearly derailed the program had nothing to do with the models. It was the integration layer between real-time AI routing decisions and a legacy policy system that updated on a 24-hour batch cycle. The AI was making decisions based on customer state data that was, by definition, always a day old.

Fixing that required infrastructure investment that wasn't in the original scope. What surprised me was how little of that conversation involved the AI itself:

Looking back, I don't remember many conversations about model accuracy. I remember conversations about budgets. Ownership. Which team would take responsibility when something went wrong.

When we addressed those layers, not just the algorithm, the results shifted materially. Complaint volume dropped by 90%. Delivery speed improved by 96%. The AI wasn't different. The operational architecture around it was.

Insurance Has Always Been a Trust Business

Insurance was a trust business long before it became a technology business. Customers trust insurers with their financial security. Regulators expect decisions they can explain and defend. Employees have a different concern altogether: they want technology to support their judgment, not quietly replace it.

Consider a claims environment. An AI model may identify potentially fraudulent claims with impressive accuracy. Yet if investigators cannot understand why a claim was flagged, or if the escalation process is unclear, the organization faces a difficult choice: trust a recommendation it cannot explain or ignore a recommendation it cannot defend. In insurance, that tension often matters more than the model's accuracy score.

Trust Changes Everything

Regulatory expectations are also changing. Across major markets, insurers are facing growing pressure to explain how automated decisions are made, monitored, and governed. Regulators are asking harder questions than they were two years ago. That shift is real, and it's not slowing down.

Some of the most mature programs I've seen weren't built by organizations with the most advanced models. They were built by organizations that invested early in governance.

When I look at AI programs that struggle, the same questions keep coming up.

The first question is, “Can we trace any AI-influenced decision back to the data that produced it, the model version that processed it, and the human who is accountable for it?” If the answer is no, the program has a governance gap that will surface at the worst possible moment.

Another question worth asking is, “Have the people closest to AI outputs been involved in designing how those outputs reach them?” Not briefed after the fact — involved in design. The distance between those two things is usually the distance between adoption and shelf life.

And the third one is, “Is the integration layer between AI systems and core operational data treated seriously, or as a technical detail to be handled later?” In every AI program I've seen fail quietly, the integration layer was a detail. In the ones that scaled, it was a strategic decision.

Beyond the Algorithm

I've stopped being surprised when a technically successful model struggles to create business value. I've stopped being surprised when a solid model fails to move the needle. By now I know where to look, and it's never the algorithm.

Most insurance organizations don’t need more AI pilots. They need the discipline to turn what they’ve already built into something that actually gets used by real teams, in real decisions, under real pressure.

Most of these organizations already have AI. What they're missing isn't access. It's the organizational work that makes AI usable, and that work doesn't show up in a vendor demo.


Figen Ozmen

Profile picture for user FigenOzmen

Figen Ozmen

Figen Ozmen is a technology executive and consultant with 25+ years of experience in insurance and financial services.

Auto Claims Modernization Needs Better Data

Billions spent on digital claims technology can't overcome fragmented vehicle data that continues driving operational leakage and fraud.

Auto Accident Claims

The auto insurance industry today is facing many new challenges, including elevated repair costs, evolving fraud risk, and policyholders still expecting fast, almost immediate answers when a vehicle claim disrupts their lives.

In fact, the CCC Intelligent Solutions reported that total-loss claim share reached a record, with vehicles seven years or older accounting for more than 72% of total-loss valuations as aging vehicles and rising repair costs continue putting additional pressure on claims operations. Average total repair costs were above $4,730 in 2024, a 3.8% increase year-over-year, with costs rising a further 1.4% during the first half of 2025.

That said, the real problem extends beyond just claims volume or repair inflation. Many teams still rely on fragmented data across multiple sources when verifying basic claim information. And every delay in that process causes additional expenses and friction. This means the claims process can only modernize if adjusters can access verified data early enough to make better decisions before those costs escalate.

Digital Claims Tools Need Stronger Data Beneath Them

Forrester expects U.S. insurance technology budgets to reach $173 billion in 2026. So, it’s safe to assume that carriers have spent millions, if not more, investing in front-end claims technology. FNOL automation to mobile photo uploads, AI-assisted triage, and digital communications have all undoubtedly improved speed and customer access. But, like many other technological advancements, those tools only perform as well as the data that feeds them.

Many bottlenecks appear after intake, when adjusters need to confirm whether a claimant has clear ownership or whether title activity creates settlement risk. A claim can move through digital intake quickly and still stall once a team needs verified vehicle data from these disconnected systems.

In total-loss workflows, a missing lien record can hold up payment, a title discrepancy can force late-stage review, and a VIN inconsistency can trigger additional investigation after the carrier has already invested time in valuation and settlement coordination. Digital claims systems create speed at the front of the process, but it’s verified data that protects that speed through resolution.

Claims Leakage Often Starts With Small Data Failures

It’s very rare that claims leakage happens due to just one dramatic error. It usually builds through repeated friction across thousands of files. For example, a delayed lienholder confirmation adds handling time, and a late title issue creates settlement rework. Each of these issues may look manageable individually, but across the total claims book, those small failures add up to real cost.

Claims leaders already track macro severity drivers such as repair inflation and litigation exposure. Operational leakage deserves the same attention because it sits closer to the daily work of claims teams. It affects cycle time, adjuster capacity, policyholder satisfaction, and payment accuracy.

The cost environment makes those small breakdowns harder to absorb. But it’s better data that gives carriers a direct way to reduce friction inside the claim, rather than only reacting to severity after it shows up in the file.

Total-Loss Claims Need Earlier Verification

Total-loss claims place a heavier burden on data quality because they require coordination across multiple parties. The carrier may need to confirm ownership, communicate with a lienholder, validate title status, process documentation, and resolve payment expectations within a very compressed timeline.

When adjusters can access verified title, lien and ownership information in real time rather than relying on fragmented lookups across disconnected systems, they can identify title issues before any valuation discussions advance. Earlier visibility helps claims teams spend less time handling administrative issues late in the process and more time focused on claim resolution, policyholder communication, and overall exposure management.

That can help improve control over claim outcomes, because adjusters spend less time resolving administrative issues late in the file and more time managing exposure, documentation quality, and policyholder communication.

Stronger Data Also Strengthens Fraud Detection

Fraud risk has also increased the importance of connected claims intelligence. Modern fraud schemes often exploit gaps in vehicle records, ownership data, title activity, and identity verification.

NICB projected a 49% rise in insurance crime involving identity theft by the end of 2025. Its analysis also found that nearly one quarter of identity-theft referrals involved synthetic identity activity. And with insurers in the U.S. losing roughly $300 billion to fraud per year, nearly 25% of the industry’s total value, it’s a costly issue to have.

Auto claims teams need to see these risks earlier in their workflow to stop schemes in their tracks. Title manipulation, VIN inconsistencies, suspicious transfer activity, irregular lien documentation, and undisclosed prior vehicle events can all indicate exposure. When adjusters or SIU teams see those indicators late, it’s the carriers that face higher investigative costs and weaker recovery options.

Connected verification data helps claims organizations identify suspicious patterns before payments even move forward. It also helps SIU teams prioritize the files with the highest risk, rather than forcing adjusters to chase disconnected data across every claim.

Data Security Has Become Part of Claims Performance

Claims data carries high security value because it often combines personally identifiable information, vehicle identifiers, ownership records, payment information, and lienholder details. As claims operations become more digital and increasingly dependent on outside data providers, carriers are placing greater scrutiny on how sensitive information moves across third-party systems and whether those systems meet modern security expectations.

That makes claims operations an attractive target for fraud actors and cybercriminals, and it is also why claims leaders need strong data governance and clearer visibility into the vendors supporting critical claims workflows. Teams need to know who accessed sensitive claim data, how systems use it, and whether third-party workflows protect it with the same discipline expected inside the carrier’s environment. As more carriers rely on outside data partners to support total-loss, fraud, and settlement workflows, security can no longer sit apart from claims performance. For data partners operating in this environment, SOC 2 compliance is not optional. It is the baseline signal that security controls have been independently verified, not just self-reported.

Better Claims Data Improves Adjuster Productivity

Claims organizations also continue to face staffing pressure and heavier file complexity. Experienced adjusters should spend their time evaluating exposure and guiding claim outcomes. Many still spend too much time searching for records, confirming basic facts, and resolving data inconsistencies that technology should surface earlier. Earlier verification can help reduce that burden.

When claims teams can trust core vehicle and ownership data, adjusters can move files with greater confidence. They can reduce manual follow-up, improve documentation quality, and focus attention on claims that require judgment rather than administrative tracking.

This also improves consistency across claims teams. Fragmented workflows create uneven outcomes because different adjusters may use different sources, ask different questions, or catch problems at different points in the file. Connected operational data provides teams with a shared foundation for decision making.

Why the Next Phase of Claims Modernization Should be Operational

Carriers need infrastructure that enhances data integrity across verification-intensive workflows, especially in total-loss processing and settlement coordination. Stronger claims data helps reduce leakage, improve cycle time, strengthen fraud detection, and protect adjuster capacity. Security also needs to sit at the center of that infrastructure. Claims data has become too valuable, too sensitive, and too operationally important for carriers to treat governance as a secondary concern.

The insurance industry has already improved customer-facing claims technology in abundance. Therefore, the next phase of modernization should naturally focus on the quality of the underlying data, especially the verified title, lien, and ownership layer that total-loss and fraud workflows rely on most.


Lee Perine

Profile picture for user LeePerine

Lee Perine

Lee Perine is co-founder of YASSI.

He works with insurance and automotive organizations to improve vehicle-data workflows, verification processes, and operational efficiency within auto claims environments.

4 Key Questions for AI Deployment in Insurance

As insurance embraces AI, the architecture decisions behind deployment may matter more than the capabilities it delivers.

Deploying AI

The insurance industry has embraced AI with remarkable speed. Across agencies and carriers alike, artificial intelligence is moving from experimental pilots into the workflows that matter most, such as underwriting, policy servicing, claims, financial reconciliation, and client communication. The momentum is real, and the potential is significant.

But as AI moves deeper into core operations, a critical question isn't getting enough attention: How is this AI actually built, and where does the data go?

Most industry conversations about AI have focused on capability. But capability without architecture is a liability. And for an industry built on trust, the architecture decisions behind AI may matter more than the features it delivers.

The Gap Between Adoption and Understanding

Insurance professionals are practical people. When a new tool saves time, reduces errors, or helps serve clients better, adoption follows quickly. That pragmatism has driven rapid AI adoption across the industry, but it has also created a gap between what organizations use and what they understand about how it works.

Consider the questions that rarely get asked during an AI evaluation: Where does my data go? Who trained this model, and on what? Is there a human checkpoint before AI-generated outputs become authoritative? And if a regulator asks how a decision was made, can I produce an auditable trail?

These aren’t abstract concerns. They are the practical realities of embedding AI into workflows that touch sensitive policyholder data and regulated decisions. The answers depend entirely on which AI tools an organization has chosen and how they were built.

Why Vertical AI Carries Inherent Advantages

Not all AI is created equal, and the distinction that matters most in insurance isn't the size of the model, it's whether the AI was purpose-built for the industry or adapted from a general-purpose tool.

General-purpose AI platforms are broadly useful, but broad applicability comes with trade-offs. These models don’t understand ACORD forms, policy data structures, commission reconciliation logic, or the regulatory requirements governing insurance information. When pointed at insurance tasks, they can produce outputs that look right but miss the context that makes them reliable.

AI built specifically for insurance — trained on insurance data, designed for insurance workflows, and embedded in the systems where insurance professionals already work — operates under fundamentally different assumptions. It understands the data structures, the regulatory context, and the operational patterns that define how insurance actually gets done.

This distinction has direct security implications. Insurance-specific AI can be hosted in controlled environments, designed with industry-appropriate data handling rules, and embedded directly into the management systems agencies and carriers already use, reducing data handoffs, third-party dependencies, and points of exposure.

The Four Questions Every Insurance Organization Should Ask

As AI becomes woven into daily operations, insurance leaders, whether they run a five-person agency or a national carrier, should be asking four fundamental questions about every AI tool they adopt.

1. Where Was This AI Trained, and on What Data?

AI models are shaped by their training data. A model trained on general Internet content will approach an insurance task very differently from one trained on years of insurance-specific transactions, documents, and workflows. The former might generate a plausible-looking summary of a policy; the latter understands what a policy actually means in an operational context.

Beyond accuracy, training data raises important questions about data privacy. Organizations should understand whether their own data could be used to improve a vendor's models, and specifically whether customer data is ever used to train public models. The defensible standard is clear: customer data should never be used to train models that serve other organizations or the general public. This isn't a technical footnote; it's a foundational trust commitment.

2. Where Does My Data Go When AI Processes It?

When an AI tool reads a policyholder's information, generates an underwriting recommendation, or reconciles a financial statement, that data has to go somewhere for processing. The question is whether it stays within an environment the technology provider owns and controls, or whether it passes through third-party infrastructure that introduces additional risk.

The most secure approach is an AI architecture in which the provider develops, hosts, and maintains the models in its own controlled environment. This means data isn't routed through external APIs, third-party model providers, or shared infrastructure where the chain of custody becomes harder to verify. For agencies and carriers handling sensitive personal and financial information, the fewer hands that touch the data, the better.

3. Is There a Human in the Loop?

AI that operates without human oversight isn't intelligent — it's reckless. In an industry where a single data error can affect coverage, pricing, compliance, or a client relationship, AI-generated outputs need human checkpoints before they become authoritative.

This doesn’t mean every AI output requires manual review. But high-stakes outputs, including anything entering a policy record, any financial recommendation, or any coverage determination, should pass through a trained professional who can confirm, adjust, or override. The goal is augmentation, not replacement.

4. Can I Prove How a Decision Was Made?

The regulatory environment around AI in insurance is evolving rapidly. The NAIC's Insurance Data Security Model Law has been adopted in more than two dozen states. New York's 23 NYCRR 500 sets rigorous cybersecurity requirements for insurers. Colorado's AI governance legislation and the NIST AI Risk Management Framework are signaling the direction of future oversight. And across every jurisdiction, the expectation is moving toward the same principle: if AI is involved in a decision that affects a consumer, you need to be able to explain how that decision was made.

This means AI systems need to maintain auditable trails that go beyond simple logs of what happened. Organizations need explainable records of why. Which data inputs informed the output? What model logic was applied? Was a human involved in reviewing the result? Organizations that invest in auditability now are building a foundation for regulatory resilience. Those who treat it as a future concern are accumulating risk.

Security Is Not a Feature. It’s an Architecture.

The mistake many organizations make is treating AI security as a procurement checkbox, just another line item on an RFP or a section in a vendor questionnaire. In reality, secure AI isn't something you add after the fact. It's a function of how the AI was designed, where it lives, what data it was trained on, and how it interacts with the systems around it.

The most meaningful security advantages come from architecture, not add-ons. AI that is natively embedded in the platforms where insurance work happens, rather than bolted on as a separate tool, inherently reduces the attack surface. Data doesn't have to travel between disconnected systems. Integration points don't require additional middleware or third-party connectors that introduce new vulnerabilities. And the AI operates within the same governance and permissions framework that already protects the organization's core data.

This is the architectural argument for embedded, insurance-specific AI: it's not just better at insurance tasks — it's inherently more secure for insurance data.

Decisions That Define the Next Decade

The insurance industry is in a defining period for AI adoption. The choices agencies and carriers make now about which AI tools to trust, how those tools interact with sensitive data, and what governance standards they demand from their technology partners will shape their risk exposure, regulatory standing, and client trust for years to come.

The organizations that get this right won't be the ones that adopted AI fastest. They'll be the ones that asked the hardest questions before they deployed it and chose partners whose answers held up under scrutiny.

AI has the potential to make insurance faster, smarter, and more responsive. But only if the intelligence we deploy is built on a foundation of security, transparency, and accountability. Client trust has always been the industry’s most valuable asset. The AI we build should protect it.


Anupam Gupta

Profile picture for user AnupamGupta

Anupam Gupta

Anupam Gupta is chief product officer at Applied Systems

He was previously CPO at 4C Insights and then at Mediaocean, which acquired 4C Insights. He has also led product organizations for several tech companies, including at Vubiquity, Mixpo, and Microsoft.

Quantum Computing for Insurance Still Years Away

Quantum computing holds promise for complex financial modeling, but current technology is limited by noise and qubit count.

Quantum Computing

Stories of quantum computing revolutionizing modeling are everywhere, and the parallels from quantum to Monte Carlo seem tempting. But how will stochastic modeling work, and how close are we to having working models? Is this the technology to place your bets on?

What is it?

Quantum computing is a new field of computer science that uses quantum mechanics to solve complex problems. Classical computers use “bits” that take a binary state – 0 or 1 – to represent information. Think of them as similar to a coin at rest that can be thrown to result in either heads or tails landing upwards. By contrast, quantum computers use quantum bits (qubits) that can exist in multiple states simultaneously, like a spinning coin. Qubits can also be entangled, meaning the state of one can directly influence the state of another.

This enables the development of a whole new set of algorithms beyond the capabilities or performance of traditional computers.

However, the compute step time of quantum computers is in the order of milli- or micro-seconds compared with the nanoseconds of traditional computing. With parallelization of the more plentiful older technology, a classical system can be seven to eight orders of magnitude faster than a quantum step.

Are they real?

Prototype quantum computers have been built, and these are accessible over cloud platforms. However, while these computers are theoretically capable of delivering, they are hindered by high noise levels (random errors), making superior use of them unattainable. To address this issue, quantum computers often require several magnitudes more physical qubits than the logical qubits presented to the user.

The algorithms can be built and tested on traditional computers, too. There are software development kits that enable quantum programming and quantum simulators that simulate quantum computers on high-end traditional computers.

To date, quantum computing is being used to solve problems with complex interactions, including systems optimization, drug research and materials research. It can also be used in cryptography, to both create and break encryption methods.

Can they be used for life financial modeling?

Research in the last five years showed that quantum computers can calculate a value at risk (VaR) on an asset portfolio with a quadratic speed-up compared with traditional computers. That is, if traditional computers are N-squared steps, then quantum is in N steps. However, this is a very simplified case.

In one theoretical application of quantum computing, approximately 36 billion physical qubits would have been required to perform useful computation using today’s noisy qubits and known error correction schemes. Yet, the largest quantum computers today only have around 6,000 qubits. By comparison, this is a problem that can be solved on a personal laptop within seconds or at most minutes.

In addition, as with graphical processing units (GPUs), quantum computers currently have significant limitations where it is necessary to input or output large volumes of data.

Practical applications of quantum computing are therefore many years away, and most likely to first emerge with algorithms that are exponentially faster than traditional approaches.


Mark Brown

Profile picture for user MarkBrown

Mark Brown

Mark Brown is global proposition lead of life financial modeling for insurance consulting and technology with WTW.

Brokers Should Rethink D&O Priorities

Soft market apathy and emerging exposures are pushing D&O brokers to compete on comprehensive coverage rather than price alone.

D&O Crossroads

The directors and officers (D&O) marketplace is at a crossroads. On one side are soft market conditions that have persisted since 2022, creating intense competition among carriers, driving lower pricing and broader terms for insureds. On the other side are macroeconomic headwinds such as inflation, tariffs and a tightening credit market, leading to an uptick in corporate bankruptcies and restructuring.

As these forces collide, savvy brokers are responding by shifting their focus from price to protection. They are using this window to negotiate broader coverage, rather than just lower premiums, for their clients.

History Doesn’t Repeat. It Rhymes.

The current D&O landscape is reminiscent of the cyber insurance market from 2021 – 2023. After those three years of soft conditions, the market hardened fast, leading to double-digit premium increases that caught many insureds off guard.

Could the D&O market have a similar knee-jerk reaction? It’s entirely possible.

Persistent soft markets can create apathy among insureds and underwriters. Businesses that incur six-figure D&O claims and only modest premium increases may begin to feel a false sense of security, believing that financial negligence or regulatory violations will bring few consequences. Carriers, meanwhile, can grow overly permissive in their underwriting practices. They may skip legitimate questions, such as asking about a debt covenant, just to win more business solely on price.

When the market hardens quickly, as we saw with cyber, brokers can get caught in the middle, navigating a tug-of-war between premium spikes for disillusioned clients and tighter underwriting from increasingly wary carriers.

Top Exposures and Exclusions Show the Cracks

Despite favorable terms for insureds in the current D&O market, certain exposures are already causing carriers to tighten their underwriting standards.

A fiercely competitive merger-and-acquisition (M&A) environment is the primary exposure. Over the last few years, we’ve seen privately held companies across multiple industries sell partially or fully to private equity (PE) or move to an employee stock ownership plan (ESOP) model. As companies battle for PE money, the pressure for higher valuations is intense, and boards that overvalue or undervalue their companies face potential D&O claims.

Simultaneously, inflation is shrinking corporate margins, leading to issues with creditors and putting debt covenants at risk. Boards often must respond with creative cost-cutting or risk insolvency or bankruptcy.

Underwriters are responding to these forces with caution. While bankruptcy and solvency exclusions remain rare, antitrust exclusions are emerging in industries like healthcare, driven by concerns about local monopolies or coordinated pricing behavior following an M&A.

Some carriers are also implementing cyber exclusions, which limit protections for board members regarding corporate investments in new IT solutions and in IT risk management initiatives. An emerging subset involves biometric exclusions due to mishandled fingerprint, eye or facial recognition data. Carriers will sometimes bundle a biometric exclusion with a cyber exclusion, creating double exposure for insureds.

Compete on Form, Not Price

These emerging exclusions underscore why chasing the lowest premium can leave insurers dangerously exposed. That’s why brokers should consider leveraging the fierce carrier competition spurred by the soft market to find the most comprehensive coverage for their clients, rather than just the lowest-cost policy.

Such an approach often benefits all parties. Insureds can better manage their risks at a more competitive price. Brokers may receive added protection from potential errors and omissions (E&O) claims. And carriers win quality business and form trusted, secure relationships with brokers.

To see how such a negotiation could work, consider the example of a broker shopping a D&O policy. The broker finds a carrier with room to reduce their client’s premium by $2,000. Instead of taking the full amount as a premium discount, the broker negotiates a $500 premium reduction, then uses the remaining leverage to increase antitrust coverage, raise derivative demand limits, lower retentions, add employed lawyers and soften the bodily injury property damage exclusion. The insured benefits from stronger coverage and cost savings.

Shop Carefully and Broadly

In the race for the best deal, companies may also encourage brokers to shop their policies aggressively in a soft market. Yet switching carriers could put the insured in a worse position, especially for companies with an open claim, and potentially create issues with continuity of coverage if the placement isn’t reviewed thoroughly.

For companies without pending claims, brokers must be thorough when shopping policies. Use benchmarking tools to compare the insureds’ D&O limits with others in their industry. Then be prepared to talk with 20 to 30 carriers to find a policy that removes key exclusions, delivers on price and puts the insured in the most secure position possible.

Brokers should evaluate carriers carefully based on the quality of their claims experience. Niche expertise is another important factor. A broker working on behalf of an insured that has transitioned to an ESOP, for example, should choose a carrier that understands the unique nuances of such structures and can tailor coverage to those distinct needs.

Limit Insureds’ D&O Exposures

In the D&O world, the majority of losses are related to defense costs. An insured can be fully innocent of wrongdoing and still suffer a significant loss. Brokers should educate their clients about this reality and offer these additional tips to reduce D&O-related risks.

Create a diverse board of directors. Encourage companies to be intentional about who sits around the boardroom table. Boards with members who are diverse in gender, race, geography and industry bring unique perspectives, often helping executives find the most innovative solutions to significant business challenges.

Form deep relationships with creditors and vendors. Insureds with long-term creditor relationships are typically better positioned to weather the financial hardships that affect companies during a period of prolonged inflation than those who switch vendors frequently.

Encourage employee feedback. Boards that request feedback when implementing new technologies, policies or procedures – and then make changes based on that input – are positioned to build a culture of transparency that mitigates D&O risks.

Keep Learning and Evolving

Unlike other markets, the D&O space evolves from year to year based on many factors, from inflation and trade policies to stock market volatility and social justice movements. That’s why brokers should stay on top of the latest news and gather information from a variety of sources, including those with opposing views. A well-rounded broker will be best prepared to help insureds protect their business no matter how quickly or drastically the market shifts.

Insurance's FNOL Blind Spot Costs Billions

First Notice of Loss has evolved into insurance's most fraught moment for fraud, yet carriers treat it merely as administrative intake.

Blind Spots

For 30 years, the insurance industry has treated First Notice of Loss as an intake event. A form to fill out. A call to log. A queue to manage. That framing made sense when fraud was something you investigated months after a payout, on a claim file that had already cooled. It does not make sense in 2026.

Today, FNOL is the single highest-leverage minute in the entire claims funnel. It is also the moment when the industry is most exposed. Roughly 10% of property and casualty claims carry some element of fraud or exaggeration, and the Coalition Against Insurance Fraud now estimates total annual U.S. insurance fraud at more than $300 billion across all lines (CAIF 2024; Insurance Research Council 2023). The overwhelming majority of that exposure is decided in the first claimant interaction, not in post-payment forensics. Yet the average carrier still treats those opening 60 seconds as a workflow problem rather than a decision problem.

Three structural shifts have changed the ground under FNOL in the last 24 months, and most of the industry has not caught up.

Shift one. FNOL stopped being a call.

The first thing to acknowledge is that FNOL is no longer one channel. It is at least five.

A modern claim opens across phone, chat, web form, direct message, and email, often in parallel, with photos and documents arriving asynchronously through whichever channel the claimant finds most convenient. A claimant who calls in might also upload damage photos through the carrier's app and submit a supplemental statement through a web form within the same hour. The single "call recording" that the industry's QA and SIU practices were built around is now one of five surfaces, none of which by themselves contain the full claim.

That fragmentation has a cost. The contradictions that used to surface naturally inside one conversation with one adjuster now scatter across surfaces that no single human reviews end to end. A claimant can say "no injury" on the FNOL call, upload medical imagery inconsistent with that statement to the photo portal, and submit a supplemental narrative that quietly raises a soft-tissue claim, with each of those three artifacts living in a different system. The fraud signal is the gap between channels. Most carriers cannot see it.

The line items underneath this add up quickly. Bodily injury buildup, the classic profile of the minor collision turned into the multi-thousand-dollar demand letter, costs the U.S. industry an estimated $13 to $18 billion annually, at industry detection rates of only 12% to 18% (IRC 2023; NICB 2024). Staged accidents add another $7 to $10 billion, with detection rates as low as 4% in some carrier books (NICB 2024). Personal injury protection mill activity in no-fault states accounts for another $10 to $15 billion (NICB 2024). Almost all of these morphologies begin in the first claimant interaction. Almost none of them are caught at that interaction today.

Shift two. The bad actors got AI before the carriers did.

The second thing to acknowledge is that the offensive side of the fraud equation reached operational AI faster than the defensive side did.

Synthetic documents, AI-generated damage photos, voice-cloned callers, and coordinated multi-channel fraud scripts moved from research curiosities to commodity tools in the last 18 months. Pindrop's 2024 Voice Intelligence Report tracked a 475% year-over-year jump in synthetic voice attacks against contact centers, with insurance among the top three targeted sectors. The FBI and FinCEN issued separate 2024 advisories on AI-enabled financial fraud, including specific guidance on voice cloning and synthetic identity. None of this is hypothetical anymore.

The implication for the claims function is uncomfortable but straightforward. The defensive stack the industry built between roughly 2010 and 2020, which consists primarily of post-payment forensics, structured-data anomaly detection, and rule-based scoring, was designed for a world where evidence presented to the carrier was, at a minimum, real. That world no longer exists. A carrier facing a deepfaked recorded statement, an AI-generated damage photo set, and a synthetic supporting document does not have a fraud problem that legacy SIU tools were built to solve. They have a verification problem at the front door, in real time, while the claimant is still on the channel.

Shift three. Compliance and customer experience are squeezed in the same minute.

The third shift is regulatory and operational. Carriers are being asked to do two things in the same FNOL window that used to be addressed sequentially.

The NAIC's December 2023 Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, the NYDFS Circular Letter No. 7 of 2024, Colorado SB21-169, and 3 CCR 702-10, and the EU AI Act's Annex III provisions for insurance decision making all push in the same direction. They expect documented, explainable, auditable decision support at every point where an algorithm influences a claim outcome. They do not accept "the model said so" as a defense.

At the same time, the customer experience side of the carrier organization is being asked to deliver frictionless digital intake, low effort scores, and same-day or instant decision making for low-complexity claims. The two pressures do not contradict each other in principle. In practice, they compress into the same minute of work, and the workforce most carriers staff at FNOL is not built to hold both at once.

Manual call QA helps less than it used to. Industry benchmarking suggests that most carriers audit under 5% of claimant interactions, sampled after the fact (Verisk 2024; LIMRA 2024). Rule-based bots cannot read intent, hesitation, coercion, or contradiction. The gap between what regulation now expects, what customers now expect, and what the existing tooling can actually deliver is the gap where loss ratio is leaking.

The category gap

There is a useful way to read the existing AI-in-insurance vendor landscape, which is to ask what each category of tool is actually telling you.

Detection tools tell you what has already happened. They scan claim files after the fact and surface anomalies.

Prediction tools tell you what might happen. They score claims, prioritize SIU queues, and forecast severity.

Customer experience automation handles workflow. It routes, summarizes, and responds.

The category that does not yet exist at scale, and the one the FNOL problem actually demands, is the layer that tells the rep, the system, and the SIU lead what to do right now, while the claimant is still on the line. Real-time, in the interaction, explainable, omnichannel. Not a dashboard for tomorrow morning. Not a score on a closed file. A decision-support layer that sits inside the conversation as it is happening.

That category has been the missing piece of the claims AI stack for the entire post-2015 era. It is what the next decade of FNOL has to deliver.

What the new FNOL operating model looks like

The carriers that figure this out will have four properties in common.

First, they will treat the claim as a single multi-channel entity, not as a call plus a form plus a photo. Contradictions and red flags will be surfaced across channels, not within them.

Second, they will operate in real time. The decision to fast-track, to probe further, to escalate to SIU, or to request additional evidence will be made while the claimant is still in the interaction, not three weeks later.

Third, they will be defensible. Every alert, every recommendation, every score will carry its reasoning, its source evidence, and its audit trail. Regulators are not asking for this politely anymore.

Fourth, they will close the loop with the human. The rep on the phone, the supervisor in the QA chair, the investigator in SIU, and the executive watching loss ratio will all see the same signal, in the same explainable form, at the same moment. The system's job is to give them the next move. The human's job is still to make the call.

A one-point loss-ratio improvement on a mid-sized property and casualty book translates to tens of millions of dollars on the bottom line (Verisk 2024). That is the economics that makes the new FNOL operating model a CFO conversation, a CCO conversation, and a compliance conversation, not only a fraud conversation.

Closing

FNOL is not a workflow problem. It has not been one for a long time. It is the highest-leverage minute the insurance industry has, and right now it is also the most exposed. The industry's defensive posture was built for a world that no longer exists. The tools we use to meet today's claimant interactions, fraudulent or legitimate, need to be designed for what the front door of the claim has actually become.

The carriers that move first on this will not save a few basis points on loss ratio. They will redefine where claims operations sit in the carrier's value chain. The carriers that move last will keep paying the bill, in larger and larger checks, for a problem that was always solvable at the very first minute.

Sources cited in the article

  • Coalition Against Insurance Fraud (CAIF), 2024 industry fraud estimate.
  • Insurance Research Council (IRC), 2023, claim fraud and buildup rates in personal auto.
  • National Insurance Crime Bureau (NICB), 2024, staged accident, BI buildup, and PIP industry detection ranges.
  • Pindrop Voice Intelligence Report, 2024, +475 percent YoY synthetic voice attacks against contact centers.
  • FBI and FinCEN 2024 advisories on AI-enabled financial fraud and synthetic identity.
  • LIMRA, 2024, Life carrier fraud and contact center benchmarking.
  • Verisk, 2024, contact-center QA coverage benchmarking and loss-ratio sensitivity.
  • NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, December 2023.
  • New York Department of Financial Services (NYDFS), Circular Letter No. 7 of 2024.
  • Colorado SB21-169 and 3 CCR 702-10, life insurance algorithm and predictive model governance.
  • EU AI Act, Regulation (EU) 2024/1689, Annex III provisions relevant to insurance decision making.

Strategic Framework for Unifying Insurance Data

Federated data models offer insurers a pragmatic unification path that accepts fragmentation rather than fighting it.

Unification

Insurance organizations are eager to unify their data, and it's difficult to think of a time when cloud-first data tooling was in a better or more competitive state. The industry has learned hard lessons from the “big data” era of technology hype, and making the scramble to AI capability easier is a compelling reason on its own to have unified data.

However, these sorts of projects have a track record of failure – not from lack of vision, drive, or even capital but from execution missteps endemic to insurance and other highly regulated industries.

This doesn’t have to be the case. With the right preparation framework, many pitfalls can be avoided before beginning major data projects. Better still, insurers can follow the advice that their agents and brokers would give customers. They can incur minor continuing costs (“premiums”) to protect against various catastrophes like blown deadlines or cost overruns.

Fragmented and Legacy Systems aren’t going anywhere

Many insurers are rightly proud of their history, but it inevitably bleeds into aging technology stacks. It’s a self-reinforcing loop, as the systems implemented 10, 20, or 30 years ago are relied upon and influence multiple data domains. Internal IT and development team members keep their skillset focused, since the business problems they solve are hard enough, and eventually, job descriptions – including for new hires – require experience in the legacy tech.

But even a longstanding system can’t expand everywhere. Insurance is an industry built on partnerships and connections among independent entities, with dozens of layers and players for an average policy. Similarly, when organizations grow through acquisitions, these software and data systems are typically retained in place, keeping fragmentation alive.

Buying a Data Unification Policy

Before embarking on a specific three-phase approach, there are foundational concerns that must be addressed. These require both concrete costs (time and money) and the ability to make clear decisions about specific topics.

  • Compliance and Security: Do we know how to store data from partners and internal systems? Control access to it from the start, and derive value from tokenization and masking?
  • Data Governance: Do we have a plan to do more than meet regularly to discuss governance? Are we ready to apply software-based controls to govern our data?
  • Data Reliability: Will we observe how our data flows to continuously test its quality? When it’s broken, will we know how and where to fix it?
  • AI Readiness: Do we have real use cases we’re targeting that we’re legally allowed to pursue? Do we know how to control costs and explain what AI tooling is doing?

These topics aren’t just technical, but there’s a clear and significant danger in staying away from the weeds. It’s worth coming to clear decisions about tools, architecture, and approaches. Even concerns like DevOps, cost optimization, and monitoring dashboards should be considered to a minimum level of granularity.

The other component of this equation, no less important, is achieving buy-in from business, risk, and finance teams. The former will be contributing significant resources to governance in any unification project worth doing. Knowing how to explain the value here is critical. Having a clear technical plan to show non-technical people will ensure their confidence.

Accepting Fragmentation and a Federated Model

It’s tempting to fantasize about a single monolithic data environment, perfectly clean and united, where truth and definitions are constants for every consumer. At a small enough scale (and low enough loss ratios), this is possible.

For the rest of us, however, the latest advances in cloud data technology offer a federated approach, where claims, billing, brokerage, and other teams keep their fragmented systems relatively in place. Instead of copying data into the monolith, queries with centralized compute but distributed connections are used. Fewer pipelines must be developed and maintained, data duplication is reduced, and each line of business has the ability to join the unified world at its own pace.

This approach only works if you’ve paid the premiums for your data unification policy. Without centralized identity and access management, security and governance become unsustainable. Without a unified governance catalog for federated data sources to feed metadata into, knowing where to get the data for a use case becomes difficult or impossible. Without data reliability, the few pipelines that must be built for each line of business risk failure, and a unified analytics layer will find its value diminished.

The federated approach can, at first glance, seem like a risk: analytic workloads here can be more expensive than those built on top of a monolith. This approach reflects how most insurance environments actually function. However, by mitigating risk upfront with dedicated planning and a pragmatic architecture, data unification moves from fantasy to reality.

The 4-Minute Mile of Cybersecurity

Historical threat data and AI are finally enabling cybersecurity teams to forecast attacks once thought impossible to predict.

Security

In 1954, Roger Bannister accomplished what many believed was impossible when he became the first person to run a mile in under four minutes. For decades, athletes, coaches, and experts viewed the barrier as a hard limit. Once Bannister broke it, however, others quickly followed. The physical capability had existed all along; what changed was the belief that it could be done. The four-minute mile became a powerful symbol of innovation—proof that perceived limitations are often waiting for the right combination of data, determination, and insight to overcome them.

Fans of HBO's "Silicon Valley" may remember the fictional entrepreneur Richard Hendricks standing on stage at TechCrunch Disrupt, attempting to prove that what many experts believed was impossible could, in fact, be done. The show's humor came from exaggerating the startup world, but its central theme was very real: transformative innovation often begins with a claim that sounds implausible until someone demonstrates otherwise.

Cybersecurity may be approaching a similar moment. For years, the industry has largely accepted that cyber threats cannot be forecast with meaningful accuracy. Attackers are too adaptive, environments too complex, and variables too numerous. The prevailing wisdom has been that defenders can detect, respond, and recover—but not predict. Yet history is filled with examples of assumptions that survived only until someone challenged them successfully.

Today, predictive cybersecurity may be facing its own four-minute-mile moment.

The Warning Signs Were Already There

If the past year demonstrated anything, it is that cyber threats continue to evolve in ways that create measurable patterns.

Throughout 2025 and into 2026, organizations witnessed continued growth in ransomware activity, increasingly sophisticated phishing campaigns, business email compromise schemes, and the rapid weaponization of newly disclosed vulnerabilities. Threat actors moved faster, leveraged automation more effectively, and increasingly exploited trusted relationships within supply chains and cloud environments.

At the same time, artificial intelligence began changing the economics of cybercrime. Attackers gained access to tools capable of generating convincing phishing content, improving social engineering campaigns, and accelerating reconnaissance activities at scale. While AI did not fundamentally change attacker objectives, it increased the speed and efficiency with which adversaries could pursue them.

Despite these developments, few of the trends appeared without warning. Many were visible in historical incident data, vulnerability disclosures, threat intelligence reporting, and cybercrime statistics years before they became dominant headlines.

This is perhaps the most important lesson from the last year: major cyber trends often emerge gradually before they become obvious. The challenge is not a lack of signals. The challenge is identifying those signals early enough to act upon them.

Organizations that can recognize emerging patterns before they become widespread gain a strategic advantage. They can prioritize investments, adjust defenses, and prepare for the threats most likely to materialize rather than those that dominated yesterday's news cycle.

That is the promise of predictive threat intelligence—not predicting the unpredictable, but recognizing tomorrow's risks before they become today's incidents.

Why Prediction Wasn't Possible Before

Historically, cyber threat forecasting faced three major obstacles.

First, there was insufficient historical data. Comprehensive cybercrime reporting was fragmented, inconsistent, and often unavailable.

Second, organizations lacked the analytical capabilities needed to process large volumes of threat information across multiple years and sources.

Third, there was little understanding of how attack patterns evolved over time. Most threat intelligence focused on indicators of compromise, malware signatures, and tactical observations rather than long-term behavioral trends.

As a result, cybersecurity became highly effective at detection and response while remaining largely reactive.

The industry learned to identify threats quickly. It never learned how to forecast them.

What Changed?

Several developments have fundamentally altered the landscape.

Over the past decade, major organizations have published increasingly comprehensive cybercrime and breach data. Sources such as annual incident reports, cybercrime statistics, ransomware tracking, phishing studies, and vulnerability disclosures now provide a rich historical record of attacker activity.

At the same time, advances in analytics and artificial intelligence have made it possible to identify relationships and trends that were previously hidden within massive datasets.

Most importantly, the cybersecurity community has accumulated enough historical evidence to begin recognizing recurring patterns in attacker behavior.

Cybercriminals may be creative, but they are not random.

Attackers follow incentives. They pursue profitable targets. They reuse successful techniques. They adapt to environmental changes. Like financial markets, supply chains, or military campaigns, cyber threats exhibit measurable patterns over time.

The existence of these patterns creates the possibility of forecasting.

Moving Beyond Traditional Threat Intelligence

Traditional threat intelligence answers questions such as:

  • What threats exist today?
  • Which vulnerabilities are being exploited?
  • What indicators should we monitor?
  • Which adversaries are currently active?

These are valuable questions.

Predictive threat intelligence asks a different question:

What is most likely to happen next?

Instead of focusing exclusively on current conditions, predictive models examine historical trends, environmental factors, emerging attack behaviors, and long-term patterns to estimate future threat activity.

This does not mean predicting the exact day, time, or victim of a cyberattack.

Rather, it means identifying which categories of threats are most likely to increase, which attack methods are gaining momentum, and where organizations should focus their defensive resources before attacks occur.

Forecasting weather does not predict the path of every raindrop. It predicts conditions.

Cybersecurity forecasting follows the same principle.

Testing the Hypothesis

The concept sounds appealing, but prediction without validation is merely speculation.

Any claim of predictive capability must be tested against reality.

The approach my team has pursued relies on historical cybercrime and breach datasets spanning multiple years. Forecasts are generated using prior-year information and then compared against subsequent outcomes.

The objective is straightforward: determine whether historical patterns can reliably forecast future cyber activity.

The results have been encouraging.

Repeated testing has demonstrated strong correlation between projected threat activity and actual outcomes across major cybercrime categories. More importantly, the forecasts consistently identified directional trends before they became widely recognized by the broader market.

While additional validation remains necessary, including independent third-party review, the evidence increasingly suggests that predictive cybersecurity is not only possible—it is practical.

Why This Matters

The implications extend far beyond threat intelligence teams.

For security leaders, predictive forecasting can improve budget allocation, staffing decisions, technology investments, and strategic planning.

For boards of directors, it provides a more forward-looking view of cyber risk.

For government agencies, it creates opportunities to prioritize resources and focus defensive efforts on emerging threats before they become widespread.

For cyber insurers, predictive intelligence may represent one of the most significant opportunities in the industry.

Today's underwriting processes often rely on lengthy questionnaires, point-in-time assessments, and historical claims information. These approaches provide valuable insight into an organization's current security posture but offer limited visibility into future threat conditions.

Predictive intelligence introduces a new dimension: understanding not only how secure an organization is today, but also the threat environment it is likely to face tomorrow.

That distinction could fundamentally reshape cyber risk evaluation.

The Next Frontier

It is important to acknowledge what predictive cybersecurity is not.

It is not a crystal ball.

It will not eliminate uncertainty.

It will not prevent every breach.

No predictive model can perfectly account for black swan events, geopolitical crises, major technological disruptions, or entirely novel attack techniques.

However, perfection has never been the standard.

Weather forecasting is imperfect, yet no one questions its value.

Economic forecasting is imperfect, yet governments and businesses rely on it every day.

Military intelligence is imperfect, yet strategic decisions depend upon it.

The same principle applies to cybersecurity.

The objective is not certainty.

The objective is better decisions.

Even a modest improvement in forecasting accuracy can help organizations allocate resources more effectively, reduce exposure to emerging threats, and improve resilience against future attacks.

Black Swans

Of course, no discussion of predictive cybersecurity would be complete without acknowledging the role of black swan events. A black swan is a rare, high-impact event that falls outside normal expectations and can significantly alter the threat landscape. In cybersecurity, examples include the rapid shift to remote work during the COVID-19 pandemic, major geopolitical conflicts that trigger new cyber campaigns, or the sudden discovery of a critical vulnerability affecting millions of systems worldwide. These events can accelerate, delay, or completely reshape established threat patterns.

Importantly, the existence of black swan events does not invalidate predictive models any more than hurricanes invalidate weather forecasting or market shocks invalidate economic forecasting. Instead, they highlight the need for forecasting systems to incorporate uncertainty, confidence levels, and continuous reassessment. The goal of predictive threat intelligence is not to eliminate surprise; it is to improve decision-making under uncertainty. Organizations that understand both the likely future and the potential impact of unexpected disruptions are often better positioned to adapt when conditions change. In many cases, predictive models can even help identify emerging anomalies early, providing valuable warning that the environment is shifting and that assumptions should be revisited.

Looking Ahead

Cybersecurity stands at an inflection point.

The industry has spent decades mastering detection and response. Those capabilities will remain essential. But the next evolution may be the ability to anticipate rather than simply react.

The combination of historical cybercrime data, advanced analytics, artificial intelligence, and growing knowledge of attacker behavior has created an opportunity that did not exist a decade ago.

The question is no longer whether cyber threats can be studied for predictive signals.

The question is how quickly organizations will embrace the possibility that the future of cybersecurity may be forecastable.

Just as Roger Bannister demonstrated that the four-minute mile was possible, predictive threat intelligence may ultimately prove that one of cybersecurity's longest-held assumptions—that the future cannot be forecast—was never a law of nature at all.

It was simply a barrier waiting to be broken.


Timothy O'Neil

Profile picture for user TimothyO'Neil

Timothy O'Neil

Timothy S. O’Neil, CISSP, CEH, is president and founder of AigisPoint Predictive Intelligence

A retired U.S. Army lieutenant colonel with more than 25 years of cybersecurity leadership experience, he has held senior security architecture and information security leadership roles across the healthcare, insurance, telecommunications, and consulting industries. He is the developer of the Strategic Predictive Threat Intelligence (SPTI) platform, designed to help organizations and cyber insurers anticipate emerging cyber threats before they become losses. 

Countdown to 'Q-Day' for Cyber Insurers

Quantum computers threaten current encryption methods. Cyber insurers must assess clients' post-quantum cryptography readiness before "Q-Day" arrives.

Readiness

The world is only just coming to terms with artificial intelligence (AI). But there's another technology far fewer people are talking about—one that could drive even greater social and economic disruption. Quantum computing will bring with it an extraordinary leap in processing power, but at the same time new data security risks for organizations.

For insurers, whose businesses rest on accurately assessing and pricing risk, this is a concern. And it's one that is growing by the day. Google recently brought forward its timescale for post-quantum cryptography (PQC) migration to 2029.

As a matter of urgency, insurers need to scrutinize clients' PQC road maps, as well as their own.

Quantum for good and bad

Quantum computers are powerful pieces of technology for several reasons. But most impressive are the qubits that power them. Unlike classical bits, which can be only one or zero, qubits can be both at the same time. That means quantum computers are capable of performing calculations thousands or maybe millions of times faster than today's most powerful supercomputers. This has major implications for the insurance industry.

Quantum-powered analytics could theoretically revolutionize how data is analyzed—for example, through powerful new predictive modeling. That could help insurers make better data-driven business decisions, price risk more effectively, and even reduce fraud, among other things.

However, the negative side of the ledger is arguably even greater for issuers of cyber liability insurance. So-called cryptographically relevant quantum computers (CRQCs) will be capable of solving the mathematical problems on which much of the world's encryption is based; in minutes rather than millions of years. That will be a security disaster for all the businesses that rely on asymmetric encryption, which is all of them. Protocols as ubiquitous as SSH (for remote access) and SSL/TLS (secure websites) use this type of encryption.

This is an urgent enough issue to address today—even if the timeline for CRQCs stretches into the early 2030s. But it's more critical than that. As far back as 2024, NIST warned about Harvest Now, Decrypt Later (HNDL) attacks. State-sponsored threat actors, in particular, are suspected of hoovering up large volumes of long-lived but encrypted data today, with a view to descrambling it when CRQCs emerge.

Urgent questions to answer

Insurers therefore need to answer several urgent questions. First are customer-facing issues. How does the risk associated with CRQCs breaking asymmetric encryption affect future payouts? And how should that risk be factored into premium pricing? There is a reckoning coming. Smart carriers will already be looking to gain more insight into the PQC plans of their policyholders and prospects.

Next, insurers need to think about their own businesses. When CRQCs land, their own data will be at risk, unless they migrate to PQC standards and infrastructure. The final piece of the puzzle is the supply chain. Insurers need to ensure their connected ecosystem of resellers, reinsurers and brokers is also taking PQC steps to protect their data. Threat actors are past masters at finding the weakest link in the enterprise security chain. And very often, that is an under-secured partner or supplier.

Planning starts now

As of last year, just 5% of global organizations had deployed quantum-safe encryption, according to one study. Given HNDL attacks are already happening, this needs to change.

Yet moving to PQC is no simple task. Legacy systems are everywhere. Those relying on hardcoded cryptography will be particularly time- and resource-intensive to update. Key management software will need to be redesigned. Certification and compliance processes will need to be reconfigured.

Asymmetric cryptography spans the entire corporate world. It keeps financial transactions secure, websites protected and messaging chats safe from prying eyes. For organizations to truly minimize risk they will need to get PQC assurances across extensive supply chains.

To insulate themselves from future losses, insurers therefore need to start checking how their current and prospective policyholders are planning to address quantum risk. Organizations need a complete understanding of what type of cryptography they're using, where they're using it, and what data it is protecting. Then a risk assessment can be properly run to ensure the most critical data is protected with new PQC algorithms first.

If no such steps are put in place, insurers must assume that the risk of data exposure will continue to increase for enterprise customers as the Q-Day clock counts down.

Looking inward

Insurance companies need to look at their own systems, data and applications with the same rigor. And be prepared to make potentially painful changes to mitigate CRQC and HNDL risks.

The risk does not stop at the front door either. Data in cloud environments, at the broker's office, or transmitted via marketplaces and reinsurers could be compromised by a CRQC. It is imperative to extend PQC plans to all of these environments.

That won't always be easy. PQC keys and signatures are much larger than existing ones, potentially increasing storage requirements. Processing these algorithms may add latency to time-sensitive environments. And legacy hardware like routers may need completely replacing if they can't take the requisite firmware upgrades.

A regulatory imperative

However, standing still is not an option. And with regulators circling, doing nothing may even put insurers in legal jeopardy. Quantum computing promises much. But before we harness its potential, we must first mitigate its accompanying cyber risks. That work should start tomorrow.