Cyber Insurance Beyond Data Breaches | Michelle Faylo (Full Interview)
Michelle Faylo · September 29, 2026 · 55:17
Back to EpisodeWelcome to the security cocktail hour. I'm Joe Patti
I'm Adam Roth.
Adam,
we're lucky today. You know, we always say we're cyber guys and we're really risk managers, but we have someone on today who probably knows a hundred times more about risk than than we do. We're like amateurs. We've got Michelle Faylo. Michelle, welcome.
Thank you very much. Happy to be here. Great to see you guys.
Great, great, great to have you on. so you know, one of the things we've been talking about a lot on the show lately, because it's kind of our thing, is not just cyber, but how the the real world is coming into. You know, we've been talking about drones and and surveillance and even, you know, Adam dealing with the ethics of cyber warfare and all the things that are going on there lately.
You are actually a very experienced and knowledgeable person in the in the world of insurance and writing cyber insurance. So I've gotta think this is something you're seeing a lot these days.
yes. yes.
Everything just what technology is embedded in now. how the lines around privacy are being blurred, right? What is what do people even view as private? What is confidential to them? It varies person to person. And technology is embedded in everything we do, everything we touch, washing machines, the car we drive, it's it's everywhere, it's everything. So it's it's very risky.
it's very active. There's and then when you add AI, everything that's going on with AI, that's a whole nother element to what's happening with cybersecurity, technology, privacy, data breaches, what activity looks like with threat actors, it's constantly evolving. Entertaining, job security.
So that's int
that's definitely interesting. So you're I I think you you're alluding to if you're an organization and you started implementing AI in some aspects of your business, that might raise your premiums and your and the likelihood to get compromised or maybe something happened. Yeah.
Without a doubt. With without
doubt. So AI is impacting companies that are using it, right? Because we all want to work faster. We want to accomplish more with with less. you know, we're managing how many people are are working on anything with their hands, their minds, but mistakes that they make, right? So how can we use computers to fast track all this? But that also means things can get messy very quick. on the other side of that is threat actors are using all the AI too, right? They can use that technology to
scan environments ten times, a hundred times, a thousand times faster. So instead of doing manual labor and research, right, this fast tracks the way that they do their research and the impact ultimately that they can have.
I I just got back from Estonia. I went to this this this this cyber conference on cyber conflict and one of the things that everybody is talking about is how threat actors are not only using L LMs or AI to create that malware, to create that aspect of how to compromise an organization
Right.
but they're using the threat actors are using the same LLM that they use to create the malware to search their own malware
To search for vulnerabilities so they can close
Right.
them up and w and that's exactly what they were talking about that the speed in which an AI or an LLM can compromise is ten, twenty, a hundred times faster than it ever was, and sometimes so I I'm assuming you're not, you know, insuring threat actors, thank God, right? But but but it's so hard to keep up with those techniques and tactics
The TTPs so it must be crazy.
It is right.
It is. It's it's very intense. there's a lot that's developed over the last ten, twenty years in cyber insurance and in the cyber insurance market. But what has happened is a lot of insurance carriers have really focused on data breaches, failure of security, you know, the release of confidential information, or I would say non data breach privacy, where it's the you know, the release of some information without actually it being a data breach.
But that is cyber insurance, right? Cyber insurance policies have been drafted to respond to those scenarios. What underwriters have kind of shifted away from is errors and omissions coverage and understanding errors and omissions, because
You know.
AI really falls under an errors and omissions policy, right? So it's technology,
It does.
errors and omissions, it's software and all these different capabilities that are created by these companies. And then they're going and selling it if there's an issue, if there's a hole, there's a gap.
There's something wrong, if there's a bias with the model, all of that can create litigation, but it's not necessarily going back to a cyber policy. It's going back really to an errors and omissions policy, employment practice policy, things like that. So the insurance community really needs to come together to understand AI as a peril, right? Not just one policy. Same thing with cyber insurance. Cyber, you can have financial loss, but you can have physical damage. That happens as well, right? Property damage, bodily injury. Same thing could happen with AI.
And AI is growing. I mean, one of the stats that I read is AI is is growing 700 times faster than the internet. Right. So think about how fast we got hot mail addresses and Yahoo addresses, right? Think about like these little tags that we used to have in our emails. This is growing that much faster and it's popping up everywhere. So it is it's very complex. it's creating a lot of curiosity for the insurance community.
A lot of it right now is covered under an errors and omissions policy because how the the language is drafted. But time you know what's gonna happen? Time will tell. Wait till the claims come in and then things start to shape. And we didn't really intend to cover this. Well then you now you're gonna start revising language. So the lawyers the lawyers will keep busy. Don't trust me, the lawyers are on top of all this. They
lead the
Yeah.
paths, you know, of all that litigation and class actions and all that. so don't worry, in due time we will be hearing and reading about this in the headlines.
They're the ones making the money.
Yeah, well that's
Yeah, go ahead, I'm sorry.
Th they make
all the money. It's not the
Yeah. Yeah.
impacted individuals that get their, you know, duh you know, fill out this form and get your twelve dollars. Twelve dollars is actually pretty amazing. Usually it's, you know, fifty cents or two bucks. But the lawyers, yes, they make all the money.
Well that's really interesting what you're saying about the errors and omissions, because you know, I've gotta think that at least, you know, when when I was doing it, if you get breached, it's your cyber policy that covers you. And you know, and if they breach you with AI, well then it's still that. But what about in a in a case where you know everyone's writing their software now with AI? They're all like, it's all Claude Code it's all all this stuff,
and it's not always great, so if that introduces a vulnerability into
Mm-hmm.
a product, I mean we think of it as a as a cyber thing, but is that then an errors and omission? Like you you better have that coverage too or
Well, yeah,
it it depends, right? I mean, this is the famous words that all the lawyers say, it depends. Let's see the claim come in. But yeah,
It de w we use that too a lot, you know.
so but companies a lot of majority of companies are not necessarily just getting something off the shelf, but they're not necessarily building anything from the ground up either. They're buying parts of algorithms and and pieces and links to a chain that they can ultimately incorporate into their environment and morph in different ways.
But what now what we're seeing right now is the large majority, they're using other parties for that stuff to kickstart that stuff. And so yeah, that that it can come in and trigger policy. It depends if it's at the first party event or a third party event, right? Are you impacted? Did it create a business interruption or something like that? But all these companies are so intertwined now, and you think about dependent business, right? Who's relying on you to make a widget? Who's replying relying on you, you know, to provide some sort of professional service?
Companies are so intertwined, no one company is doing everything now. So there's a systemic element to it too, because insurers are looking at errors and omissions, they're looking at security failures, right? Privacy events, but then they're looking at who's relying on business and how that upstream and downstream, how that could impact things and the size of a loss because of something like that. It's incredible. Large majority of the time you're reading about these data breaches that are happening that you read about or see in the news.
You actually don't know the folks that are behind the scenes and the lengths that, you know, i i the the chain of events that happen to actually get to the breach. Nine times out of ten, it's not the entity in the headline, it's someone that supported them back office, a back end some way, provided them some sort of piece of the software that gets integrated or manipulated some way into their own system. And it gets real complex real fast.
bring up a weird aspect of this that people are gonna look at they're gonna say, What? But what I'm seeing
Yeah.
now is and I'm gonna get to the second part in a minute, but people are util utilizing humanoids in their own homes, like the Tesla robots, those are endpoints to their network. They're gathering
Right.
data, they're gathering information, they're full of information. And I'm just curious, does those do those humanoids or robots
that are doing tasks, that are collecting data, that are storing data, and this is what Joe and I have been talking about recently, and the drones themselves that are endpoints, that are that are edges to a network. Yes, I know they fly, I know they have their own issues and their aviation and they can crash, but those devices are endpoints to a network that gather and com and hold data, sensitive data. And they're
That's right.
they're instituted into these networks either via cell cards or other things.
Are those entering into the same type of insurance?
Yeah, they're all considered as endpoints when you're looking at a policy and you're you're building out and understanding what the risk and exposure looks like. You're asking about all of that, right? Where are all the windows that are open, the doors that are open, how often are your neighbors coming over, right? Who are you loaning your keys to to get into your house and all of that? All that is taken into consideration. And those are still those AI agents and robots, they're they're still considered computers. They're not considered, even though they might have that human behavior, try to have that human behavior.
There's still at this point in time still compo considered computers and part of computer systems. So it's still very much included in what the way the insurance policies are already drafted.
Okay then. So then we get back to the physical stuff because then we're talking
A little while back about, you know, autonomous systems and what happens when a drone flies into you or lands in a highway or a robot goes and really breaks something badly. you know, I never thought about it because always I've always been involved in cybersecure in cyber insurance, where it's always been, you know, strictly, almost strictly breaches and and privacy. That's it. We never had to worry about the liability of physically breaking something.
Right.
is is that
Something that still goes on cyber or is that I don't know, something else. I I don't even know the terminology.
Yeah, there's there's
a few companies out there now and there's there's traditional insurance carriers, like you have like the insure techs and the heavy tech type insurance carriers that are developing specific AI policies. Now they're not there I've seen quotes, I've seen policy language, but nothing's been tested yet. So there's still a question of what's covered in a current policy, E and O and cyber, versus what's covered in this AI policy. And the AI policy does
It brought in s some key definitions and brings up in some of these factors. It talks talks about the large language models and things that could go wrong and it will get more AI specific, but those policies haven't been tested yet. it's also very hard to how do you price for something like that, right? So you're kind of throwing a dart at a dartboard right now because you don't have a loss history, you don't have these hard examples yet, you don't know the regulatory environment in this whole space yet. So it's very hard to figure out what pricing looks looks like for that.
And then these these big AI companies that might want a manuscript AI policy with that title and is customized and built for them, the language is still in draft form and the policy limits are actually not really there yet. So these AI policies might have five or ten million dollars in limit. You think about autonomous vehicles,
Wow, that's nothing.
right? If you're thinking about autonomous vehicles and all this other stuff,
I could do a lot more. Yeah. Yeah, that's nothing.
bodily injury, property damage, systemic risk, you're talking hundreds of millions and billions of dollars of losses.
Like it's gonna take a lot because no single company is gonna put up those limits. It's a group of those companies. It's reinsurance, it's backing. So again, it's like that this whole domino effect. So there's still a lot that needs to be developed because these markets are saying, Well, I want to see a clean come in first, right? You we're throwing kind of darts at a dartboard and and we're we're coming up with different scenarios that we could run through, but there's only so many things that we could run through as humans based on the experience that exists out there already. So it's gonna take some time to develop.
So w we we we s we have an episode coming out having to do about our autonomous drones delivering packages. But the funny part about it is that that that autonomous network that that those drones while they while those drones are flying and we've also talked about bot networks, right? You take over
Mm-hmm.
a bot you take over the all these wash machines, all these dryers, all and then
That's right.
and then they attack a network. Imagine that somebody compromises a drone bot network, but instead of them doing
electronic or cyber s bot network and they're attacking the network. Now they're physically attacking buildings. So
Yeah.
so th so I want to be the underwriter that writes that. I want to figure like, whoa I think the po probability of a drone swarm crashing into somebody's house is ten to one. So let's, you know, wr you know
Yeah, do you remember these movies from like years and decades ago where there was like flying things and just
Judsons?
yeah, like all this stuff
Yeah.
and you think about it and you're like, no, that's very much here, right? Your neighbor can have a drone, companies can have a drone. I was just at one of the the FIFA games and there were drones all over the place. And we were like the security was super intense, right? There's thousands, tens of thousands of people, and nobody actually knew where the dr who owned the drones. We're like, is that is that
This location?
Yeah.
Is that private people? Is that some kid taking aerial shots? You don't you don't really know all the time what's up there, but you can
Yeah.
easily manipulate these things. They're machines, right? You can get somebody behind the wheel that shouldn't be there and now they're doing things that they shouldn't
be doing.
Me.
I'm known as one of the world's worst drone pilots. I destroyed mine on its third flight, so you don't insure
My dad used to have
me. That's it that'd be insane.
Yeah, the the airplanes
So yeah.
way back in the day and we used to go out in the field and watch these airplanes. They're actually very hard to control. All the those the drones, you know, back in the day it was the the airplanes and now it's the drones, but it's not easy. You need a license, basically.
Well,
I I I I I'm a UAV pilot, but you know, we also had another episode that came out and we spoke about drones and the that every dr every FIFA game is a w is basically a Super Bowl. And the issue with drones is that you can detect them. You can use S DR, software to find radio. There's plenty of products out there that could detect signatures, but the biggest issue is not even law enforcement agencies can take down a drone. i it's
The military can use certain drones, they can use certain
Mm-hmm.
EMF guns and you know electronic magnetic frequency to control it and try to try to jam it and bring it down carefully. They have other drones that use nets to capture it. But the problem is, yeah, you can detect a drone. Yeah, you can know a drone is there. But what you can't do is take it down, 'cause it's unlawful to take a drone down. So that's that's the interesting part, right? You can insure a drone for capturing data or for having data
But you know, if a drone is gonna swarm or a drone's gonna come to your event and Joe and I spoke about this from doing public events or own stuff, you know, you can put canopies in place or they can't see or record you. You can use certain d certain ways of of isolating VIPs from being attacked, but what you can't do is stop the drone physically from doing what it's doing. It's very extremely hard.
Yeah.
Yeah, the joke seems to be you don't wanna have the drone come out of the sky and hit a bus full of nuns. That would be bad. So
Yes. And w there's never w just one drone either. Wherever there's one, there's many more that
Lots, yeah.
are out there. So even if you'd knocked one down, right, there's another replacement and reinforcements coming shortly.
Okay, so let me ask you something, you can maybe solve a misconception I have, or which is prom probably totally incorrect. way, way back I actually worked in IT for an insurance company. And I remember them saying, you know, underwriting is amazing, it's all these statistics, these guys with with everything. And they would say, like, look, you give me your vital statistics or whatever, and I can practically tell tell you when you're gonna die. You know, I mean in the aggregate, they'd say, or
Thanks. I don't want to know.
Yeah, I don't wanna know exactly.
But I mean I think you kind of touched on it earlier with some of these things that are so unknown, like with AI, where we not only have any history of what they're gonna do, even the people creating the stuff have no idea what it's gonna do, whether it's gonna
Yeah.
work or not with a lot of things. I mean, how in the world do you do you insure that? I mean my really simple thing, how do you know what to charge? I mean,
what your loss is gonna be.
Yeah. Well, right now it's based
on the facts, right? So what does a tech E&O policy cover now, right? So it's the hardware and software and the support services and everything going around, you know, that offering. the E&O has decades more of experience than cyber policies do, right? Cyber policies still have only been around. We've gone through one really rough cycle with pricing, but that's nothing, right? You need more of that to really shape it. So
Right now it's it's questionable. People are looking and saying, well, this is your computer system. This is an expansion of your network. This is device drones are still connected to your network, right? It's just an extension of that. And the tech E&O is expected to already pick that up. So right now it's a very soft market still in cyber insurance, but this is going to be definitely something that starts to churn and firm up the market and firm up that pricing. And I can see insurance carriers pushing more on that E&O.
to level set what the pricing looks like until you do have the experience to come in and actually something to kind of get more surgical on and dissect. But right now it's there's there is an element of throwing a dart at a dartboard. Yeah.
So so you so you mentioned that the that the cyber insurance market is soft. I mean the the last time I was dealing with it, which was maybe three, four years ago, it was not soft. It was really tough. People were scrambling to get to get coverage.
Yeah, unassurable, right?
yeah, and the ransomware hasn't gotten hasn't gone away. I don't know, that was a big thing. Kinda Yeah, so
Yeah, right. Ransomware's never gonna go away. It's
so what's what's happened? What's changed there?
So there's
the market is still it's soft now. Yes, there was during the ransom like ransomware peaking and kind of these worlds and the the stars were aligned and everything was really coming together where car multiple carriers were being hit at the same time. All segments, all industries were being hit. Before it used to be, you know, retailers, healthcare companies, the obvious, right? Who has credit card information, financial institutions, like health information, where's some of this obvious stuff?
Manufacturers, you couldn't sell a cyber policy, you couldn't give a cyber policy to for free to manufacturer. But then ransomware really started to change that because these start actors would get in the system, you know, they'd be able to get into one company, but then jump into another company, right? Because you have a lot of these companies that are intertwined. That caused all the pricing to go up. Losses were skyrocketing, rates started to go up. If you didn't have key controls in place, you could be completely uninsurable. You can get a non-renewal.
Yeah.
The entire market could look at you and say, Nope. I had situations at the time when I was on the underwriting side where I would see 200, 2000% price premium increases. It was it was crazy.
god.
So, but now what happens on the side of all this, right? The the
Mm-hmm.
carriers, you have your traditional markets that are in it, you have your insure techs that are in it, and like bringing that it's that next wave of in of insurance capacity.
And then you've got a bunch of newbies that are saying, we don't really write cyber, but I would like to get two million dollars for something or five hundred thousand dollars for something that would have otherwise maybe been fifty grand or a hundred grand previously. So you had a bunch of markets come in. So where in some insurance markets were really saying, Hey, listen, we're gonna really cut back on how many policies we're writing, we're gonna manage our limits, we're gonna manage how penetrated we are in certain sectors and in segments.
Other markets came in and said, Well, we're gonna scoop that up and take advantage of the pricing being up here. They didn't necessarily have all the underwriting skill, right? And they didn't, right? They're new to it. You have to you if you do learn underwriting account after account, having a claim after a claim. You learn, you have to learn from the claims, right? and so what was happening is these markets were coming in and all the buyers, the the markets expected to win back these accounts.
At a better price in in a better c condition and under better circumstances. But instead, all these new markets came in and wanted to get a piece of that pie, and they're there's still the same number of buyers. The non buyers were like, the pricing is too high, I'm never gonna buy them. So now where we are is pricing is very competitive. There's a lot more markets that are even. There's over 200 cyber insurance markets, without a doubt, right now. There's there's hundreds. they all claim to be yeah.
That's a lot more than there used to be, I know. Yeah.
They all complain, you know, they all complain about what's going on. Everybody contributes to rate decreases. Like nobody wants to lose that account that they're on because it's hard to win it back. It's hard to find seven figure premiums that exist right now because somebody else is coming and saying, Hey, I'll do that for 20% less. Hey, I'll put up $10 million a limit instead of five. And so more markets, more capacity. Pricing is is super competitive. And so, you know, whenever you want to go out and try to get an increase.
You've got some other market swooping in saying, Hey, I I'll I'll do that and I'll do you one better. So the pricing is soft right now. Even with everything going on, it's still soft right now.
I can see that, but the thing that's totally ringing in my head from what you said is all these new markets with aggressive pricing, I mean, can they can they pay the claims? Do they even have any idea
Well
what they're on the hook for?
well that that's to be seen, right? We've already seen yeah, well I mean
wow. Okay.
that we've already seen some of these markets pull out of certain industries, right? Healthcare and municipalities continue to scare folks, airlines. I don't know an airline that hasn't been hit with something, right? Their airlines are always in the news. and so th there's definitely problematic classes of business that folks will just turn away from. So there's less capacity.
But there's still so much capacity, you can still get creative with how you build a tower. So
So
yeah, I every time I think of insurance and probability and and risk, I think about Ben Stiller, I think it was, in that movie with Molly, I think it was. That woman. So t so are there any of these
Along came Polly. He was an underwriter and he was paranoid and freaked out and
Crazy VIPs from companies, obviously you can't say who, that have that level of like, I wanna get insurance for a certain risk, maybe in cyber something that's never been done before. Is there any like one offs?
There's always some companies out there that are dabbling in things because they want to be the first one, right? That's how you grab
Mm-hmm.
headlines. That's where you're making a lot of money. That's where, you know, companies then go public. I mean, it's it's a moneymaker for sure. There's definitely companies that are out there that are really testing the limits. insurance policies, you need experience and history to to be able to underwrite these things. So there we'll find markets that will work with them and create custom language for them, but it's still gonna be hard to maintain it.
Right. If there's reinsurers in the background. So you can have an insurance tower, but if there's reinsurers behind you, they're always gonna handcuff you too and provide some limitations on things. It's very, very complex. There's a lot of layers to it. but there's definitely some companies that are pushing the envelope. Those are the
Yeah.
best underwriting meetings to go to, because even if e as an underwriter or a broker, those are the meetings I like sitting in. I can ask any question. I can ask anything I want. It doesn't mean they're gonna answer it, right? But like hearing some of these things.
Sitting in meetings, yeah, that's amazing. And then walking out and going, Are you crazy? Like, what is happening right now?
I know insurance for a lot of people can be a dry subject, but y you you must have y
It is not dry.
y you you must have some crazy stories about stuff that's gone on.
There's
I there's been a number of meetings, you know, over my career that I've been in where we blatantly ask questions and the a company will say, No, no, no, no, no, we're not doing that and then, you know, months later there's a headline that somebody's doing something and launching and launching a product and we're sitting there going, like you know. But you gotta realize these big companies, they also carry a lot of weight, right? Look who's sitting on their boards, the impact that they have. Like it's
There's a lot of it's very complicated, very twisted, crazy little industry that we're in here. It's definitely entertaining.
Give an example.
Yeah, Charles Bolden, he was he was on our podcast, he's an astronaut, beautiful, incredible, incredible man. And this man, we were discussing about that there's internet on the ISS on the International Space Station, and we're talking about there's a proxy at Goddard, which is NASA's one of NASA's locations.
Yeah.
So I'm saying to myself, What? You have WhatsApp and Facebook and other apps on the space station? How
Yes.
does that proxy work?
And I have to imagine like a
So it must be a good one.
company like yours might be the one insuring them or something. I don't know.
Yeah, there's a lot that's happened. you know, there's we I've seen a lot more companies that are involved in space stuff, like aerospace, even nautical boats, things like that that are happening, you know, in deep sea. There's I mean, what you think is happening in space in the air also happens in the water. Like there's a lot of things that you don't hear about.
Of course. Satellite
There's a lot that you that we're doing because that's how we see what is happening around the world, right? That's your set of eyes
Yeah.
for machines to go see what's going on in the rest of the world. So yes.
There's windows and doors that are open up in space and the little green creatures are, you know, hacking away at that too.
That
that's gonna be next month. Like when they when they land, you're gonna have to ensure some of the things they're doing. But that's exactly it, right? At at that NATO
Okay.
conference they were talking about GPS spoofing and that's from satellites. And that's one of the biggest issues that threat actors and nation states are doing. If they
Without a doubt.
if they compromise your GPS on your on your on your boats, if they compromise on the tanks, on the drones, you're gonna have these
That's right.
big issues. So
GPSS spoofing is is a very big issue and once you're compromised, your whole entire network goes up in smoke and almost literally, which is why we talk about cyber conflict using ethical warfare, because
Right.
not only does it affect w and that's that was one of the basis of this conference, that civilians are the are impacted by nation state and government cyber wars because
at the end they they're compromising their their their their their networks, their infrastructure in order to is
Right.
in order to create havoc.
Yeah. I mean, anything that that is happening in other other countries, you know, people are like, are we gonna get attacked? Are there gonna be bombs and things going around? It's like you don't need to leave your chair. Like you don't have to get in a field anymore, you know, with a knife and whatever and rifles and everything. You could just sit in a computer in the comfort of your own home with a nice cough tail and and go crazy. You could do everything from that chair. You could, like you're saying, impact those GPS.
you can impact coordinates, you could just turn everything really against itself, right? So things could be crashing, right? Trains, you think about trains, positive train control and all that. You cannot they these countries want to cripple other countries. They don't necessarily want to even blow them up, but it's they want to cripple you. They want to impact your systems and your infrastructure. They want to take out your power, they want to impact your water supply.
Right? Even water. Water gets pumped up from the earth, but then it's cleansed and it goes through a whole machine, you know, in a a cleansing and purification process. It's all computers, right? You could easily taint that right away. There's you could get access to all of this quite easily.
Right, so you know, that makes me think of as we start getting into the real world and the
Yeah.
kin the kinetic world as we like to say being fancy. I remember that a while ago there was something in cyber where what was it? There there was a like a standard insurance exception for like acts of war and stuff. And and a company tried you know, invoking it because someone got hacked and they said like, no, this is a nation state and this was
You know, this was not business, this was warfare or something. I don't even r remember how that got resolved, but we're seeing a lot more warfare now and cyber warfare. where does that stand? I mean, you know,
Yeah.
we we we would always worry about when when I was working, being either directly attacked by a nation state or just kind of being collateral damage, so to speak, in the in the cyber world.
Yeah. So the war exclusion language that exists, it's been picked apart, it's been drafted in so many different ways. at the end of the day, there's a lot of activity that can come out of a really tough country, right? A c a country that people are not super friendly with and has really isolated themselves and we can all guess who those countries are. and but there's a lot there's a lot that's not necessarily happening directly from that country. It could be
people within that country, it could be people that have that nationality and background but live right here in the United States. And they could say, we support that that thought or way of thinking or, you know, the things that they're pushing for, fighting for, you know, and what the conflict is arising from. And the burden of proof is still on an insurance care carrier. And it's the the big word and it's all that attribution, right? That's the word that keeps coming up. And it's it's very hard to prove that, right? There hasn't been anything
contributions near impossible,
especially
when you're talking about the big guys.
Exactly. It right.
And even everything that was going on now in the the the you know international and geopolitical environment, we didn't see any we had a lot of people asking about the war exclusion again, but we didn't see claims that were were picked up and referencing the war exclusion and hitting the headlines. You didn't see anything in the news about that. So now you know, now it's it's it's really, really hard to prove. and again, we're gonna have to see more of this stuff happen, like the way that
The US communicated with Iran and what was going what goes on with Russia and Korea and all this nonsense is it's really interesting to watch. And there's a lot of things that you could point fingers at, but you have to prove certain things happened and there's certain qualif like qualifying events and there's an order of events, and that has not happened. So they can't invoke the war exclusion and say this is not covered. The other part of this is if something were to happen, right, and you were to say war exclusion, right? Because
You have to be careful what's happening with all these insurance companies. We as much as we have all this capacity now, we can't just see poof and have all the insurance companies go away. There's no financial backstop right now that would help the cyber insurance environment, you know, and support through the government if something big were to happen. And that's another part of this. Like if we did invoke the war exclusion or if we or we had this systemic event, how do claims even get paid? There's still only much what do we mean, printing money in the basements to pay these claims. Like systemic risk is a real thing.
reinsurance is a real thing. The financial backstop and the involvement of the the government to kind of dictate which way traffic is going, how this stuff is reviewed and understood is still kind of in limbo right now. We don't have that backstop for cyber like we do for other lines of insurance. So another layer of complications.
It's like stuck yeah.
It's like Stuxnet, Joe, right? I mean Stuxnet, you
Right.
know, it's one government and another government, but the transmissions were through regular corporations, regular emails. Yeah, I understand there was an air gap part to it and it came with a USB,
Right.
but eventually the whole idea behind that PLC, behind that malware was to literally not be active to to be communicable. Almost like a like a like excuse me for saying it's like an S T D
It was passed from one to another, but it only targeted that specific PLC, that specific model, that specific type of PLC in order to compromise it. And that and that's what happens with these nation states now, right? They use the transmission of ordinary bots, ordinary companies. They compromise you know, providers in order to bring their malware down into normal companies that eventually get to contractors and other things. So this is where we are today. We're using
c commercial and civilians to were targeting them, you know, all nations basically, in order
Yeah.
to eventually get that malware, that that that information eventually to some kind of government contractor or or the government itself.
Yeah, I mean, you know, I never thought about it in these terms 'cause I'm, you know, more of a technology guy. But you know, what you just said that if in case there's a systemic event, everyone's making claims, things happen, that
Let's read it.
there's no government backstop. I mean, we're at we're at the point in cyber now where y you can't operate, you can't do business without cyber insurance.
Right.
I mean, I can't imagine if s things started happening and
Companies really go out. They have huge
Yeah.
loss of business. They have huge investigations. It takes a lot to get them stood up and if they can't get paid for that, my God, that would be disastrous.
Right. This is why we
it really is. And it's it's so complicated, right? It's not like
Uh-huh.
a single event. There's it's the in how these businesses are intertwined. It's how you can buy software as a service, right? SaaS, and you can completely use it off the shelf or you can manipulate it in a new way into your system. Like we're we're constantly creating new layers of complexity to all of this. The E&O part of it, the online, offline cyber, true cyber part of it.
The peril part of it, right? So if you even think about cyber policies, there is no single cyber policy that covers all acts, first and third, physical, non-physical. Those four quadrants are not covered in a single policy. Think about what's gonna happen with property insurers and casualty insurers, right? This is gonna it kind of got kicked out of property. They they signed off and signed slips covering it, and then they came back and they're like, now we're gonna sign exclusions, go buy cyber policy for it. But as things get more physical,
and end and the the end result is more physical, that bodily injury property damage, you're gonna see prices and and more coverage baked into those policies and you're gonna start to really see cyber as apparel. And it's that's when I really think that the government will put pen to paper and start to get that group and you know team of folks and cohorts and whatnot together to to problem solve and figure out how we're gonna address this. Cause it's it's it's eventually gonna happen. But we wait
yeah.
until the eleventh hour.
buildings on fire, right? That's not the best way to go about things. We shouldn't we shouldn't be waiting that long.
We we have another podcast coming up shortly, by a gentleman that I met in one of the NATO conferences and and we spoke about you know, people like Joe and I, we were lucky, we work for an enterprise and a lot of times insurance is mandated by these organizations in order to do business with customers.
Yes.
Customers say you want to do business for me, you need this this this type of insurance. You
Yeah, you have to. Yeah.
gotta be audited, you have to have this, you have to have that. But these smaller businesses
They can't afford cybersecurity insurances and that might they might not even be mandated to have it. For example, it
Yeah.
might be a mom and pop insurance company with twenty five people working for them. That's still a mom and pop, but they're still making a significant amount of money, have a significant amount of customers, but but E and O insurance, the level they might need, they they might not be able to afford. And one of the
Yeah.
again, the aspects of this this conference I went to SideCon was does the government have
Have an obligation to provide some kind of support, some kind of monetary, some kind of help for
Yeah.
these smaller companies that are being targeted by nation states, by governments, since they are, you know, like if for example, if you're walking down the street and you know, there's people attacking you, but they're you know, there might be terrorists, does the government protect you? Of course they do, right? They they they have to come in and have
Well yeah. Yeah.
to
Do I police the area? But we don't have that with cyber, do we?
Right.
There's we don't. we've seen in the insurance community though, a lot of these markets what they're doing now is offering education and di major discounts to integrate certain controls or or you know, incorporate, I should say, certain controls in the r at the right endpoints, right? 'Cause a lot of folks, a lot of companies will say, We have all these controls in place, but are they at the right endpoints? Like it doesn't matter what you buy.
If it's not in the right place at the right time. So these companies are now starting to come together and looking at all of the different activity that's ha that has gone on, taking lessons learned and offering major discounts to prioritize controls that you put in place, when and where, they look at you by industry. and we've got a few markets right now that are even willing to stabilize and and kind of cap what your insurance pricing looks like. And then even if there is a claim or something that happens.
They're still renewing the policy and then doing a lot of hand holding after post event to keep that company insured, but to continue to change and improve what their their cyber resiliency and their cyber profile looks like. But that's insurance companies. Like you again, you need this on a very, very grand scale. there's still stats that I read about, you know, maybe half 50, 55% of companies buy cyber. There's still a ton of non-buyers.
education is still a big issue. Folks don't realize what you can get covered in a policy. you know, there's still this belief of, well, I it's not where I need it to be. You read the wrong headline or you read, you know, you gotta really talk to a broker and insurance carriers to get to the bottom of things because there is a lot of coverage that's out there. There's a lot of capacity that's out there, there's a lot of help and training and education and all of that that that's out there. and I really think we've got to focus on the non-buyers to educate them.
We need more buying the policies because then you ultimately learn more, right? You learn more from
Right, right.
those companies, even not just them having a clean and learning, but you learn more about you know how these companies are operating. And now's our time to do it with everything going on with AI, because there's such a pivot in the way that these companies are working and building out their workforce. Now is our time to get ahead of that. To you know, take notes and learn and then build things and get the government involved if and when it makes sense to get them to back these things and build these things out.
that makes sense. Yeah, I guess I guess everything is a when there's a challenge it's an opportunity too.
Yes. Kinda scary opportunity, but yes.
Okay, so we need to deal with a little bit of business here, which is that your wardrobe is just looking fantastic. Thanks for wearing the the sh the shirt.
Why, thank you. I know a guy. I mean
I I can let you know who it is. I know a guy. I get some amazing swag. loving the t shirt, love to be advertising great companies and great folks. So yes, proud to be wearing this T shirt today.
Great, thank you. I will tell you also that We often send our guests a little gift, a mug, a shirt whatever it is. but I believe you are the first guest who has sent us something. At least you sent me one of these fabulous Lockton glasses. I I g I got it. yeah, that
Yes, and spin it. Turn it around too.
yeah, I meant to ask you, and it's got this thing on the on the back. I don't know if everyone can see it.
But you've got the same one. It says Jack's
Yeah, it says Jack Place. I do.
Place. What is Jack's Place?
So Jack Lockton started Lockton, right? He was
Uh-huh.
our our founder, he was our CEO, and his family is very much still part of Lockton. we are a privately held organization and they are embedded throughout the entire organization and various lines of business and production and everything. And there is a number of in-house
Bars and restaurants
Ooh.
that have been opened up. and there's a couple that are are actually called Jack's Place that have been opened up by his family members. And we at Lockton have one actually in in our home office in Kansas City. And we have this really cool stemware. well, I should say stemless wear, but we do have stemware as well. And we have it there's a big Jack's Place sign and
our Lockton logo. And so we've got some pretty cool swag there. So if you're ever in Kansas City or any of our other offices, we also have some bars there. I personally like the one in KC the best. Yeah.
Are you kidding me? I
worked I worked for Prudential, and I mean
Yeah.
we were lucky if they cleaned the bathroom once a day. I mean that's you have bars. my God.
Yeah. We have listen, we do
Lockton honestly for it's like 16, 17 years now, has been voted consecutive years best place to work. they do a lot for associates, and it's not just about buying a you know a a bottle of wine for anybody either,
I'm sure. Yeah.
but they they focus on on their associates, the the needs of their associates, the happiness of their associates. That all leads to very productive associates.
And so we have an amazing talent pool and folks that work at Lockton typically stay at Lockton because of the opportunity that they have there. and so it's it's been a great place to work. I worked with them when I was an underwriter and now I'm here overseeing the cyber practice across the US.
So maybe the future, Joe, when we do our conference,
That's great. Well,
they can help us with some of the glasses.
can c can we do a live stream from Jack's Place? that that would be great. A cheese bowl container.
Of course. We that would actually be amazing. We have like a cheese bowl container. We have snacks.
Ha ha ha.
We have a bartender. We have like we have we have anything and everything that you can imagine. I'm I'm pretty sure I know the right people in the right places that can make that happen.
I I don't wanna mention the
that's awesome.
place yet 'cause we're we're we're in negotiations, but we're trying to get into a very well known I guess national kind of treasure. And
Okay.
and we don't know if we're gonna get on it yet, but you know, we're we're trying to get on site to certain locations. You know, Joe Joe and I our our dream is is to expand our conference.
And our I'm sorry, our podcast and then do some conferences and other stuff. Actually build a conference 'cause we feel like
We see things a little bit differently, but we would, you know, love the opportunity one day maybe. If it does work out, let us know. But if it doesn't we understand, but we would love to do something like that.
No, we we would love that too. I love environments where we can speak, and that's what I love about this podcast that we're speaking very frank with one another, right? We're not using
That's it.
crazy, funny buzzwords that only certain people know. This is real world stuff, right? We're all impacted as individuals, as businesses, but it's it's it's the communication and the learning, the endless learning. So I love tapping into environments like that. You meet the best people, you develop the best relationships with those and
We would love to partner with you on something like that.
I'm I'm gonna turn this
Right.
over to Joe in a second, but Joe will explain w why this is the way it is, 'cause the whole nature of the of our our show is based on a bar. So j j Joe, what what what what was the vision
No, yeah, well
again?
no, the idea for the show was,
Yeah.
you know, I realized, I said, where are some of the best discussions we've you know, we've had about, you know, business like this kind of thing? And I'm like, at the bar, at a conference or at a happy
That's right.
hour or something, you know, and where you not only have some great conversation, learn some things, but you very often will talk to
Speak frankly.
some people who, you know, in cyber the field is so broad that, you
Right.
know, who
do some things that you don't do, who do insurance, you who do the legal stuff, who do you know, other things that are like outside your field and I mean you just learn so much and have a good time too. So so well thank you. And
Yeah. This is
and and here's to Jack. Sounds like it sounds like he was a great guy. All right.
yes, here is to chat. Thank you.
Yeah, I would say yeah, those conferences are great. Again, that's like like you said, you're building the the best relationships and people are are so much more likely to just kind of ask questions and be curious. Sometimes when you're on a stage or you're in a a much bigger, grander environment, it it could be a little intimidating and things like that. But the companies that are going to these events now and vendors, I mean, everybody is kind of searching everyone else out to build that network and community.
That's what made cyber insurance develop and and get where it is now. And that's what's gonna help the AI environment and still, you know, the developing environment around cyber. I've gotten to know so many folks in the FBI, the CIA, tech, big tech vendors, forensic companies, law firms, like these these folks that are there's so many different facets to this. It it keeps it very entertaining and fascinating. and it's yeah, I've made a career out of it and I don't plan on leaving anytime soon. Having a little bit too
yeah, I
much.
Fun.
exactly. And you know, I I never ask a question in a session. I'm not doing I'm in front of all these people. It's like I w I wanna talk to the
God, I ask questions in sessions.
speaker in the bar, preferably on at least the second round, and find out what's really going on. You know.
Yeah. Exactly. At their second happy hour. That's right.
But Michelle, but but but Michelle
I I met a lot of people that are coming on the podcast in the session. So like one guy that's coming up, he's like he sat next to me and and I'm like he's like, I'm sitting next to you just so I could be friendly with you so you don't ask me hard questions during the session. Meanwhile, this guy was a brigadier general of a country, really smart, really sharp. He's like bef I'm joking, he's befriending me so I don't ask hard questions, but
A lot of the good questions you ask at a session are incredible. But Joe is right. Joe and I I'm gonna say and I say this with a lot of emotion. We're very lucky people. You know, Joe came to me about three something years ago and said, Hey, let's let's build let's do a podcast. But the the the the reach and the exposure and the amount of stuff that we have learned from people like you and and to get this out to right now our limited audience, but we're gonna get build our audience,
Yeah.
people
People who are gonna watch this are gonna say, I never thought about that in cybersecurity. I know people talk about risk and insurance, but wow, I didn't realize it was that detailed and that immersed and that they they're gonna listen, they're gonna understand
Yeah.
more than they did before.
Right. It's conversations like this that are gonna get people to understand it too. Not the Uber technical ones with all the acronyms and all that. It's that becomes so overwhelming. and there's some great books out there too. Like I've really gotten into reading, just tell me give tell me how it is, right? Don't give me anything fancy in some big book. Just have someone talk to me and engage me. Tell me about what's happening inside or tell me what's happening with the AI and the evolution of AI. And there's
There is some good stuff out there, but that's what's gonna get people to learn about it.
yeah, absolutely. And I'll tell you, I mean, you know, something like this I I I liked I like to do because for me, you know, getting our cyber insurance and doing all that was my annual ordeal. And I always knew there was a little bit more to it than just that. So it's fascinating to to
Yeah.
learn a bit more from someone who really knows what's going on.
But
Yeah.
we're kinda coming to the end. So I have to ask where I mean, where do you think things are going if you're you know, if you're a CISO, if you're a director or whatever.
when it comes to your your insurance, what should you be thinking about and talking to your board or to your, you know, bosses about?
Yeah, I I still think there's
there's a lot of education that has to get into those types of leaders that then speak to the boards, you know, going to board level. there's we actually just put out a a threat report at locked in that touches on past, present, and then where things are going in the future. We were pretty dead on with our report from last year, so we'll see what what comes out in the next 12 months. But a lot around education, putting the key controls that need to be in the right places at the right time.
A lot around employee education. A lot of still what's happening is someone's clicking on something, someone's moving too
Yeah.
fast, someone's on a mobile phone. so there's a there's a lot that you could put into place. you're working with your insurance carriers, you're working with your insurance brokers, we can help you prioritize and show you now, we can show you the impact of putting key things in place and the impact that will have on your premiums. you know, seeing what's happening in the claims environment with litigation and the regulatory environment.
that could never happen to me. Well, now there's stories that show how this can happen to you. So really going through that process and having that conversation, taking those data points back and and getting people to come within your organization to help you have some of those conversations. It's not all on the risk manager to go talk to the board. We bring SWAT teams to talk to the that those executive teams. you know, there's a lot of information to be shared. And really this cyber community has come together. We're all trying to fight the bad guys. You know, yes, there's premium and
and whatnot and it's a business, but we're trying to r fight some really horrible people here that have the potential to do some catastrophic things. So working together is is really what it's all about and again leading to that education piece.
Yeah.
that's great
to like, you know, if you need something for your budget, call your insurance broker and say, Hey, you gonna be looking favorably on this?
Right. They've got thousands of clients
we've talked to. We could tell you, right? We could tell you what's coming down the pipeline, what's going to be a problem in six months. We spend
Mm-hmm.
a lot of time. We don't talk to clients just at renewal. We're talking to clients every month throughout that policy year because something constantly is changing, right? And would I have coverage for this if this happened? Should I add something like this? Should I get increased limits in the middle of this right now? What's happening outside the US, inside the US? And so we're constantly having those discussions, and they're very valuable.
So
it's it's funny, like you guys are and and and and please I say it respectfully, you guys are like dental insurance and medical insurance. Your your dental your dental insurance will say, please get a cleaning every
Yeah.
six months. Please and then your your medical insurance.
Your annual checkup.
Yeah, please make sure that you're watching your sugar. And the reason why is that these insurance companies know if they prompt you to do these these
That's right.
wellness checks that you might not have a claim
'Cause you did the right thing. So I can almost see like, Hi, this is XYZ Insurance. Do you have your EDRs in place? Have you been doing
That's right.
your maintenance? Have you been doing your patching? Let us know. We'll be more than happy to help you and walk you through and have a nurse call you to walk you through the steps in order to make sure that you limit your liability.
Well you think about property insurance, right? People go on site and they're like, put a sprinkler here, where is this
Yeah, yeah.
exit?
Mm-hmm.
Protect this endpoint, create a air gap. Like you could see how this stuff actually works now because there's more content that we can rely on to educate, but there's still a lot more work to do.
Joe, we're gonna have to become brokers and do some insurance now.
You get these
really cool glasses if you do
Yeah.
Yeah, I I know really. Got a get a bar and everything in the in the building. Very cool.
I got a coaster around
here somewhere. I I I have a coaster. I have a couple of things, yeah. It's cool.
No, that's great. Well, Michelle, thank you so much for joining us. I mean I really learned a lot. there is a lot to this and it sounds like the like this world is still changing, definitely still evolving. There's a lot going on.
It is. I really appreciate the time and and being asked to join you guys. I love these conversations and I love the background that you both have as well. And I'd love to have a two-point-oh a to be continued.
Well, that being
Absolutely.
said, th before we depart, if you had to tell the audience three things, just simple things to to look out for, to think about for the future, what would those three things be? If you don't mind me asking?
Yeah, I mean I would tell I would tell organizations, communication is key, right? You should be talking to your executives. IT should be talking to legal, like that whole community has to come together. A lot more education and training for employees. Like you think new talent's coming in in and coming out. I can't tell you how many times somebody doesn't even end somebody's dial in or like all their login and everything that they're attached to because we work in a remote environment, somebody's still able to access things.
you know, three months after they no longer work for an organization. So there's a lot of those types of controls that can be put in place. Employee education. Stop clicking on things. Slow down.
Heh.
No one needs to get that
Yeah, we
email at eleven fifty eight PM. It can wait till tomorrow morning when you can read something on a computer. Those those are the big things I would hit on.
actually got in trouble. I I opened up a link that was a phishing link, but I opened up an isolated browser. I
Yeah.
said, let me just open this up an isolated browser. But because the URL was part of a phishing campaign, I still got hit. I'm like,
Yeah.
stop. It was a freaking isolated browser. It was not going anywhere. I don't care. I and I still got hit for it. I'm like
Adam, please. How
man how many times have you tried that trick? Yeah, it was an isolated browser. That's it. You know. It was safe. It was research. It was research.
It was an isolated browser, but no no it was me. It was me. But but if it's an isolated browser,
Yeah, it wasn't me.
even if it targets it, there's nowhere for the malware to go.
Right now there's some like kid in his mom's basement in zip up hoodie going, This guy said it was an isolated event. He's gonna
There you go, that's it.
prove that it wasn't so isolated. Someone's gonna find you now after they hear this.
Yeah. All right. Well, Michelle, thanks again. It's been it's been
Amazing conversation. Amazing.
great having you on. Adam, we're just giving you a bad time. Come on. We're cool. We're cool.
Yes. I know.
Yeah, it's fine. I've I I've beginning a bad
time for the last seventy five years. Wait, I'm not seventy five, am I?
So
I didn't think so.
gosh.
I don't think you're seventy five. You've you've got a a ways to get there. Well, thank you very much. Have an amazing weekend and we'll talk soon. Yes.
Thank you very much, Michelle.
All right. Thanks a lot, Michelle. And thanks
everyone for listening. Take care.
