Vendor Risks Take Center Stage
During the InsuranceFest 2026 in Santa Monica, experts identified vendor risk as a significant concern in the realm of cyber insurance. A panel discussion moderated by Keith Savino, CEO of Emergence Insurance, featured key voices such as Garrett Droege from WTW, Nadia Hoyte of USI Insurance Services, and Fitz Swain from RT Specialty. The panel focused on the evolution of cyber coverage and the common underestimations of risk by insured companies. As organizations increasingly rely on digital infrastructure and third-party vendors, the complexities surrounding these risks escalate, warranting a deeper analysis.
Misconceptions About Third-Party Exposure
Droege emphasized that many organizations overlook third-party exposure, mistakenly believing that they transfer their cyber risks to suppliers. "A lot of people think they're outsourcing that – like someone else has the data and so we don't have to worry about it," he noted, pointing out that a significant number of cyber incidents involve third parties who inadvertently create vulnerabilities. This mindset can prove detrimental, especially as cyber incidents don't just affect the immediate party but ripple across their supply chains, potentially impacting numerous stakeholders.
Hoyte elaborated on this issue, explaining that while firms often perform initial due diligence, they commonly fail to grasp the full extent of their exposure throughout their supply chains. Instead of adopting a holistic approach, businesses frequently rely on standard checks, such as suppliers' System and Organization Controls (SOC) attestations. They often miss the critical step of examining the contractual relationships further along the chain. As companies become increasingly interconnected, this level of oversight is not just advisable; it's necessary.
Insurers' Evolving Underwriting Stance
As organizations increasingly depend on third-party technology providers, underwriters are placing greater emphasis on supply chain vulnerabilities and oversight in their assessments. This shift comes amid rising concerns regarding AI-related exposures, which have thrown traditional risk models into disarray. Insurers now find themselves refining policy language and underwriting practices to better address these modern threats. It’s a sign that the industry is awakening to the multifaceted nature of risks that businesses face today.
Swain noted a trend where insurance carriers are introducing AI-specific exclusions in errors and omissions policies. This change particularly targets businesses utilizing AI-generated outputs without substantial human oversight. By doing this, insurers are responding to very real risks and the implications of AI making substantial operational decisions. He mentioned the risks linked to the growing use of AI, including misguided legal information based on fabricated data, as an example of what insurers are now addressing. This shift in underwriting practices may reflect a more cautious approach, but it also highlights a fundamental gap in the understanding of AI’s limitations.
Examining Coverage Gaps
The panel also raised alarms over coverage gaps emerging from exclusions within general liability policies. Swain warned that many general liability (GL) policies now incorporate cyber exclusions, which can effectively leave businesses vulnerable if related risks materialize. Here's the thing: exclusions tied to technology-related risks aren't merely a nuisance; they represent a significant threat to business continuity. Companies may find themselves facing catastrophic financial repercussions when these gaps in coverage manifest.
Hoyte argued that rather than broad exclusions, the industry should work towards developing more nuanced underwriting inquiries related to AI deployments. It's essential to assess not just the technology itself but also its contextual application within business operations. Insurers must evolve beyond simplistic assessments if they hope to remain relevant in this complex landscape.
Implications of Quantum Computing
Looking ahead, Droege urged brokers to prepare clients for the implications of post-quantum cryptography, referencing guidance from the US National Institute of Standards and Technology (NIST). The intersection of quantum computing and cybersecurity is an area of growing concern, particularly as the capabilities of quantum technology become more feasible. Droege articulated the potential outcomes should quantum computing technology fall into the wrong hands: "If we get a quantum computer in the hands of a bad actor... all of your passwords are gone. So it is the end of the world." That sentiment isn't exaggerated; it's a stark reminder of what's at stake.
Swain echoed this concern, confirming that current encryption standards may quickly become insufficient in a quantum-enabled landscape. As these technological shifts loom, businesses need to be proactive rather than reactive. Waiting until a security breach occurs could jeopardize not just their assets but their reputation and customer trust.
While effective quantum threats may still be a future concern, Droege advised brokers to initiate discussions with clients now, using NIST's roadmap as a framework to navigate the complexities of transitioning to post-quantum security measures. If you're working in this space, you might want to start thinking about how these guidelines could shape your security strategy.
The Future of Cyber Risk Management
As the risks tied to vendor relationships and emerging technologies like AI and quantum computing evolve, so too must the frameworks for managing these risks. Businesses will need to reevaluate their cyber insurance needs regularly and foster deeper collaborations with their insurance providers. The unexamined vulnerabilities in supply chains, paired with the increasing sophistication of cyber threats, mean that companies can no longer afford to adopt a one-size-fits-all approach to risk management.
This is more significant than it looks. Organizations that can effectively manage their cyber risk exposure, including that tied to third parties, are likely to have a competitive advantage in demonstrating resilience in the face of potential cyber threats. In the end, the time to act is now—before it’s too late.