Aon warns businesses are too slow reacting to AI cyber risk, and London's insurance wordings are still catching up too

Started by Midnight Wolf, Jul 17, 2026, 03:30 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Aon warns businesses are too slow reacting to AI cyber risk, and London's insurance wordings are still catching up too   Views(Read 155 times)

Midnight Wolf

Aon is calling for stronger cyber risk management practices following an April 2026 UK government open letter warning that AI can now find software weaknesses and write working exploits at a speed and scale that would have been impossible just a year earlier. Rob Kemp, Aon's UK CEO of Commercial Risk, said the firm's own Global Risk Management Survey found cyber attacks and data breaches remain the single top enterprise risk for 2026, expected to stay there through 2028, with many businesses describing themselves as only somewhat prepared, citing fragmented internal governance and limited testing of AI specific incident scenarios. Some organisations, Kemp said, are still treating AI risk as a future problem and delaying the cyber strategy work it actually demands right now

Aon's core message is that AI hasn't changed the fundamentals of cyber risk management, it has dramatically increased the scale and likelihood of attacks succeeding. The advice is refreshingly unglamorous, focus on core controls that already work, patching, vulnerability remediation, staff training on phishing and social engineering, and specifically stress test those controls against AI enabled attack scenarios rather than assuming existing policies automatically cover them

The same capabilities making attacks faster, quicker reconnaissance, automated exploitation, harder to trace attack chains, are simultaneously making it harder to attribute any given attack to a specific actor, which creates a genuine problem for how insurance policies are written. Lloyd's market clauses covering state backed cyberattacks were updated in 2026 specifically to shift the exclusion test away from proving an attack came from a state and toward whether it caused significant impairment at a national infrastructure level instead, a practical acknowledgment that attribution based tests get harder to apply as attacks speed up and obfuscation improves

All of this is playing out against a soft UK cyber insurance market, Marsh's 2026 outlook describes rising demand and expanded insurer capacity keeping premiums relatively low even as new AI specific products start to emerge, while the UK's Cyber Security and Resilience Bill is set to expand mandatory security and incident reporting requirements to a wider range of managed service providers, data centres and critical suppliers this year. High profile incidents like the 2025 Jaguar Land Rover cyberattack have already pushed cyber insurance awareness up among smaller UK businesses that have historically been underinsured, but the overall picture is one of both corporate risk management and insurance market wordings still racing to catch up with a threat that's moving faster than either

SystemWarden64

Shifting the exclusion test from attribution to actual infrastructure impact is such a pragmatic fix, attribution has always been the weakest link in cyber insurance and AI just made it even harder to rely on

Omega

A soft market with rising capacity keeping premiums low right as the actual threat gets more severe is an uncomfortable mismatch, feels like pricing hasn't caught up to reality yet

Slay40

The advice to stress test existing policies against AI enabled scenarios rather than assume they already cover it is such practical, actionable guidance compared to the usual vague warnings about AI risk
Posted from a machine that definitely needs a clean install

GlassKnight89

Some organisations treating this as a future problem is the part that should worry people most, the government's own letter is describing capabilities that already exist right now, not a hypothetical

Mesh Ross

Jaguar Land Rover getting cited as the wake up call for smaller UK businesses shows how much a single high profile incident can shift industry wide awareness practically overnight
RTFM and then ask

Louise82

Fundamentals not changing but scale and likelihood increasing dramatically is a really clean way to frame this, the basic controls still work, they just need to be applied with much more urgency now

Laura53

Feels like the insurance market is always a step behind whatever the current threat is. By the time wordings catch up, attackers have already moved on to the next trick. AI just accelerates that gap. Small firms reading this probably think it's a big-company problem, but those are the easiest targets.

Kayla82

The Jaguar Land Rover mention hits because it shows scale doesn't protect you anymore. If anything, complexity creates more entry points. A small supplier with one weak endpoint can still be the door in. Seen it happen in a logistics chain where a tiny vendor exposed credentials and suddenly the bigger partner was scrambling :o
Just here for the craic :)

Harbour17

A lot of execs still treat AI cyber risk like it's some future scenario instead of current reality. Meanwhile, tools are already automating vulnerability discovery. That April letter wasn't subtle. It basically said the window between flaw and exploit is shrinking fast.

Rory93

Part of the issue is language. Insurance policies still talk about breaches like they're static events, but AI-driven attacks are adaptive. They probe, adjust, and retry in ways older definitions don't capture. That mismatch is going to cause disputes when claims start rolling in.
404: Signature not found in this dimension

CacheLayerShark

Worked with a mid-sized retailer last year that thought basic endpoint protection was enough. Then they got hit with a credential stuffing wave amplified by AI tools. Nothing fancy, just scaled up beyond what their defenses expected. Took them weeks to recover, and insurance barely covered it :-\

BackRowBob

Not convinced insurers will ever fully catch up. Their business model relies on quantifying risk, and AI makes that messy. How do you price something that evolves daily? Feels like premiums will just keep rising while coverage narrows.
Forum veteran. Battle hardened.

Postie

There's also a cultural lag. Boards still see cyber as an IT issue instead of a business continuity issue. Until that changes, reactions will always be slow. The tech is only half the problem.
Entangled with my ex, deployment & my sanity

HeartbreakKid_Fan

There's also the human factor. Employees using AI tools without understanding data leakage risks is already happening. Not malicious, just unaware. That's a different kind of vulnerability.

SlayedRebellion

Funny how everyone rushed into AI for productivity gains but barely considered the attack surface it creates. New integrations, new APIs, more data exposure. It's like adding doors to your house and forgetting to install locks :P

Dialer75

Curious how this plays out with reinsurance. If primary insurers struggle to model AI risk, reinsurers will be even more cautious. That could ripple through the entire market.

CosmicRay17

Reminds me of early cloud adoption debates. Same pattern: rapid uptake, slow policy adaptation, then a wave of incidents that forces alignment. AI is just moving faster through that cycle.

Ruby92

Another angle is supply chains. Even if a company tightens its own systems, partners might not. AI-driven scans don't care where the weakness is, just that it exists. That interconnected risk is tough to insure cleanly.
Not financial advice. Not medical advice. Just vibes.

VidiTechnica

Part of me thinks we'll see a new category of policies specifically for AI-related incidents. Separate wording, separate pricing, maybe even separate underwriting teams. The current frameworks feel stretched.
Be excellent to each other

UltraShane86

People underestimate how fast attackers iterate with AI. A vulnerability disclosed in the morning can be weaponized by afternoon. That compresses response time to almost nothing. Traditional patch cycles just don't keep up.

NatureBoyRyan65

End of the day, speed is the theme here. Attackers are faster, tools are faster, exposure is faster. If businesses and insurers don't match that pace, they're playing catch-up indefinitely ;D

BigDog

The JLR case feels like a narrative anchor now. Every conference will reference it as the moment people "woke up". Whether that leads to lasting change or just a temporary spike in spending is another question.

Related Topics (1)

Save money on everyday spending Free cashback on thousands of retailers
View offer