EY team machine sectot

How to prepare the insurance sector for machine-speed threats

Insurers have spent decades building cyber defenses around human-speed threats. Frontier AI is changing the rules.


In brief
  • Insurers appear better positioned than many industries, yet hidden visibility and control gaps could be rapidly exposed by frontier AI.
  • Attackers can now identify, prioritize and exploit vulnerabilities at a pace that might exceed traditional organizational response models.
  • The gap between attack velocity and organizational response velocity is becoming the defining resilience challenge for insurers.

For years, cybersecurity in the insurance sector has been calibrated to a predictable rhythm: detect, assess and respond before an attack materially impacts operations. That model is now under strain.

The emergence of frontier AI models, capable of advanced reasoning, large-scale code analysis and automated vulnerability discovery, is reshaping both the speed and accessibility of cyber attacks. Tasks that once required highly specialized knowledge can now be executed faster and at scale. Recent industry testing shows that these models can help identify vulnerabilities across complex environments and facilitate the development of potential attack paths in near real time.

This is not a future scenario; it is a shift that is happening now and that calls for proactive adaptation.

The question is no longer whether these capabilities will affect the insurance sector, but how quickly organizations can adapt their resilience models to match the changing threat landscape.

Traditional cybersecurity frameworks assume time: time to detect anomalies, time to investigate and time to respond. In a frontier AI context, that assumption weakens significantly.

This matters because insurers operate highly interconnected environments: policy administration systems, claims platforms, broker portals, partner application programming interfaces (APIs) and growing AI-driven capabilities.

As a result, exposure is not confined to core systems. It accumulates across the extended enterprise.

The new cybersecurity reality for insurers

The 2026 EY Global Cybersecurity Leadership Insights Study provides a critical lens on this challenge. Based on a global survey of cybersecurity leaders, the study finds that 36% of organizational assets fall into a “vulnerability zone,” defined by insufficient visibility and security coverage.

At first glance, insurers appear relatively well positioned. Only 18% of assets fall into the “vulnerability zone” (significantly below the cross-sector average of 36%). This reflects the maturity of regulatory frameworks and sustained investments in risk management and control environments.

A relative strength for insurers
18%
18%
of insurance assets fall into the “vulnerability zone,” half the cross-sector average (36%).

However, this relative strength masks structural weaknesses that frontier AI is likely to expose rapidly.

 

1. Visibility remains incomplete across critical assets

Fewer than half of insurance organizations report full visibility over their digital estate. In an environment where frontier AI can identify and exploit hidden dependencies at scale, these blind spots represent a material risk.

 

2. Control gaps are emerging on AI-enabled systems

Customer-facing AI is a growing point of exposure. Only 29% of insurers have full visibility over customer service AI assistants, and just 13% report having full cybersecurity controls in place.

 

This is particularly critical as these systems often sit at the interface between sensitive data, customer interactions and automated decision making.

 

3. The pace of change is accelerating beyond control cycles

More than a quarter of insurers report that APIs, cloud storage and managed databases change monthly or more frequently, requiring constant updates to security controls.


In a frontier AI context, where vulnerabilities can be identified and weaponized rapidly, this creates a persistent lag between change and control.

 

The research also highlights a deeper shift: Resilience must evolve from a recovery mindset to a continuous understanding of where exposure is accumulating and how quickly it can be reduced.

 

For insurers, this aligns closely with regulatory expectations around operational resilience (e.g., protecting critical business services) and underscores the need to focus on the minimum viable enterprise: the essential capabilities that must remain operational under stress.

2026 EY Global Cybersecurity Leadership Insights Study

EY research explores how cybersecurity leaders are using recent frontier AI threat revelations as a catalyst to build resilience.

Regulation is turning resilience into a strategic imperative

This shift, to focus on the minimum viable enterprise, is also being reinforced by regulation. In Europe, the Digital Operational Resilience Act (DORA) now applies across the financial sector and sets a clearer expectation for insurers: digital resilience can no longer remain a topic owned mainly by cybersecurity teams. It must be governed as an enterprise-wide risk, with closer connections between technology, operations, risk management and business continuity.

DORA focuses on five areas that are highly relevant in an AI-driven threat environment: information and communication technology (ICT) risk management, incident reporting, resilience testing, third-party risk and cyber threat information sharing.

This means moving beyond policies and control design. Insurers must be able to show that resilience works in practice, especially for the important and critical functions: the services and processes that matter most to customers and the market.

This starts with a clearer view of critical assets, business services and technology dependencies. Cloud providers, platforms, brokers and outsourcers all play a role in the delivery of insurance services. If one link fails, the impact can spread quickly across operations, customer access and regulatory commitments.

DORA also makes accountability more explicit. Digital resilience becomes a board-level topic, not just a technical compliance issue. This matters in an AI context, where attackers can move faster and exploit weak ownership, limited supplier oversight, or insufficient testing of realistic crisis scenarios.

For insurers, DORA is therefore an accelerator. It turns the resilience agenda into concrete obligations and pushes organizations to industrialize capabilities that were often unevenly deployed. In a machine-speed threat environment, compliance is not the end point. It becomes the baseline for a more adaptive resilience model built around the services that must remain available under stress.

From exposure to engineered resilience: building cyber resilience in the age of AI

Preparing for frontier AI-driven threats requires more than stronger defenses. It requires a rethinking of how cybersecurity operates at its core.

Three priorities stand out for insurance leaders:

1. Achieve continuous visibility across the extended enterprise

Traditional asset inventories and periodic assessments are no longer sufficient. Insurers need real-time visibility across applications, data flows, identities and third-party dependencies.

Without this, the true attacks surface and therefore the real risk remain unknown.

2. Prioritize based on business-critical exposure

Not all vulnerabilities carry equal risk. What matters is how they can be combined and whether they impact critical services such as claims processing, underwriting or customer access.

This requires shifting from technical severity metrics to business aware exposure analysis, focused on exploitability and potential operational impact.

3. Accelerate response through controlled automation

As attack timelines shrink, manual processes become a limiting factor. Automation, within defined policies and guardrails, is essential to reduce response times.

This includes:

  • Automated prioritization of vulnerabilities
  • Rapid patching and configuration updates
  • Dynamic access management (e.g., just-in-time privileges)
  • Real-time containment of suspicious activity

Automation does not remove control; it enforces it at speed.

Preparing the insurance sector for future cyber threats

Frontier AI does not mark a distant evolution. It signals a near-term inflection point.

The insurance sector has strong foundations: mature risk management practices, regulatory alignment and experience in operational resilience. However, these strengths must now be adapted to a context where threats evolve faster than traditional decision-making cycles.

The organizations that will be well prepared are those that act before frontier AI capabilities become fully commoditized. They will move from static protection to dynamic resilience, from delayed response to real-time action and from partial visibility to continuous exposure management.

In a sector built on trust, the ability to operate securely under pressure is not just a technical requirement. It is a strategic imperative.

Transforming financial services with operational resilience strategies

Resilience is vital in today’s fast-changing financial world. Organizations must adapt to threats and embed it into their operations.


Summary

Frontier AI is reshaping the cyber threat landscape, allowing attackers to identify vulnerabilities, analyze complex environments and construct attack paths at unprecedented pace. While insurers appear better positioned than many industries, recent research indicates that visibility gaps, emerging weaknesses in AI-enabled systems and accelerating technology change could expose hidden vulnerabilities. Traditional cybersecurity models, built around human-speed detection and response, are becoming insufficient. As regulatory requirements such as DORA reinforce resilience expectations, insurers must shift from periodic risk management to continuous exposure management, combining visibility, business-focused prioritization and automation to build machine-speed resilience.

Related articles

How will AI redefine resilience for risks not yet imagined?

AI’s speed, scale and insight drives resilient growth in today’s complex risk environment. Learn more.

How can you redefine resilience for the next frontier of vulnerabilities?

An EY study found that 36% of assets in organizations are vulnerable to cybersecurity threats. Explore your sector’s strengths and weaknesses.

Three strategic actions for insurance CROs in 2026

Insurance risk management is evolving through advanced risk analysis, continuous risk assessment and integrated risk solutions. Learn more.

Stu Doyle + 1

About this article