Regulation is turning resilience into a strategic imperative
This shift, to focus on the minimum viable enterprise, is also being reinforced by regulation. In Europe, the Digital Operational Resilience Act (DORA) now applies across the financial sector and sets a clearer expectation for insurers: digital resilience can no longer remain a topic owned mainly by cybersecurity teams. It must be governed as an enterprise-wide risk, with closer connections between technology, operations, risk management and business continuity.
DORA focuses on five areas that are highly relevant in an AI-driven threat environment: information and communication technology (ICT) risk management, incident reporting, resilience testing, third-party risk and cyber threat information sharing.
This means moving beyond policies and control design. Insurers must be able to show that resilience works in practice, especially for the important and critical functions: the services and processes that matter most to customers and the market.
This starts with a clearer view of critical assets, business services and technology dependencies. Cloud providers, platforms, brokers and outsourcers all play a role in the delivery of insurance services. If one link fails, the impact can spread quickly across operations, customer access and regulatory commitments.
DORA also makes accountability more explicit. Digital resilience becomes a board-level topic, not just a technical compliance issue. This matters in an AI context, where attackers can move faster and exploit weak ownership, limited supplier oversight, or insufficient testing of realistic crisis scenarios.
For insurers, DORA is therefore an accelerator. It turns the resilience agenda into concrete obligations and pushes organizations to industrialize capabilities that were often unevenly deployed. In a machine-speed threat environment, compliance is not the end point. It becomes the baseline for a more adaptive resilience model built around the services that must remain available under stress.
From exposure to engineered resilience: building cyber resilience in the age of AI
Preparing for frontier AI-driven threats requires more than stronger defenses. It requires a rethinking of how cybersecurity operates at its core.
Three priorities stand out for insurance leaders:
1. Achieve continuous visibility across the extended enterprise
Traditional asset inventories and periodic assessments are no longer sufficient. Insurers need real-time visibility across applications, data flows, identities and third-party dependencies.
Without this, the true attacks surface and therefore the real risk remain unknown.
2. Prioritize based on business-critical exposure
Not all vulnerabilities carry equal risk. What matters is how they can be combined and whether they impact critical services such as claims processing, underwriting or customer access.
This requires shifting from technical severity metrics to business aware exposure analysis, focused on exploitability and potential operational impact.
3. Accelerate response through controlled automation
As attack timelines shrink, manual processes become a limiting factor. Automation, within defined policies and guardrails, is essential to reduce response times.
This includes:
- Automated prioritization of vulnerabilities
- Rapid patching and configuration updates
- Dynamic access management (e.g., just-in-time privileges)
- Real-time containment of suspicious activity
Automation does not remove control; it enforces it at speed.
Preparing the insurance sector for future cyber threats
Frontier AI does not mark a distant evolution. It signals a near-term inflection point.
The insurance sector has strong foundations: mature risk management practices, regulatory alignment and experience in operational resilience. However, these strengths must now be adapted to a context where threats evolve faster than traditional decision-making cycles.
The organizations that will be well prepared are those that act before frontier AI capabilities become fully commoditized. They will move from static protection to dynamic resilience, from delayed response to real-time action and from partial visibility to continuous exposure management.
In a sector built on trust, the ability to operate securely under pressure is not just a technical requirement. It is a strategic imperative.