
The cyber threat landscape has shifted dramatically in just the past two years. Attacks that once required months of skilled effort by experienced hackers can now be executed in a matter of minutes, thanks to the rapid evolution of artificial intelligence. And in at least one recent incident, an autonomous AI-driven attack occurred with virtually no human involvement.
This reality is changing how underwriters, risk managers and executives approach cyber risk. Preventative controls remain essential, but they are no longer sufficient on their own. Increasingly, the organizations weathering cyber events best are those that have built resilience into every layer of the business.
“Because of AI, it’s almost impossible to completely avoid a cyber attack,” said Ryan Kratz, Head of Cyber for North America at MSIG USA. “We’re really focusing on resiliency first now more so than ever. How are you responding to an attack? What are your business processes in place to recover from that attack?”

Ryan Kratz, Head of Cyber for North America, MSIG USA
Three or four years ago, cyber underwriting conversations centered largely on preventative measures, those being multi-factor authentication (MFA), endpoint detection and response (EDR), and similar controls. Those controls still matter, Kratz said, but the introduction of AI into both offensive and defensive environments has fundamentally changed the risk picture.
On the offensive side, AI has compressed the timeline for attackers. “Two years ago, it could take months for even a really good hacker to find their way into an ecosystem, where now it could potentially take minutes,” Kratz said.
On the defensive side, Kratz sees organizations racing to deploy AI internally, sometimes without the governance, oversight or inventory management necessary to do so safely.
“We’re in an AI arms race amongst organizations,” he said. “I get it. You don’t want to fall behind, particularly compared to your competitors. At the same time, you need to do it in a responsible manner.”
Compounding the challenge is the third-party dimension. Nearly every cyber event MSIG USA sees today has a third-party component, whether from IT vendors, cloud providers or other partners integrating AI into their own environments.
“It’s very rare now for a cyber event to happen in isolation,” Kratz said. “The majority of events we see happen from some kind of third-party event that ultimately creeps its way into an insured’s ecosystem.”
There’s also a workforce dynamic worth noting. As experienced professionals retire and younger employees increasingly rely on AI tools, organizations risk losing institutional knowledge about business processes and incident response, while simultaneously expanding their technology exposure.
While prevention remains a core underwriting focus, Kratz said the organizations that recover fastest from cyber events share a common set of characteristics. Chief among them: cyber risk is treated as an executive- and board-level issue rather than a technology problem.
“We traditionally thought of cyber risk as a technology event,” he said. “It really is an organizational and executive board-level event now. It’s not just about getting your technology systems up. It’s about keeping your business up and running.”
The organizations that bounce back most quickly tend to prepare in several deliberate ways:
1. Tested incident response plans with executive buy-in. The strongest programs bring the CEO, CSO and other executives into annual tabletop exercises alongside outside counsel, with clearly defined roles for who makes which decisions when an event occurs.
2. Business continuity plans that identify critical assets in advance. Knowing which systems need to come back online first — before an event occurs — minimizes downtime and business impact.
3. Immutable, offline backups. “Organizations with offline immutable backups are able to fairly quickly shift to those and recover, potentially without paying a ransom and without extended, prolonged downtime,” Kratz said.
4. Cybersecurity integrated into business continuity. Many organizations already have robust business continuity plans for property-related downtime. Kratz recommends applying the same rigor to cyber. “If a manufacturing plant goes down because of a cyber breach as opposed to a property event, I’d like to see a similar response,” he said.
5. AI governance, policies and procedures, now. Rather than waiting, organizations should establish AI governance frameworks, inventory the AI agents deployed in their environments, define what those agents can do autonomously, and set clear rules around what data employees can input into them.
“Don’t get caught on your heels,” Kratz said. “AI is here, and it’s going to get faster and stronger. Develop those policies and procedures now so you’re not trying to catch up later.”
Of course, the foundational hygiene controls still matter. MFA, EDR, vulnerability management, privileged access management and employee security awareness programs cannot be allowed to erode, even as attention shifts toward resilience.
Conversely, the organizations that struggle to recover tend to react in an uncoordinated manner, lack executive alignment, or deploy new technologies without proper governance in place.
As MSIG USA expands further into the primary cyber policy space, the carrier is building its approach around a resilience-first philosophy. That is one that treats cyber insurance not as a transactional product, but as an ongoing partnership.
“I don’t think cyber insurance should be transactional and end when the policy binds,” Kratz said. “Yes, we are a risk transfer tool for insureds, but we should also be there throughout the life cycle of a policy to help them.”
As a leading, data-driven specialty insurer, MSIG USA is developing technology designed to move underwriting from a static, point-in-time exercise to a dynamic one. That includes active monitoring capabilities. For example, alerting insureds to zero-day vulnerabilities they may be exposed to so they can act quickly to mitigate them.
The carrier is also focused on helping insureds understand the broader ecosystem of technologies that shape their cyber exposure, from cloud providers and vendors to operational partners and customers.
“Cyber is not a one-stop risk anymore,” Kratz said. “We want to help our insureds identify the ecosystem of cyber technologies they’re using. This will help them understand the full spider web of technology that might impact their environment.”
From an underwriting perspective, that means asking a more expansive set of questions: What AI agents are deployed in your environment? Are they subject to human oversight? What sensitive data are employees inputting into them? What controls prevent unauthorized data leakage? And how are third-party vendors using AI in ways that might affect your data?
Looking ahead, Kratz expects autonomous AI-driven events to become a defining feature of the cyber landscape — one that both insureds and underwriters must be ready to navigate.
“We, as underwriters and our insureds, are going to have to expect to live in a world where AI can function effectively autonomously, without that human element,” he said. “We need to be able to adapt to that as an underwriting market.”
To learn more, visit https://www.msigusa.com/.
![]()
This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with MSIG USA. The editorial staff of Risk & Insurance had no role in its preparation.