







We need to rethink how we are discussing cyber risk. 204 nationally significant attacks logged by the NCSC in the past twelve months, more than double the year before.
An economy where five million SMEs remain largely uninsured. Cyber Risk Reckoning in London brings together security, risk management, insurance and regulatory professionals together to question how we approach cyber threats and what has to change for the market to remain functional and business resilient.
How the day works, in the round.
Every working session runs as a goldfish bowl: an inner circle of invited practitioners, one seat kept permanently open, and a surrounding room to engage in the session.
The forum exists because the conversations this industry must start to have involve shared lessons and a discussion based format.
08:00
REGISTRATION & REFRESHMENTS
08:50
WELCOME ADDRESS | The 2026 CIF Cyber Insurance State of the Market Briefing
Drawn from closed-door community conversations across the year and collected data – the read that frames the day.
09:00
OPENING KEYNOTE | Cyber Risk Breakdown: State of the Threat
Drawing on portfolio-level data and frontline market intelligence: what has actually changed since Mythos entered early access, what nation-state activity looks like in an AI-accelerated exploitation environment, and where the gap between attacker capability and organisational defence sits in Q4 2026.
09:30
AI Aggregation Risk – Realistic Disaster Scenario
Can current vendor risk management frameworks survive machine-speed exploitation, and if not, what replaces them?
- Where is the modelling community on second-tier concentrations – identity providers, CDNs, specific SaaS categories and how are portfolio managers adjusting line size ahead of the models catching up?
- What does machine-speed exploitation do to the patching assumptions underneath current underwriting, and what has materially changed at renewal?
- As aggregation concerns push towards named-peril framing, what does that do to the product for mid-market and SME buyers who need simplicity?
Panellists:
- Ed Pocock, Head of Cybersecurity, Gallagher Re
- Dr Stephan Brunner, Senior Cyber Actuary, Munich Re
10:30
The Protection Gap: A Failure of Decision, or a Failure of Product?
This session pressures common explanations around the cyber protection gap.
- Is it a failure of decision-making that better analytics and advisory can close?
- How can we better educate the market on cyber risk and business resilience?
- Are buyers responding rationally to a product not yet trusted to pay at the scale and speed of today’s losses demand as cyber losses shift from data compromise toward operational disruption and sustained revenue impact?
Panellists:
- Lyndsey Bauer, Strategic Delivery Lead – Cyber, Miller Insurance
- James Creasey, Head of Cyber, Inigo
- Peter Wedge, GC, Testudo
11:30
NETWORKING BREAK
12:00
BREAKOUT WORKING SESSIONS – IN THE ROUND
Cyber War Room Simulation
This interactive session drops delegates into a live crisis scenario, moving from first alert to executive decision-making under real-time pressure. The scenario is authored with a threat intelligence analyst to ground it in current, real-world adversary behaviour, with Google Mandiant serving as the session’s intelligence partner.
Participants:
- Mathias Frank, Head of Incident Response, Mandiant UK & Ireland
Quantum Preparation Today
The question is what can the insurance industry do to help our policyholders prepare?
- Externally, should the carrier begin asking policyholders about their quantum plans and align with vendors to help them start the planning process?
- Internally: How does the carrier understand the risk they are willing to bear?
- How to harden systems and create a game plan for today and tomorrow’s quantum exposure.
Participants:
- Jason Curreri, General Counsel and Head of Wordings, Elpha Secure
The Claims Experience: Business Interruption
Business interruption has proven one of the more difficult elements of cyber cover to price and to adjust. Contingent and systemic exposure adds a correlation risk that is hard to diversify and has shaped how carriers approach sub-limits and wording.
This session looks at the claim from the market’s perspective: how BI losses have influenced pricing and terms, where the practical difficulties in adjustment arise, and how forensic-accounting and claims practice are maturing as the line develops.
Participants:
- Patrick Cannon, Global Head of Cyber Claims, Canopius
- Michael Milne, Investigative Accounting, Meaden Moore
13:00
NETWORKING LUNCH
14:00
Ransomware Economics and Payment
Mandatory economy-wide incident reporting is moving towards legislation. This session works through what that actually means for the cyber product.
- Where is coverage bending, and what does facilitation cover look like under a notify-and-pause regime?
- What happens to the threat-actor business model – do we see a shift to extortion-without-encryption, and is the policy ready for it?
- What is the operational reality for an insured covered by the ban when systems are down and the clock is running?
Panellists:
- Anja Shortland, Professor in Political Economy, King’s College London
- William Finley, Senior Cyber Underwriter, QBE
14:45
DATA-LED PANEL
The Reckoning: The Claims Picture vs. The Narrative
The session opens with a data-led briefing on where losses are actually landing and coverage disputes are doing to the buyer relationship at the moment of claim.
Are enterprise risk functions and the insurance market developing a shared understanding of cyber risk or increasingly working from different pictures of the same threat landscape?
Panellists:
- Lindsey Maher, Head of Global Cyber Development, CFC
- Ben Watson, Head of Cyber, Westfield Specialty
- Jimaan Sané, Head of Growth Cyber, Chubb
- Jelmer Andela, Global Commercial Director Cyber, Liberty Mutual
15:45
NETWORKING BREAK
16:15
POINT – COUNTERPOINT – THE BUYER-SIDE
What CISOs, CROs and GCs Need From the Cyber Insurance Market
The day’s closing set-piece: a buyer-side panel built around what cyber insurance needs to look like for enterprises operating at meaningful scale and complexity — a peer conversation to shape discourse on AI and cyber risk for the enterprise.
- On cyber and AI risk, what is becoming harder to explain and quantify with confidence, and where is the gap between what boards expect and what risk leaders can credibly deliver?
- Third-party risk — vendors, suppliers, partners and the AI systems embedded across them – how are you managing it in practice, and where are the limits of what’s manageable?
- Over the next 24 months, what’s the risk on your register you’re least confident the insurance market is set up to support?
Moderator: Jean Bayon de La Tour, Head of Cyber International, Howden
Panellists:
- Chrisitiane Baetz, vCISO – Cyber Security Delivery Partner, Financial Conduct Authority
- Peter Downie, Chief Risk Officer, JLL
- Peter Kovacs, Head of Information Security and Data Privacy, nudge
17:10
CLOSING REMARKS
What the Room Has Worked Through
Drawing threads together across all in-the-round sessions: key tensions, emerging consensus, and what carries into the year-round programme for the Cyber Insurance Frontier community. Closing remarks to follow.
17:20
END OF CIF LONDON 2026
View Agenda