Cyber Insurance Frontier event bringing together cyber risk leaders from all across Europe

We need to rethink how we are discussing cyber risk. 204 nationally significant attacks logged by the NCSC in the past twelve months, more than double the year before. 

An economy where five million SMEs remain largely uninsured. Cyber Risk Reckoning in London brings together security, risk management, insurance and regulatory professionals together to question how we approach cyber threats and what has to change for the market to remain functional and business resilient.

How the day works, in the round.  

Every working session runs as a goldfish bowl: an inner circle of invited practitioners, one seat kept permanently open, and a surrounding room to engage in the session. 

The forum exists because the conversations this industry must start to have involve shared lessons and a discussion based format. 

08:00

REGISTRATION & REFRESHMENTS

08:50

WELCOME ADDRESS | The 2026 CIF Cyber Insurance State of the Market Briefing

Drawn from closed-door community conversations across the year and collected data – the read that frames the day.

09:00

OPENING KEYNOTE | Cyber Risk Breakdown: State of the Threat

 

Drawing on portfolio-level data and frontline market intelligence: what has actually changed since Mythos entered early access, what nation-state activity looks like in an AI-accelerated exploitation environment, and where the gap between attacker capability and organisational defence sits in Q4 2026.

09:30

AI Aggregation Risk – Realistic Disaster Scenario

 

Can current vendor risk management frameworks survive machine-speed exploitation, and if not, what replaces them?

  • Where is the modelling community on second-tier concentrations – identity providers, CDNs, specific SaaS categories  and how are portfolio managers adjusting line size ahead of the models catching up?
  • What does machine-speed exploitation do to the patching assumptions underneath current underwriting, and what has materially changed at renewal?
  • As aggregation concerns push towards named-peril framing, what does that do to the product for mid-market and SME buyers who need simplicity?

Panellists: 

  • Ed Pocock, Head of Cybersecurity, Gallagher Re  
  • Dr Stephan Brunner, Senior Cyber Actuary, Munich Re

10:30

The Protection Gap: A Failure of Decision, or a Failure of Product?

 

This session pressures common explanations around the cyber protection gap. 

  • Is it a failure of decision-making that better analytics and advisory can close?
  • How can we better educate the market on cyber risk and business resilience?
  • Are buyers responding rationally to a product not yet trusted to pay at the scale and speed of today’s losses demand as cyber losses shift from data compromise toward operational disruption and sustained revenue impact? 

Panellists:

  • Lyndsey Bauer, Strategic Delivery Lead – Cyber, Miller Insurance 
  • James Creasey, Head of Cyber, Inigo
  • Peter Wedge, GC, Testudo 

11:30

NETWORKING BREAK

12:00

BREAKOUT WORKING SESSIONS – IN THE ROUND

 

Cyber War Room Simulation

This interactive session drops delegates into a live crisis scenario, moving from first alert to executive decision-making under real-time pressure. The scenario is authored with a threat intelligence analyst to ground it in current, real-world adversary behaviour, with Google Mandiant serving as the session’s intelligence partner.

 

Participants:

  • Mathias Frank, Head of Incident Response, Mandiant UK & Ireland

 

Quantum Preparation Today

The question is what can the insurance industry do to help our policyholders prepare?

  • Externally, should the carrier begin asking policyholders about their quantum plans and align with vendors to help them start the planning process? 
  • Internally: How does the carrier understand the risk they are willing to bear?
  • How to harden systems and create a game plan for today and tomorrow’s quantum exposure.

Participants:

  • Jason Curreri, General Counsel and Head of Wordings, Elpha Secure

 

The Claims Experience: Business Interruption

Business interruption has proven one of the more difficult elements of cyber cover to price and to adjust. Contingent and systemic exposure adds a correlation risk that is hard to diversify and has shaped how carriers approach sub-limits and wording. 

 

This session looks at the claim from the market’s perspective: how BI losses have influenced pricing and terms, where the practical difficulties in adjustment arise, and how forensic-accounting and claims practice are maturing as the line develops.

 

Participants:

  • Patrick Cannon, Global Head of Cyber Claims, Canopius
  • Michael Milne, Investigative Accounting, Meaden Moore

13:00

NETWORKING LUNCH

14:00

Ransomware Economics and Payment

 

Mandatory economy-wide incident reporting is moving towards legislation. This session works through what that actually means for the cyber product.

  • Where is coverage bending, and what does facilitation cover look like under a notify-and-pause regime?
  • What happens to the threat-actor business model – do we see a shift to extortion-without-encryption, and is the policy ready for it?
  • What is the operational reality for an insured covered by the ban when systems are down and the clock is running?

Panellists:

  • Anja Shortland, Professor in Political Economy, King’s College London  
  • William Finley, Senior Cyber Underwriter, QBE

14:45

DATA-LED PANEL  

 

The Reckoning: The Claims Picture vs. The Narrative

 

The session opens with a data-led briefing on where losses are actually landing and coverage disputes are doing to the buyer relationship at the moment of claim. 

Are enterprise risk functions and the insurance market developing a shared understanding of cyber risk  or increasingly working from different pictures of the same threat landscape?

 

Panellists:

  • Lindsey Maher, Head of Global Cyber Development, CFC  
  • Ben Watson, Head of Cyber, Westfield Specialty
  • Jimaan Sané, Head of Growth Cyber, Chubb  
  • Jelmer Andela, Global Commercial Director Cyber, Liberty Mutual

15:45

NETWORKING BREAK

16:15

POINT – COUNTERPOINT – THE BUYER-SIDE

 

What CISOs, CROs and GCs Need From the Cyber Insurance Market


The day’s closing set-piece: a buyer-side panel built around what cyber insurance needs to look like for enterprises operating at meaningful scale and complexity — a peer conversation to shape discourse on AI and cyber risk for the enterprise.

  • On cyber and AI risk, what is becoming harder to explain and quantify with confidence, and where is the gap between what boards expect and what risk leaders can credibly deliver?
  • Third-party risk — vendors, suppliers, partners and the AI systems embedded across them –  how are you managing it in practice, and where are the limits of what’s manageable?
  • Over the next 24 months, what’s the risk on your register you’re least confident the insurance market is set up to support?

Moderator: Jean Bayon de La Tour, Head of Cyber International, Howden  

Panellists: 

  • Chrisitiane Baetz, vCISO – Cyber Security Delivery Partner, Financial Conduct Authority
  • Peter Downie, Chief Risk Officer, JLL  
  • Peter Kovacs, Head of Information Security and Data Privacy, nudge

17:10

CLOSING REMARKS

 

What the Room Has Worked Through

 

Drawing threads together across all in-the-round sessions: key tensions, emerging consensus, and what carries into the year-round programme for the Cyber Insurance Frontier community. Closing remarks to follow.

17:20

END OF CIF LONDON 2026

View Agenda

REGISTER