“Maliciousness at scale”: The cat and mouse chase of AI in cybercrime
In 2024, 52% of US companies reported losing sensitive information due to cybercrime, with 26% of these incidents involving business email compromises. The costs are staggering—the average data breach in the US hits $9.36 million per event.
AI is a double-edged sword in this context. While it offers powerful tools for organizations to protect themselves, it also equips cybercriminals with new capabilities to launch smarter, more convincing attacks. Staying ahead requires constant vigilance and adaptation.
Rising demand for cyber insurance
The surge in cybercrime has pushed demand for cyber insurance dramatically higher. Yet, many small and medium-sized businesses remain underinsured, despite being prime targets. These organizations often lack the cybersecurity resources of larger companies, making coverage and expert guidance more critical than ever.
Effective cyber insurance isn’t just about financial protection—it’s about equipping businesses with the knowledge and tools to respond quickly and confidently when incidents occur.
New threats, sharper tactics
Cyber threats are evolving fast. Ransomware attacks are up sharply, alongside social engineering scams, link baiting, and deep fakes. Data breaches still carry heavy costs through fines, lawsuits, and recovery efforts. Business email compromises are increasing, driven by attackers’ ability to scale operations.
Attackers are refining their methods, using AI to craft targeted emails at scale and rapidly scan networks for vulnerabilities. This acceleration in attacker capabilities means defenders need to match pace with technology and training.
The role of AI: both threat and shield
AI turbocharges attackers by enabling them to automate email creation, analyze what tricks work best, and scout weaknesses in systems faster than any human could. But AI also strengthens defenses—automated monitoring tools can flag unusual activity in real time and help identify breaches early.
The cyber battlefield is a constant contest between offense and defense, each side pushing the other to innovate.
Investing in your people: the frontline defense
Employees are the first line of defense. Upskilling teams to spot scams—both obvious and subtle—is essential. A well-trained workforce can dramatically reduce the risk of successful attacks.
Education is the most valuable investment. Free, regularly updated training resources for policyholders can build a security-aware culture. Everyone in the organization shares responsibility for staying alert and proactive.
Adapting insurance coverage for the future
As AI reshapes cyber threats, insurance policies must evolve. More organizations, including smaller businesses, are recognizing their exposure and the need for coverage. Policies will need to keep pace with emerging technologies and attack methods.
This is a dynamic space—cyber insurance isn’t a “set it and forget it” solution. It requires ongoing attention to shifting risks and continuous improvement in protection strategies.
Further learning
For insurance professionals looking to deepen their knowledge of AI’s impact on cybersecurity, exploring courses on AI and automation can provide valuable insights and tools. Resources like Complete AI Training offer practical courses on AI applications relevant to risk management and cyber defense.
