In April, an AI model found a 27-year-old vulnerability in OpenBSD, an operating system that runs firewalls and other critical infrastructure. Four months later, APRA's 2026-27 corporate plan named frontier AI as a source of potentially more severe disruption and told regulated entities that rapid advances in these capabilities require an urgent strengthening of technology and cyber resilience.
The industry response so far has been to route this to the security team, which is understandable, but check out APRA's language: The plan asks for effective cyber controls, yes, but it also asks for better governance and oversight of technology risk (not just cyber risk). Those are different things, and insurance organizations are more exposed than they think.
If you strip away the AI framing. APRA wants to know something simple: does the board understand the technology footprint it is accountable for? Where does policy, claims and customer data live? How many systems touch it? Who owns each integration, and which ones are still running because nobody switched them off?
For a large insurer with a security operations center, those questions (should) have owners. For a mid-market carrier, or an MGA running delegated authority across three capacity providers, the honest answer is often a policy system from one decade, a claims system from another, a broker portal bolted on later, an accounting package that reconciles to none of them, and a set of spreadsheets that do the real work in between. Each of those has credentials, an integration surface, and a vendor. Each is a place a fast-moving attacker can start.
WTW's Benjamin Di Marco made the point at the Insurance News Beyond the Buzzwords conference in July: open a typical work environment and there are hundreds of APIs running between the organization and third parties. His reference case was Optus, where an API that should have been decommissioned long before was a central part of the breach. Nothing exotic. Just an interface nobody was tracking.
AI is evolving fast (and doing weird stuff). With frontier models like Mythos, what really changes is time. Willis describes this acceleration as the risk, with the gap between a vulnerability being discovered and being exploited shrinking sharply. Anthropic itself said it expects frontier capabilities to advance substantially over the next few months, and ASIC's Simone Constant put it more bluntly, describing the clock as sitting at a minute to midnight.
Shortening that gap changes what resilient means. A control regime built around an annual penetration test and a yearly cyber update to the board assumes the attacker moves at roughly human speed. Coalition CEO Joshua Motta drew the line for cyber underwriters: cyber risk cannot be underwritten on annual snapshots any more. The carriers operating on continuous telemetry will know which risks to write and which to walk away from. The ones still on annual questionnaires will not. He expects the hard market to arrive quietly.
That logic runs in both directions. If your cyber insurer is moving to continuous verification of your controls, and Willis is already signalling that weaker controls mean more scrutiny at renewal, then you need to see your own estate continuously too.
This is where core platform decisions become resilience decisions. Every additional system holding regulated data is another attack surface, another patch cycle, another vendor whose security program you are trusting, and another set of credentials to rotate when someone leaves. Every point-to-point integration between those systems is an interface with an owner (or more often without one).
Consolidating onto one system of record does not make you invulnerable. What it does is make the estate countable. One data model means one place the data lives. One managed API surface means every integration is known, authenticated, logged and retirable. When APRA or your capacity provider asks how many systems touch claims data, the answer is a number rather than a project.
Endava's Baneesha Narang framed the next competitive divide in insurance as the ability to operationalize and scale AI rather than simply having access to it. The same divide applies to defending against it. Allianz CIO Joanne Walker noted at the same event that banking has seen some movement back toward keeping data assets closer, precisely because people want to know where they are. The question is not cloud versus on-premise. It is whether you can point to where your data is at all.
Count the systems, spreadsheets and integrations that hold or touch policy, claims and customer data. For each one, write down the vendor, the owner, the last patch date and the last time anyone reviewed who has access. For each API, write down what it connects, who owns it and whether it is still needed.
If that exercise takes an afternoon, you are in reasonable shape and the security team can take it from there. If it takes a fortnight and the answer still has gaps, that is the finding, and it belongs in front of the board before the cyber controls discussion, not after. We covered the governance side of this in Your claims team is already using AI. Can your board govern it?
APRA has given you the framing. The frontier AI threat is real and it moves fast. But the exposure it exploits is the technology estate you already have. How many systems would an attacker need to break to reach your claims data, and could you answer that today?