InsurTech Geek Podcast podcast

Cyber Risk Engineering and Emerging AI Risks with Jay Vinda from Mosaic Insurance

0:00
33:57
Rewind 15 seconds
Fast Forward 15 seconds

Jay Vinda, Global CISO and Cyber Risk Engineering Lead at Mosaic Insurance, joins host James Benham live at ITC 2026 to explore cyber risk engineering, the emerging risks surrounding AI, and how cybersecurity intelligence is changing insurance.


Jay grew up in London wanting to be a chef, studied mechanical engineering, and spent a couple of months in Peru building wind turbines for villages without electricity. A cybersecurity graduate scheme in 2016 was meant to last a couple of years; he stayed, earned a master's in information security while working, and spent about eight years protecting banks and government before moving into insurance. At Mosaic he protects the company as its CISO and helps its cyber underwriters assess every risk the way an attacker would.


In this episode:

• Why the person who buys a cyber policy and the CISO who knows what could go wrong are rarely in the same conversation, and how Jay bridges the two.

• How criminal marketplaces and ransomware operators made funding, not technical skill, the real barrier to cybercrime.

• Why generative AI erased the old phishing tells, and what the scams that work today look like: no urgency and no link.

• Why the basics still beat the shiny tools, and why so much "AI-powered" security is fluff.

• What frontier AI changes for defenders, from vulnerabilities that sat undetected for 26 years to a risk appetite far lower than a criminal's.


Key Quotes:

"Insurers have loads of data, but they're just not using it very well."

"Social engineering is still a very easy way to compromise a company."

"Our risk appetite on the defensive side is just a lot lower than a criminal's."

"Really, you don't need that much to be a criminal."


Chapters:

00:00 Cyber risk engineering and emerging AI risks, live at ITC 2026

00:24 First time in Vegas and the original attention hackers

02:09 Growing up in London and wanting to be a chef

05:25 Mechanical engineering and wind turbines in Peru

06:05 Falling into cybersecurity in 2016

10:06 When cyber stopped being a game and became a board issue

11:06 Insurance, the honeypot of data

12:10 From banks and government to insurance

13:08 What Mosaic does: Lloyd's syndicates and skin in the game

14:13 Two hats: CISO and cyber risk engineering lead

16:06 The disconnect between the CISO and the cyber insurance buyer

18:32 A criminal marketplace that runs like a business

19:57 Phishing written by AI and the end of the easy tells

21:21 No urgency, no link

22:59 "How would I hack Mosaic?" and synthetic voice attacks

24:49 What keeps Jay up at night: the basics

26:34 Moving goalposts: MFA, passkeys and biometrics

28:09 Frontier AI and 26-year-old vulnerabilities

29:29 People doing stupid things: the gift card scam

30:05 Using AI as a proactive pen tester

31:01 Why defenders adopt AI slower than attackers

31:59 The people pleaser problem and wrap up


🔗 Connect:

Jay Vinda: https://www.linkedin.com/in/jayvinda/

Mosaic Insurance: https://www.mosaicinsurance.com | https://www.linkedin.com/company/mosaic1609


👤 Host:

James Benham: https://www.linkedin.com/in/jbenham


🎙️ This episode is sponsored by Terra, the next-generation Workers' Comp and Commercial P&C Software.

Visit 👉 https://terra.insure / https://www.linkedin.com/company/terrainsure/


📌 Find InsurTech Geek:

LinkedIn: https://www.linkedin.com/showcase/insuretechgeek/

Twitter/X: https://twitter.com/InsurtechGeek

Instagram: https://www.instagram.com/insurtechgeek/


Subscribe, rate, and comment. As always, Enjoy the Ride & Geek Out! 🤓

More episodes from "InsurTech Geek Podcast"