
Cyber Risk Engineering and Emerging AI Risks with Jay Vinda from Mosaic Insurance
Jay Vinda, Global CISO and Cyber Risk Engineering Lead at Mosaic Insurance, joins host James Benham live at ITC 2026 to explore cyber risk engineering, the emerging risks surrounding AI, and how cybersecurity intelligence is changing insurance.
Jay grew up in London wanting to be a chef, studied mechanical engineering, and spent a couple of months in Peru building wind turbines for villages without electricity. A cybersecurity graduate scheme in 2016 was meant to last a couple of years; he stayed, earned a master's in information security while working, and spent about eight years protecting banks and government before moving into insurance. At Mosaic he protects the company as its CISO and helps its cyber underwriters assess every risk the way an attacker would.
In this episode:
• Why the person who buys a cyber policy and the CISO who knows what could go wrong are rarely in the same conversation, and how Jay bridges the two.
• How criminal marketplaces and ransomware operators made funding, not technical skill, the real barrier to cybercrime.
• Why generative AI erased the old phishing tells, and what the scams that work today look like: no urgency and no link.
• Why the basics still beat the shiny tools, and why so much "AI-powered" security is fluff.
• What frontier AI changes for defenders, from vulnerabilities that sat undetected for 26 years to a risk appetite far lower than a criminal's.
Key Quotes:
"Insurers have loads of data, but they're just not using it very well."
"Social engineering is still a very easy way to compromise a company."
"Our risk appetite on the defensive side is just a lot lower than a criminal's."
"Really, you don't need that much to be a criminal."
Chapters:
00:00 Cyber risk engineering and emerging AI risks, live at ITC 2026
00:24 First time in Vegas and the original attention hackers
02:09 Growing up in London and wanting to be a chef
05:25 Mechanical engineering and wind turbines in Peru
06:05 Falling into cybersecurity in 2016
10:06 When cyber stopped being a game and became a board issue
11:06 Insurance, the honeypot of data
12:10 From banks and government to insurance
13:08 What Mosaic does: Lloyd's syndicates and skin in the game
14:13 Two hats: CISO and cyber risk engineering lead
16:06 The disconnect between the CISO and the cyber insurance buyer
18:32 A criminal marketplace that runs like a business
19:57 Phishing written by AI and the end of the easy tells
21:21 No urgency, no link
22:59 "How would I hack Mosaic?" and synthetic voice attacks
24:49 What keeps Jay up at night: the basics
26:34 Moving goalposts: MFA, passkeys and biometrics
28:09 Frontier AI and 26-year-old vulnerabilities
29:29 People doing stupid things: the gift card scam
30:05 Using AI as a proactive pen tester
31:01 Why defenders adopt AI slower than attackers
31:59 The people pleaser problem and wrap up
🔗 Connect:
Jay Vinda: https://www.linkedin.com/in/jayvinda/
Mosaic Insurance: https://www.mosaicinsurance.com | https://www.linkedin.com/company/mosaic1609
👤 Host:
James Benham: https://www.linkedin.com/in/jbenham
🎙️ This episode is sponsored by Terra, the next-generation Workers' Comp and Commercial P&C Software.
Visit 👉 https://terra.insure / https://www.linkedin.com/company/terrainsure/
📌 Find InsurTech Geek:
LinkedIn: https://www.linkedin.com/showcase/insuretechgeek/
Twitter/X: https://twitter.com/InsurtechGeek
Instagram: https://www.instagram.com/insurtechgeek/
Subscribe, rate, and comment. As always, Enjoy the Ride & Geek Out! 🤓
More episodes from "InsurTech Geek Podcast"



Don't miss an episode of “InsurTech Geek Podcast” and subscribe to it in the GetPodcast app.








