Leadership in Digital Risk Management for 30 Years

After more than 30 years of leadership in digital risk management, Cyber Risk Insights Limited provides actionable insight on digital risk, viewed through the lens of insurer and insured balance-sheet exposure and risk capital — applied across the full range of where that risk now lives. From the balance-sheet exposures insurers are pricing today, to the exposures the next decade of quantum-capable computing and autonomous AI will create.

Explore how this plays out across five areas:
  • Post-Quantum Transition
  • Agentic AI & Silent AI
  • Cyber-Physical Damage (CYPD)
  • Robotics & Physical AI Governance
  • Risk Capital Provisioning in Data Centre Build Lifecycle

Digital risk is bigger than cyber risk

Digital risk is bigger than cyber risk, and treating the two as synonymous is itself becoming a source of exposure. Cyber risk — data, systems, unauthorised access — is one facet of a wider phenomenon: the accumulating, interconnected exposure created as encryption regimes reach their expiry date, AI systems begin acting rather than merely advising, physical infrastructure inherits software's fragility, and intelligent machines move into the physical world. The five areas explored below are where that phenomenon is concentrating most visibly today, but the dynamic connecting them is the same: digital capability is advancing faster than the frameworks built to govern, finance, and insure it.

This matters differently, but comparably, for IT-centric and OT-dependent enterprises. For the former, exposure concentrates in data, identity, and decision-making, where an AI-driven error or a harvested credential surfaces as loss. For the latter, the same dynamics surface as physical consequence: a compromised control system, a robot acting faster than its safety layer can be trusted to catch.
Regulatory exposure
Regulatory exposure is the most immediate: obligations such as the EU AI Act's requirement for genuinely effective human oversight assume a human can meaningfully intervene, an assumption that strains once decisions occur at machine speed, and points toward a real open question — how oversight itself evolves toward continuous, meta-level approval and dynamic compliance testing, rather than static sign-off.
Risk capital provisioning
Risk capital provisioning is the second, and nowhere is it starker than data centre financing: construction-phase risk sits with sponsors and lenders, operational risk transfers as facilities are refinanced into infrastructure capital, and digital risk — quantum exposure, AI liability, cyber-physical damage — must be re-underwritten at each transition, often by parties with very different risk appetites to those who financed the build.
Insurance
The third is insurance itself, being asked to do more, differently. Beyond conventional cover, digital risk is accelerating interest in reinsurance capacity, alternative risk capital, captives, and retained risk groups — structures that let genuinely novel, correlated exposure be pooled, transferred, or retained deliberately, rather than left to default into whichever policy happens to respond.

Cyber Risk Insights Limited

14 Cotton's Gardens
London
E2 8DN
Search