9 February 2026 • 3 min read

From Remote Work to AI Risk: The New Age of Cyber Threats | FIA Cyber Quarterly

Cyber risk has evolved from basic network vulnerabilities to sophisticated AI-driven fraud and impersonation attacks. This insight explores how cyber insurance, organisational culture and human vigilance must adapt to keep pace with an increasingly complex threat landscape.

iTOO

iTOO

The pandemic of 2020 was a watershed moment for cybersecurity. As organisations pivoted to remote work, many were caught off guard by the vulnerabilities exposed through unsecured connections. The surge in ransomware and extortion attacks revealed just how unprepared businesses were for a fully digital operating model. VPNs, multi-factor authentication (MFA) and endpoint security went from optional upgrades to urgent priorities.

From a cyber insurance perspective, this period saw an unprecedented spike in ransom-related claims. The sudden shift to remote work created fertile ground for threat actors, and insurers responded by reinforcing coverage for network security breaches and data privacy violations. These events laid the groundwork for a more proactive, prevention-focused approach to cyber risk.

Rise of AI risk

Fast forward to today, and artificial intelligence (AI) is both a powerful ally and a formidable adversary. Generative AI and large language models (LLMs) have unlocked new efficiencies, but they’ve also introduced emerging risks. Deep fakes, voice cloning and AI-driven impersonation attacks are no longer speculative; they are happening now.

Professionals relying on AI-generated content face exposure to errors and omissions, especially in fields like law, finance and tech. A misinformed legal brief or a flawed algorithm in a self-driving car could trigger professional indemnity or product liability claims.

Cyber insurance policies, while traditionally broad, are now being tested by these new frontiers. Fortunately, most policies remain robust enough to cover AI-related breaches, as they still fall under the umbrella of network or data security failures.

Emerging crime trends

Today’s cyber insurance market is notably soft, characterised by high capacity and low premiums. This means businesses can access substantial coverage at competitive rates. However, this affordability should not breed complacency. The frequency of business email compromise attacks and fraudulent fund transfers is rising, driven by increasingly convincing social engineering tactics.

Threat actors now impersonate suppliers, intercept emails and manipulate banking details with alarming precision. Yet, the human element remains the weakest link, especially when finance teams are rushed or unaware. Insurers are seeing a shift from ransomware to financial fraud as the dominant claim type, underscoring the need for vigilance.

A human solution

Combatting these threats requires more than technology; it demands cultural change. Simple measures like verifying banking detail changes via phone, implementing dual approval for high-value transactions and enforcing MFA across payment systems can dramatically reduce exposure. For families and individuals, establishing code words or verification protocols can thwart AI-driven scams and voice impersonation.

Cybersecurity is no longer just an IT issue but a strategic imperative. As we enter the next quarter of the century, organisations must invest not only in tools but in education, governance and insurance that evolves with the threat landscape.

The future of cybersecurity will be shaped by how well we harness AI for defence, educate users to spot deception and build resilient systems that anticipate risk, instead of just reacting. Cyber insurance will continue to play a vital role, offering a safety net while encouraging best practices. However, the real power lies in preparation, such as knowing that a simple phone call, a second pair of eyes or a well-trained AI can make all the difference.