(Image credit: Shutterstock.)
Whatever one’s preferred origin story, it’s clear that we live in interesting times. While challenges abound, opportunities also await insurance carriers pressing into the back half of the decade. As 2025 enters its final quarter—a period of budgeting and planning—it’s worth assessing where priorities should lie heading into the new year.
Two of the most consequential themes of the past year have been the exposure of cybersecurity vulnerabilities and the rapid emergence of AI capabilities across carriers’ operating models. Both demand attention, yet each can distort priorities if viewed in isolation. The challenge now is balance.
When it comes to security, the impulse is always to spend “just a little more.” But money alone won’t solve the problem. Effective strategies require understanding emerging threat vectors, learning from higher-volume industries such as banking and retail, and staying current with vendor solutions. Supply-chain attacks proved both real and consequential in 2025, reverberating across carrier ecosystems. As technology environments grow more interconnected, vendor management and procurement now play central roles in safeguarding availability and resilience. The old fortress model of data-center security has become quaint by comparison.
Artificial Intelligence: Promise and Perspective
The relentless advance of artificial intelligence is equally hard to ignore. Proponents tout its potential to boost productivity and performance, and some insurers are already realizing benefits from agentic AI. Yet several studies—including from MIT and Gartner—suggest that results remain mixed. Gartner now places AI in the “Trough of Disillusionment,” a reminder that transformational technologies mature gradually, like the browser or personal computer before them.
The key is learning how to integrate new capabilities with existing systems while extending pilots and capturing incremental gains. This will be a marathon, not a sprint—and it must unfold alongside other mission-critical priorities such as reducing technical debt and responding to shifting customer demographics.
The Human Factor in Technology Strategy
Neither cybersecurity nor AI is merely a technical issue. Maximizing opportunity and minimizing risk require alignment across people, process, and technology. Some of the Scattered Spider incidents have underscored how easily that intersection can break down. CIOs within our Study Group network consistently identify this balance as vital to securing their environments.
A recent McKinsey study on AI reached the same conclusion: the greatest gains occur when technology is synchronized with organizational culture and workflows. In our network, the most successful AI initiatives have applied this insight deliberately.
The road ahead will offer no shortage of uncertainty. But being mindful of the people–process–technology relationship can accelerate progress and prevent wasted effort. Now is the time to find that balance.
Shock Absorption: Balancing AI Ambition with Insurance Fundamentals
