Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»The rise of the virtual CISO: a path to cyber resilience (Page 7)
Cyber resilience

The rise of the virtual CISO: a path to cyber resilience

Matthew Geyman describes the growth of the vCISO model in the MGA sector. The model offers a path to cyber resilience that aligns with both growth and fiscal constraints and is something that other sectors can learn from.
January 22, 20257 Mins Read
A helping hand for cyber resilience.

The insurance industry is witnessing unprecedented digital transformation, with the MGA (Managing General Agent) sector standing out as one of the fastest-growing and most dynamic areas. MGAs are thriving as they combine nimble operations with unique product offerings, rapidly expanding their market share. However, as they grow, they also become increasingly attractive targets for cybercriminals due to their sensitive data and limited cybersecurity infrastructure.

For mid-sized insurers and start-up MGAs, resilience against these threats is no longer optional – it’s an urgent necessity. In the face of increasingly sophisticated cyberattacks, these companies need to fortify their digital defences to protect assets, reputation, and consumer trust. Enter the Virtual Chief Information Security Officer (vCISO): an agile, scalable solution providing high-level cybersecurity expertise without the heavy overheads of an in-house CISO. For the MGA sector, which is evolving at a breakneck pace, the vCISO model offers a path to resilience that aligns with both growth and fiscal constraints.

Why cyber resilience is a must for the growing MGA sector

With the MGA sector’s rapid expansion, the stakes for cyber resilience are higher than ever. The global MGA market reached $23.9 billion in revenue in 2023, a testament to its robust growth trajectory and increasing influence. However, rapid growth also brings heightened exposure to cyber risks, especially as MGAs often rely on multiple third-party vendors to scale operations efficiently. This reliance expands their attack surface, making them attractive targets for cybercriminals.

Incidents like CNA Financial’s £30 million ransomware payment and the widespread breaches affecting insurers globally serve as stark reminders of the vulnerabilities inherent in the sector.

Recent data from ORIC International reveals different cyber loss events across the five industries that have reported the most cyber claims. It highlights the different nature of the losses suffered by each of the industry groups across nearly 1,200 reported claims between 2013 – 2019 from 50 countries with an average settled cyber claim totalling USD 4.88m.

Data breaches emerge as the most frequently reported losses, with significant financial and reputational repercussions for firms in the sector. Significantly, though, the insurance industry leads in exposure to malicious and accidental breaches among the five major industries reporting cyber claims. This underscores a pressing need for stronger cyber defences.

At the same time, while claims over $10 million make up only 5% of incidents, they account for a staggering 95% of total costs. For mid-sized insurers and MGAs, resilience against such threats is not only about protecting their own operations but also about safeguarding the client trust that fuels their growth.

The challenges of building cyber resilience for mid-sized insurers and MGAs

The growth of MGAs is driven by their ability to operate flexibly and efficiently. Yet, this agility can also be a double-edged sword in the world of cybersecurity. Many MGAs and mid-sized insurers rely on legacy systems or third-party solutions that may not be optimised to handle today’s sophisticated cyber threats. While larger insurers can invest in dedicated cybersecurity teams, MGAs often operate on lean budgets, leaving them with limited in-house resources to establish a robust cybersecurity infrastructure. Building resilience requires addressing these unique constraints.

For smaller firms, creating and maintaining an in-house cybersecurity team is rarely feasible. Instead, a vCISO offers a pragmatic solution, providing high-level cybersecurity oversight without long-term commitments or high costs. This approach allows MGAs and mid-sized insurers to focus on growth while ensuring their resilience remains a priority.

A Virtual Chief Information Security Officer offers mid-sized insurers and MGAs key benefits that align with their unique growth needs and limited resources. Firstly, vCISOs provide access to advanced cybersecurity expertise on a flexible, cost-effective basis. This allows MGAs to implement robust security measures without the significant expense of a full-time CISO, supporting their growth without straining budgets.

Secondly, a vCISO customises cyber strategies to address specific risks, helping firms build resilience against disruptions. By assessing vulnerabilities and aligning defences with business priorities, vCISOs develop strategies that support continued growth while managing cyber threats. Lastly, vCISOs enhance compliance and credibility by guiding MGAs through regulatory requirements. This oversight builds trust with clients, regulators, and partners, distinguishing MGAs as secure, reliable players in a highly competitive market.

Why cyber resilience is essential for credibility in the MGA sector

In the rush of rapid growth, it’s easy for cybersecurity to become an afterthought – especially when resources are stretched and priorities are focused on expansion and market capture. However, overlooking robust cybersecurity processes can leave MGAs and mid-sized insurers dangerously exposed to threats that could destabilise their progress. Establishing strong cybersecurity protocols not only protects the business and its data but also supports procurement standards, ensuring that partnerships are built on secure and compliant practices. As MGAs integrate new vendors, clients, and platforms, their third party risk increases with each integration – and cybersecurity becomes essential in meeting procurement requirements and safeguarding reputation, client trust, and operational continuity.

As insurers and MGAs expand their digital offerings, there’s a widening gap between selling cyber insurance and demonstrating strong cyber resilience within their own operations. For clients, this creates a perception issue: can they trust an insurer or MGA that’s vulnerable to the very risks it’s insuring against? This is where an independent vCISO can play a transformative role, helping firms establish foundational cybersecurity practices that reflect the resilience they promise to clients.

A vCISO can guide MGAs in implementing core cybersecurity practices such as multi-factor authentication, encryption, and regular vulnerability assessments. These measures help bridge the gap between external assurances and internal resilience, ultimately strengthening the firm’s credibility. In a sector driven by trust, a strong, resilient foundation is critical.

Embedding resilience as the MGA sector scales

MGAs are on a fast track to growth, often relying on a complex network of third-party vendors and data sources to scale. This makes them especially vulnerable to cyber threats originating from third-party weaknesses. A vCISO’s role in managing third-party risk is crucial, helping firms assess vendor security practices, set cybersecurity standards for partners, and monitor for potential vulnerabilities within their digital ecosystem.

The vCISO also supports MGAs in developing incident response protocols. Rapid response to a cyber incident can significantly limit damage, reducing downtime and safeguarding the firm’s reputation. By embedding resilience at every level, from internal teams to third-party vendors, a vCISO enables MGAs to grow confidently, knowing they’re prepared for whatever threats may emerge.

Resilience as a competitive advantage in a cyber-driven future

For insurers and MGAs, resilience has become a core competency. As the MGA sector grows, firms must embrace cyber resilience to sustain that momentum and protect client trust. A vCISO offers a cost-effective path to resilience that doesn’t hinder growth – allowing MGAs to benefit from industry-best cybersecurity practices while maintaining their competitive edge.

The vCISO model isn’t just about cost savings; it’s a strategic investment in a firm’s future. By embedding resilience as part of their operational foundation, MGAs can confidently scale in today’s risk-laden environment, building trust with clients and stakeholders alike. As they position themselves as industry leaders, resilience will set them apart in a sector that’s transforming at an unprecedented pace.

As the MGA sector continues to flourish, those firms that prioritise resilience will lead the way, embodying the balance of agility and security essential in today’s fast-paced insurance landscape.

The author

Matthew Geyman is Managing Director, Intersys UK

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleIt’s time to see cyber regulatory compliance as a strategic advantage rather than as a burden
Next Article How to improve BIA and other business continuity and risk surveys

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

July 9, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?