Your greatest threat now your board's best defense. A farm mutual proved it first. The “detect, decide, and fix” at machine speed era…


LION Specialty

Reading time: 5 minutes · Listening time: 7 minutes. Prefer to listen? Flip reads this week's Brief here.


For two years I've heard the same cyber story. AI is making hackers faster. AI is making attacks cheaper. AI is making your team fall behind. All true.

But somewhere along the way we stopped asking the obvious follow-up. What about our side?

A farm mutual in Indiana answered that question, and I'm spending the whole edition on it because the story touches cyber, D&O (directors and officers liability), and board governance all at once.

Here's what made the cut this week:

  • A 91-year-old farm mutual now answers cyber threats five times faster than it used to. It didn't hire a bigger team.
  • The average security team gets 960 alerts a day. Four in ten are never opened. Guess where the real one hides.
  • The same tool that can lower your cyber loss can raise a question in your next board meeting. Most directors haven't asked it yet.

The defenders got AI too

Here's the part that doesn't make the headlines. The defenders got AI too.

Think of a neighborhood watch where the burglars always had better gear: lock picks, disguises, lookouts down the block. Now the watch has night-vision goggles and radios of its own. That is where cyber defense sits today. In a 2026 survey by the International Insurance Society, 71 percent of insurance leaders called AI their top priority. Only 17 percent said they weren't ready for it. When the country's insurance commissioners surveyed auto and home writers a couple of years earlier, 88 percent of auto writers and 70 percent of home writers were already using, planning to use, or exploring AI and machine learning.

Your competitors aren't asking whether to use AI. They're choosing where to aim it.

(sources: IIS 2026, NAIC)

So what?

That makes it a board question.

The NAIC adopted a model bulletin on AI use by insurers in December 2023. Approximately 25 states have adopted it as of mid-2026. Its core principle applies to defensive tools: document what the AI does, and make sure the board knows it's running. AI governance questions are beginning to appear on some cyber renewal supplementals. Underwriters want to know whether you use AI in security operations, whether the board oversees it, and whether you log the decisions. No carrier is getting explicit rate credit for governance today. But underwriters are noticing which submissions answer those questions and which leave the section blank.

One carrier pointed AI at its own security operation. What they found is worth the rest of this edition.


The smoke detector that learned to read

You know the smoke detector in your kitchen, the one where burnt toast gets the same shriek as a real fire.

Now imagine 960 of those going off every day. That is the average for a security team, according to Prophet Security. Roughly four in ten alerts are never investigated. The real fire is somewhere in that pile, and nobody has time to find it. Indiana Farm Bureau Insurance, a farm mutual founded in 1934 writing coverage across all 92 Indiana counties, had a growing digital footprint and a small team that couldn't keep up.

They pointed AI at the problem.

(sources: Prophet Security, Dropzone case study)

The LION Lens

What happened — Indiana Farm Bureau added an AI security analyst from Dropzone on top of the tools it already owned. Nothing was replaced. The AI sits alongside the existing stack (Dropzone case study).

Why it matters — The AI reads every alert and gathers the evidence a human analyst would gather. It writes a plain-language verdict. The humans still make the calls.

Practical implications — The repetitive investigation work now runs around the clock. The analysts get their time back for the threats that require judgment.

So what?

The results are the kind that make a CFO look up.

Per the Dropzone case study, Indiana Farm Bureau reported answering threats approximately five times faster. Its analysts spent 75 percent less time on manual investigation. Most alerts got reviewed in under ten minutes. Those numbers come from the carrier's own account, published by the vendor, so read them as directional. What matters is the result: a small team at a regional mutual got around-the-clock coverage without adding headcount. A larger carrier will see a smaller lift. The discipline matters as much as the speed either way.

One moment stood out. During a routine security test, the AI flagged the tester's own activity. "It was an eye-opener for us," said Andrew Marsh, Indiana Farm Bureau's Director of Information Security.

The LION POV

Here's how we're advising clients who want the same result:

  • Run observer mode first. Let the AI investigate alongside your team for a few months. Grade its verdicts before it touches anything live.
  • Automate only the low-regret calls. Password resets, obvious lockouts. Keep a human on any decision that could take a production system offline.
  • Vet the tool like the new risk it is. An outside agent with the power to lock accounts is a third party inside your walls. Confirm indemnification terms, liability caps, your right to audit performance, where alert data is processed, and whether the vendor can train on it.

Test your response plan against two scenarios: the tool goes offline, and the tool is still running but has been manipulated into suppressing real alerts. The second is harder to detect. Speed finds the fire. Recovery limits the damage.

The carriers getting value from these tools didn't replace their people. They bought their people's time back and kept a hand on the wheel. From drowning in beeps to reading them.

Want to discuss how AI security governance affects your next renewal? Contact LION Specialty and we'll walk through it.


Speed is a board decision now

A triage nurse in an emergency room makes a fast judgment: heart attack goes first, paper cut waits.

In cybersecurity, sorting saves money. IBM found that the average breach takes 241 days to find and contain. Breaches resolved in under 200 days cost about 3.6 million dollars. The ones that drag past that line cost about 5.5 million, a gap of roughly 1.9 million dollars.

Speed matters, but how you govern it matters just as much.

(source: IBM Cost of a Data Breach 2025)

So what?

Giving an AI the authority to lock accounts is a board decision, not an IT decision.

Indiana Farm Bureau's setup keeps a full record of every alert reviewed and every verdict reached. That audit trail is evidence of oversight when the board acted on it. It is equally powerful evidence for plaintiff's counsel when the board did not. Every flagged alert your team did not act on is also in that record.

The tool can fail two ways. It can miss a real threat and let damage through. Or it can act on a false positive, lock out a real user, and cause the disruption itself. When either happens, which of your policies responds?

Most institutions have not asked that question yet. The cyber tower is often silent. A self-inflicted lockout does not fit the typical "unauthorized access" trigger. Technology errors and omissions (tech E&O) may respond if the AI is a third-party vendor product, but only if your form's definitions cover it. Those are two separate coverage questions. If you operate under delegated authority, there is a third: whether your capacity provider's program or your own is intended to respond. Settle all of them with your broker, in writing, before the tool goes live.

On the D&O side, documented board oversight is what your underwriter and your own directors will look for. A governed AI security tool with that audit trail is starting to sit alongside the controls a cyber underwriter already rewards: tested backups, endpoint monitoring, multi-factor authentication. It is not a rating credit today. But the direction is set.

Get it right and you pick up two wins from one move: you lower the odds of a costly breach, and you build the record that shows your board was paying attention.


Three questions for your next board meeting

  1. What is our current mean time to detect and contain a security incident? If nobody in the room knows the number, that's the first problem to solve.
  2. If we're using AI in our security operation, do we have a written policy, board-level sign-off, and a record of what the tool has done? Regulators and D&O underwriters will ask.
  3. If that AI tool fails, which policy is intended to respond? Cyber, tech E&O, or neither? Get that confirmed in writing before the tool is live, not during a claim.

The Bottom Line

For two years, the board question about AI has been a defensive one. Are we exposed? Could this hurt us?

Indiana Farm Bureau asked a better one. How do we put this to work on our side, and can we show that we're watching it?

The carriers who win the next few years won't be the ones who feared AI the longest. They'll be the ones who aimed it first and governed it well.

Before your next renewal, ask your broker one question: "If our AI security tool locks out a real user or misses a real threat, which policy responds, and can you show me the language?" If the answer is a pause, that is the conversation to have now.


LION has published a structured review of the five most common D&O program gaps: the D&O Contract Vigilance Blueprint, a five-day email course available to clients and subscribers preparing for renewal.

  • The policy mistakes we see most often when reviewing D&O programs
  • Where your personal assets sit when the company can't indemnify you

Want it? Just reply to this email with the word "blueprint" and I'll sign you up.

Thank you for reading today's edition.

Stay Covered Everybody,

-FLIP

P.S. The most telling moment in Indiana Farm Bureau's story wasn't a number. During a routine test, the AI flagged the tester, and their security director called it an eye-opener. The point isn't that the machine beat the humans. It's that a good leader said, out loud, that the tools had gotten good enough to surprise him.

Want to share this edition? Copy the link below:

https://lionspecialty.kit.com/posts/your-greatest-threat-now-your-board-s-best-defense-a-farm-mutual-proved-it-first-the-detect-decide-and-fix-at-machine-speed-era

And if this was forwarded to you, subscribe here: https://lionspecialty.kit.com/.

P.P.S. Nothing in this briefing constitutes legal, coverage, or compliance advice. This is market intelligence designed to help you ask sharper questions of your advisors and make better decisions at renewal.


You're receiving this because you subscribed to the LION Specialty Boardroom Brief.
Unsubscribe  ·  Update your preferences

LION Specialty

Everything you need to know to navigate the financial institution insurance market in ≈ 5 minutes per week. Delivered on Fridays.

Read more from LION Specialty

Reading time: 5 minutes · Listening time: 6 minutes. Prefer to listen? Flip reads this week's Brief here. For twenty-five years I have watched carriers buy each other for scale. The pitch is always the same: a bigger combined book with cost synergies in year two. A stronger negotiating position with reinsurers. I've nodded through that deck more times than I can count. Most of those deals didn't pay what they promised. I knew it. The CFOs across the table probably suspected it. Nobody had the...

Ransomware crews run help desks. Most firms have never tested a backup restore. Plus a record year for CEO exits, and AI scams that outgrew the social engineering sublimit.

Reading time: 5 minutes 🎧 Listening time: 6 minutes — prefer to listen? Flip reads this week's Brief here. Boards got impatient with their CEOs. Attackers are more organized than they've ever been. And FI regulators are moving faster than I've seen in 20 years. Your underwriters are stressing about all three. Lately I've felt like the cranky old insurance version of the get off my lawn guy. Saying to anyone that will listen: "Insurance programs simply weren't built for this era." This week...

A record $110,000 sanction. A federal AI-evidence rule sent back for a rewrite. And a defense play that works whether or not the rule ever arrives. Five minutes, boardroom-ready.

Reading time: 5 minutesListen time: 11 minutes Good morning. Two forces are reshaping litigation at once. Claims are getting more polished and more plentiful. The proof behind them is not keeping up. Generative AI can draft a flawless-looking brief in minutes. It cannot manufacture the evidence that brief needs. That gap is where this week's intelligence lives. Here's what's in front of you: Courts have now caught AI-invented citations in more than 1,700 filings (as of July 2026), and one...