Skip to content
The InsurTech Geek PodcastEpisodesTopicsGuestsBooksAboutSponsorContactSubscribe
Jay Vinda
← Episode guide Episode 185

How Would I Hack Mosaic? Jay Vinda on Cyber Risk Engineering, the Criminal Marketplace, and Why the Basics Still Win

Jay Vinda
Global CISO & Cyber Risk Engineering Lead · Mosaic Insurance
Published Oct 9, 2026
Runtime 34 minutes
Host James Benham
YouTube Spotify Amazon iHeart Apple

Jay Vinda

Jay Vinda, Global CISO and Cyber Risk Engineering Lead at Mosaic Insurance, joins James Benham live at ITC 2026 to explain why the person who buys a cyber policy is rarely the person who knows what could go wrong, how criminal marketplaces made funding the only real barrier to cybercrime, why generative AI erased the old phishing tells, and what frontier AI changes for attackers and defenders.

Watch here

The full episode

Press play for the whole conversation.

Sponsored by
Terra
1

From Chef to Engineer to CISO

Jay was born and raised in London, and growing up he wanted to be a chef. He still loves to cook, although delivery has mostly won. At university he studied mechanical engineering for four years, a stretch that included a couple of months in Peru building wind turbines for villages with no access to electricity. What engineering really gave him, he says, was a love of solving problems and the habit of looking at anything and asking how you would start.

Out of university he could not find a job, so he applied for almost everything. A cybersecurity graduate scheme said yes, and the plan was to do it for a couple of years and then switch back to engineering. He started in 2016, at what he calls a real inflection point: the Mirai botnet was turning swarms of connected devices into denial of service weapons, and 2017 brought ransomware like WannaCry and espionage campaigns backed by nation states. He liked it, and he stayed. Along the way he went back to university while working and earned a master's in information security, a decision that felt like a great idea right up until the dissertation.

The job changed under him. In the early days cyber was the kind of work where you built drones and hacked them because it was fun. Within a couple of years it had become a board issue, with regulatory compliance and cyber risk management turning into disciplines of their own. Done really badly at a company, he says, security failures could cost lives, or bring massive fines.

"Now I've got a job that actually means something, that actually really needs to be thought about."

Jay Vinda
2

The Honeypot of Honeypots

James calls cybersecurity one of the most important technical professions in insurance right now, and the reason is simple. Insurers sit on a treasure trove of personal data, everything you would ever need to hack the world. Jay's frustration is that the industry does not get much value out of it either. There is a treasure trove of data in insurance, he says, but the way it has been standardized, collated and categorized is just not that great.

Most of Jay's career before insurance was spent with financial institutions, mostly banks, and with government. After about eight years he wanted a change of pace and scenery, and insurance looked like a friendlier place to try. Mosaic is a specialist insurer with regional hubs across six countries and two Lloyd's syndicates it underwrites on behalf of. Jay describes it as close to the MGA model, except Mosaic has skin in the game: it always keeps a minimum of 20 to 25 percent of every risk on its own paper. It writes around ten lines, from cyber and political violence to environmental and professional liability. The name, they agree, is appropriate.

"Insurers have loads of data, but they're just not using it very well."

Jay Vinda
3

Two Hats, Two Reporting Lines

Jay's role is unusual. As CISO he reports to Mosaic's chief operating officer, who leads operational resilience for the organization, and he owns cyber resilience. He also reports to the head of cyber underwriting, a team of about 40 underwriters spread across Canada, the US, Bermuda, the UK, Germany and Dubai. For them, he uses his security knowledge to improve how each individual risk is assessed, and uses threat intelligence to map out the scenarios that make up the portfolio. In effect, he does for Mosaic's insureds what he does for Mosaic.

He also partners directly with insureds to help shape their security strategy. Some have their own CISO; others give the title to whoever runs IT. Mosaic has traditionally focused on mid-market and large corporate clients with revenues of 150 million dollars and up, and this year it opened an SME platform for companies in the 10 to 150 million dollar range. Those businesses usually do not have a CISO at all, and they often outsource to managed service providers without anyone in house who can challenge them on what their risk profile really looks like.

4

The CISO and the Buyer Are Not in the Same Room

At ITC, Jay is speaking about cyber risk through the eyes of a CISO, and it is the topic he is most passionate about right now. When a company buys cyber insurance, the buyer tends to be the risk manager, someone in the CRO's or CFO's office, or the chief legal officer. Their motivation is to get the most coverage at the lowest premium, and that is the conversation they have with the broker.

But before anyone shops for a policy, someone with a security mindset has already decided there is cyber risk the company needs to transfer: the things that genuinely keep them up at night, the problems they are struggling to solve.

Part of Jay's job is to bring those two together, so the risk manager understands that the policy wording and endorsements need to cover the scenarios that could materially go wrong for the organization. James asks whether that makes him part therapist. Jay laughs that at CISO conferences they already call it CISO therapy.

"Right now you've got a real big disconnect between the person who knows what could really go wrong and the person who's buying insurance coverage."

Jay Vinda
5

A Criminal Marketplace That Runs Like a Business

James has been building software since the internet commercialized in the early nineties, and was on bulletin board systems before that. There have always been threats, he says, mostly malicious viruses. What is different now is that the threat is state sponsored, well funded, well organized, and run a lot like an insurance company. Jay goes further: it is literally a criminal marketplace.

In the past, an attacker needed both the technical capability to operate an attack and the commercial mindset to monetize it. Neither is required anymore. With funding, a criminal can go to the marketplace and assemble the capabilities they need, and ransomware operators will take care of the monetizing.

The shift, Jay says, is not so much in capability as in capacity: how many people can now become cybercriminals. James adds that they need fewer people, too, running open weight models on their own machines with no guardrails. Their emails, text messages and synthetic voice work are all getting better.

"Really, you don't need that much to be a criminal."

Jay Vinda
6

The Tells Are Gone

Jay shares an example from the Asia Pacific region. People in Japan used to spot phishing by how the characters were put together, because an attacker who did not speak Japanese produced text that read as broken to a native speaker. Generative AI made it easy to write Japanese, Chinese or Korean that looks like a native speaker wrote it, and that way of spotting phishing stopped working.

The same is happening in English. It used to be easy to sniff out a scam: the formatting was wrong, the images were off, the HTML was poorly formed, and there was always a sense of urgency. Today, Jay says, the opening message often has no urgency and no link. It might be an email that looks like it was meant for someone else. You reply to correct the sender, they apologize, and since you are chatting anyway, the conversation carries on. And it works.

James recalls his cousin, a comedian, who about 20 years ago texted thousands of numbers by hand with a simple "hey, what's up" and was amazed by how many strangers engaged in long conversations.

7

"That's My Fault"

That raises an uncomfortable point about security awareness training. The industry spends a lot of time teaching people what bad looks like, and Jay worries it has become a liability shift: if you trained your users, the click is their fault. He does not see it that way.

A single link should not be able to take a company down, and building that resilience is the job. Jay describes the fun part of it simply: his job is basically sitting there thinking how he would hack Mosaic, how he would impact its customers, and then how he would stop it.

Synthetic voice attacks are an obvious next test. Jay has not run one at Mosaic yet, and both agree it is not hard. Open source tools make it simple, and the source material is everywhere: people speak at conferences that get published online, and company marketing teams post clips on Instagram and TikTok. Legitimate voice and video providers make you verify that you are who you say you are. Plenty of other tools do not.

"If Mosaic gets taken down because someone clicked on a dodgy link, that's my fault."

Jay Vinda
8

The Basics Still Win

Asked what keeps him up at night, Jay's answer is not exotic. It is the basics, for two reasons. First, many of the controls that protect an organization are process based. They do not need a big technology spend, but they need a lot of effort to get a control to the point where it actually prevents a threat. The temptation is to skip the effort and buy a tool.

Data classification and data loss prevention are his example. Organizations keep trying to hand the classification problem to someone else, and it becomes very expensive without being solved. Put in the time and effort yourself, he argues, and you can solve it fairly quickly.

Second, the goalposts keep moving. The basics used to be a strong password and antivirus. Then came multifactor authentication, prompts that went from once a month to once a day, and now passwordless sign in, passkeys and biometrics. James notes that authentication barely changed for decades and then transformed in the last two years. Jay welcomes it: a password manager is a vulnerability in itself, and biometrics and passkeys make his life a lot easier.

"There's so many tools out there that say they're AI-powered cybersecurity or next-generation AI cybersecurity, and it's just a lot of fluff."

Jay Vinda
9

Frontier AI, 26-Year-Old Vulnerabilities, and the Risk Appetite Gap

On the positive side, both are most excited about frontier AI, though Jay looks past the hype. For a cybercriminal, he says, it is not really a game changer yet.

It works and it is cheap, so why switch to something a lot more expensive? The defensive case is different: frontier AI can detect zero-day vulnerabilities before they are used. Jay points to Mythos finding vulnerabilities that were 26 years old, and takes two lessons from it. The reviews in use today, code reviews, human reviews and security tests, did not catch them, so this is a real step change. And he does not believe nobody knew about them for 26 years. More likely, someone knew and was saving the zero-day for a better opportunity. Now defenders can find those holes and fix them before they are used against them.

James's own biggest worry is simpler: people doing stupid things, or, as they settle on, naive and trusting things. He has two or three friends who fell for the gift card scam, and one lost their job over it. But he is just as excited about the defensive side. He vibe coded his own site, jamesbenham.com, had an AI model run a full penetration test on it, pushed it to dig ten levels deeper at maximum effort, and got back 27 upgrades. The criminals have these tools, he says, and so do we.

Jay notes that AI in security operations is not new; it was already being built in when he started in 2016. What holds defenders back is appetite for risk.

If a criminal's AI experiment fails, they move on and do something else. If a defender lets AI make decisions autonomously and it goes wrong, it hurts a lot. The landscape is now so asymmetrical in the attackers' favor that defenders are almost forced to try, helped by models they can explain and understand much better than before. The one thing that still annoys Jay: the models are massive people pleasers. These days he ends his prompts by asking for an honest opinion.

"Social engineering is still a very easy way to compromise a company."

Jay Vinda

"Our risk appetite on the defensive side is just a lot lower than a criminal's."

Jay Vinda
10

Key Takeaways

1
Crime no longer needs skill: Criminal marketplaces and ransomware operators mean attackers need funding, not technical ability, to launch an attack.
2
AI erased the easy tells: Generative AI writes flawless phishing in any language, so bad grammar and urgency no longer give it away.
3
Basics beat shiny tools: Strong controls take effort, not big spend. Many tools sold as AI-powered security never fix the problem you actually have.
4
Connect the CISO and the buyer: The person who knows what could go wrong rarely buys the cyber policy, so coverage often misses the real scenarios.
11

Connect with Jay Vinda

Jay Vinda Mosaic Insurance Podcast
Browse all episodes

Never miss an episode

Sign up for the InsurTech Geek newsletter and get new episodes, insurtech trends, and articles straight to your inbox.

The showAll EpisodesTopicsGuest DirectoryAsk the GeekBooksAboutContactPrivacyTermsSponsor the showPitch a guest
ListenApple PodcastsSpotifyAmazon MusiciHeartRadioYouTube
FollowLinkedInYouTubeXInstagram