00:00:21
Hello and welcome back to Tech TV. Uh today we’re going to be discussing some of the really major systemic attacks that there have been on uh key companies both in the UK and across Europe. Um I’m joined as normal by my uh colleague Pete. Um Pete, Jaguar Land Rover have been hit in a very big way. Tell us a little bit about what your thoughts are on this incident. Well, I’m on record as saying for ever such a long time now, um young as I look, uh that it’s about time we did something about this. Look, this is a
00:01:02
nightmare. You’ve got C companies who are actually going to an order. It’s not just Jaguar Land Rover. All of their suppliers are now in a lot of trouble. The we’re um I wrote a book about this back in 2006. It was called Cyber Alert. And everybody then was going on about this being a wild west. This isn’t a wild west. This is some sort of mad anarchic situation where you’ve got crime gangs just going around shooting the place up and everybody is is is suffering as a result. It has to stop.
00:01:35
This really has to stop. And then Bill, as a further factor, we’ve got this cyber insurance issue which is just ridiculous. Well, there have been some notifications that Jaguar didn’t have cyber insurance in place and therefore is going to have to meet the entire cost here. It’s not that they weren’t aware of the need for cyber insurance, but they were in the process of having a a new policy in place and they failed to complete the process and therefore they left themselves vulnerable. So obviously
00:02:08
there are factors that are uh both for and against insurance and every company has its own choice about whether it insures itself, whether it pays ransoms or whatever. But for them to actually intend to have insurance in place and actually through incompetence to fail to be protected, I think is a is a massive howler. And that brings us on to well what are the systemic implications here? not only of a big company like uh Jagger and we’ll come on to talk about some of the aerospace incidents as well but also the
00:02:44
systemic impact on all their suppliers um and if this is going to happen more frequently what’s going to be the impact on the insurance industry itself and I mean we’re already already seeing premiums increasing and it being far more conditional what are your thoughts on where things are going here >> well as you know Bill we At Future Intelligence, we’ve been investigating cyber insurance for well over three years now, and the situation is a complete mess. Not only for three years
00:03:16
as has future intelligence been looking at it, but during David Cameron’s administration, we were asked into the Cabinet Office by Francis Moore to actually talk to them about what we considered the situation to be. And we were there with a lot of the major insurers. And at that time I pointed out that there was an absolute need for transparency over cyber attacks. We had to know exactly that we should have mandated that people who had suffered a cyber attack should inform the police. And I said that at the time because how
00:03:52
can you expect the cyber insurance industry to come up with a proper policy or with a proper understanding of what the picture is unless they’ve got the correct figures? It’s ridiculous. And that’s what we’re seeing now. We’re seeing this situation just getting worse and worse. I mean, you look at these these um supply chains, right? The the supply chains can’t get get insurance. Um Norwich Union said uh about nine months ago that there were only around 10% of the companies in the UK that got
00:04:25
cyber insurance. So even if if Jaguar Land Rover had got cyber insurance that doesn’t mean that the situation instantly remedies itself because those companies will also be going to the wall too because the cyber insurance is just for recovery from an incident. That’s essentially what it is. So you you know and we’ve been trying to promote this to lots and lots of organizations. At the moment it’s deaf ears but the cy the insurance industry also bears a certain amount of blame in this because
00:04:59
it’s a moving playing field. So what they’re saying is that they’re going to ensure people if they consider them to have the correct cyber posture. Some people have been talking about putting into companies the equivalent of the black box that you put into a young person’s car when they pass their driving test to make sure that they’re not driving badly. Um, we need a a real root and branch remedy to all of this and we do need it fast. But I I stress insurance is not going to be the remedy.
00:05:34
Insurance is what occurs after somebody smashed through your wall. Yeah, but we do need a an accurate and competitive market where we know what the risk is and therefore there can accurately price policies otherwise there’s going to be real problem in the market and as you say insurance is never a substitute for cyber security. You need both. Um and one of the things that concerns me is on the disclosure front which is going to give the entire industry a better picture of what the risks are here. We have the government’s
00:06:15
um cyber sec cyber security and resilience bill where their talk about mandating disclosure of um incidents but this has been delayed. It’s been rumored to be coming out at various times this year. And the latest I’ve heard is obviously in the last reshuffle that’s happened very recently, the cyber security minister has changed and she’s gone to the backbenches and the the bill itself has been delayed to the next parliamentary session which will be in the spring and that puts things further
00:06:50
back. So for the insurers to have a really accurate picture of the risk here, not only do they need better disclosure so that we know exactly how many incidents are happening, but they need a better idea of what the security position is of the different companies. Now, it’s all well and good for large companies where you can do a really detailed cyber audit because these are expensive exercises to do and you can only really afford to do them for a large company and that gives you an actual accurate idea of the posture and
00:07:26
therefore you can price the risk and the policy accurately. But if you’re talking about the the mass market, it’s cost prohibitive to do that sort of detailed cyber audit. Um and we have um uh various different uh uh cyber risk agencies who try and measure risk and price it independently a bit like your credit risk or or or whatever in the financial markets. But these are very inaccurate. They don’t get access to the inside of a company. They just use bots that troll troll the net looking for
00:07:59
externally facing endpoints and they test them for known vulnerabilities to give you a score which is has it’s been compared to sort of assessing fire risk by uh taking a picture of a building from the opposite side of the street. Uh you don’t have any idea whether it’s got fire extinguishers or fire doors or anything like that. So it’s fairly inaccurate. So we do need a better picture of the risk. We do need a a cyber insurance market that’s working better and then maybe the number of
00:08:28
people having insurance or carrying it will increase beyond 10%. But if you look at the price of recovery uh and the cost involved, even if we do have a bigger market, it’s still going to mean that the costs are going to drive up premiums and it could be unaffordable. Well, but look, I mean, it’s inevitable that the premiums are going to go up. The sums don’t add up, right? Currently, I if you go to any cyber security conference, you have the people on the stage saying, “We expect 95% of
00:09:05
businesses to be here.” Well, that’s okay. But then you get companies like IBM in its threat report and various other threat reports. Those companies are saying the average cost of a cyber incident now is between 1 and 3 million for a small and mediumsiz company. Well, if 95% of companies are going to be hit and the and those are the costs, then it doesn’t add up for the insurance industry. So, it’s inevitable that the premiums are going to go up because you’re going to be be they’ll be
00:09:36
expecting to be paid out. I mean, it’s not as if if you think about car insurance, car insurance is quite expensive now, but if 95% of the cars on the road were crashing into each other, it’d be a lot more in expensive. And this is something that we need to sort out. But I will stress that cyber insurance is not a magic bullet to all of this. Cyber insurance can actually become a bit of a problem because one of the things that ransomware gangs do is when they’re actually inside a company,
00:10:05
they try to find out whether the company does have an insurance policy because then they think, “Ah, right, we can exploit that. We can probably make them pay out.” And in fact, I think it’s in um Australia and I think a similar policy has been adopted in the UK now where it’s going to be made illegal to pay out to a ransomware attack, which does strike me as actually a very positive mood because you have to destroy the market. >> Well, you’re you’re you’re hitting the
00:10:32
point there. Cyber insurance is never a substitute for protection or you desperately also need um a recovery uh plan if you need the ability and you need to rehearse your crisis management plan um and you need to ensure that your backups and everything are in place. So you you need to be um preventing an incident and having prevention and detection. You also have the need for incident response and the ability to respond. Something that’s rehearsed. You need the backups. You need to test them.
00:11:07
And and far too few people test either their incident response plans or their backups. And they find that both are lacking when things happen. So all of that is true, but effectively we have to um address this in somehow whether this is by better international policing and enforcement or better protection and detection. Um maybe we need to turn to an expert on the matter, somebody from the industry who is going to be able to shine some light on exactly what the problems are here. Uh, I’d like to
00:11:41
welcome into the studio Edward Lewis, the chief executive officer of Scel. Um, Edward, thank you so much for joining us. Um, obviously you guys have enormous experience and knowledge in this arena and you’ve been heard hearing to a lot of our pontifications here. I wonder what your thoughts are on the market, its preparedness, um the the status in terms of insurance and other factors and where we stand and what we need to do. >> Right. Well, firstly, thank you for having me on, Bill. Pleasure to be here.
00:12:19
Um really interesting to listen to you both chatting in the opening there. Um I’ve worked in cyber and in particular in the cyber insurance market for uh what near enough 18 years at this point. Um and I have to say that um I have a lot of time a lot of respect for what insurers are trying to do. We’re in a period at the moment where um the market is soft. The premiums for cyber insurance are incredibly low. There’s more capacity than there is demand. Um, if you look at statistics here in the
00:12:49
UK, only 10 to 15% of eligible buyers actually choose to buy cyber insurance. So, I don’t think there’s a problem per se with insurance at all. Quite the opposite. There’s a problem with the message about the value of insurance and trying to encourage organiz organizations actually to buy policies as part of an holistic approach to security and resilience. Um, one of the things that we often see when we talk to slightly larger organizations, so let’s be let’s be clear, we’ve got SMBs, small
00:13:18
and mediumsiz businesses, of which about 97% of all businesses in the UK are comprised. Then you get the corporate mid-market and then you get the enterprise multinational level, but they’re a very small cohort in contrast to to the vast majority of of businesses that we see in the UK. And I think for most of those businesses up until this year the general view has been look we get this this thing called cyber it’s a problem but it doesn’t feel particularly approximate tends to happen to other
00:13:50
people rather than to us. As I say that was previously this year that’s changed. we’ve got now very much in the public consciousness on the front line all of these attacks not just against big business but in terms of also how those attacks propagate and cascade down to much smaller entities in supply chain. So I think that should help certainly in terms of getting a better message out about the importance of firstly building resilience and security but secondly dealing with risk, transferring risk and
00:14:19
if you’re looking at transferring risk then one of the best mechanisms for that is to insurance. So um a sort of we’re living and breathing right now this this change in consciousness this change in approach. I suspect we will see statistics next year suggesting that more people are buying cyber insurance in 2026 than we’ve seen in the previous 5 10 years as a whole. >> Okay. What’s the backdrop to all of this Ed? Well, we you know we we’ve seen this this week alone we’ve seen two two
00:14:50
attacks or sorry I mean the Jaguar land over what was earlier. However, we’ve seen two attacks and the impact of these is beginning to become significant. I mean, we we’ve seen with the Jaguar Land Rover one, we’re seeing entire supply chains affected. We’re being told that a lot of firms in the UK are are impacted by this. We’re with the the uh the airports attack. What we’re seeing is airports have been disabled. The psychological impact on the population at large with all of this
00:15:25
is going to be that there’s a lot of uncertainty that’s being developed. You’re going to get people, we’ve had several that that there’s incidents that have involved airports, whether they be cyber attacks or fires or whatever. >> 600% increase in the last 12 months in attacks on the aviation sector. 600%. That’s the statistic that um that was issued by I think it was INISA or the NCA over the weekend. >> And so, do you want to go traveling? Do you want to end up stuck in an airport
00:15:55
with your kids and all your luggage wondering when you’re going to get back or whether you’re going to cancel the airport the the the holiday? >> Exactly. I mean, look, mo most of the incidents though that we’ve seen um in the context of aviation have been groundside, not airside. So, I think it’s it’s important that we’re balanced and careful with the message that we send. No, there is no suggestion that um the airline flight safety is at risk here. This is really about the
00:16:21
disruption and chaos that’s caused when a back-end system, an operational system on the ground, often run by a third party rather than the airport or the airline itself goes down. And what we see when these systems go down is actually the manifestation of something that’s happening beyond aviation across all aspects of our lives. Hugely increased dependency on technology. And that’s great in the sense that it brings huge efficiencies. It speeds things up. It brings commercial advantages. It
00:16:51
helps to bring cost down. But the emphasis hasn’t been so much on securities as it has on efficiency and and commercial gain. And so what we then see is this regression towards processes because we’re having to implement manual human labored workarounds. We’re seeing a regression to how things once were. Um so we can see the benefits that technology are bringing. We can see sort of the vulnerabilities also at the same time. And I think actually what it does is shine a light on the need for
00:17:21
product safety, product security, the regulation around product security in a cyber context has been scanned. Um, and that’s where really there needs to be a focus and attention. I don’t really want to speculate on whether in fact it’s safe to fly or where I should fly or take another mode of transport because it’s not about that. It’s about something much more fundamental. It’s about how do we ensure that whatever technology we bring into the world, whatever we implement to substitute
00:17:48
human process is not just efficient and cost-effective, but that it’s also secure and resilient to anybody who wants to tamper or try and mess about with it. >> But we already have a lot of regulations around critical infrastructure or what is defined as critical infrastructure. Now, this is going to be expanded in the cyber security and resilience bill because they’re expanding the definition. But Collins Aerospace, who are a big defense company and provide critical services to the airlines, would
00:18:23
most definitely have been classified as critical infrastructure and yet they were inadequately prepared. So what does this say about our preparedness about the state of cyber defenses at this moment in time? >> Well, um I think the the rush to suggest that they were illprepared is an easy one. But I would caution against haste because you can’t guard against every eventuality. No matter how high you build the walls, no matter how good your defense is, there are always vulnerabilities. and vulnerabilities
00:18:57
more often than not, not actually in the technology, but in in people. Um, there isn’t enough information at the moment about what’s gone on with Collins either for us to be able to come to any definitive view. We can speculate, but I’m not sure that speculation is particularly helpful. What I’d suggest instead is that we look at what’s happened in other incidents so far this year. There’s a bit more information about what happened with Marks and Spencers, for example, at this
00:19:22
point than we’ve got with Collins. And you might say the same thing in the sense that well they’re a a major supplier food distribution distributor in the UK and in Europe. They also should have had had good defenses. What went wrong? Well, we know what went wrong. It wasn’t actually M&S. It was a business process outsourcing company that was targeted and in particular individuals working within that company. They were then impersonated and it became very easy to pick the lock to the
00:19:52
gates into the M&S fortress because of that. And this is really where the problem lies. It’s supply chain security more often than not. And it’s the people within those supply chains in particular. And whilst we may have very good law and regulation here in this jurisdiction, a lot of the BO outsourcing that goes on takes place in jurisdictions in countries where the costs are lower, where security is softer, where there isn’t the same rigor, where there isn’t the same um where there isn’t the same emphasis on
00:20:24
the importance of security and resilience that we currently have in the UK and in Europe and growing in the West. So, Ed, Ed Ed, can I just come in there, though? Because this just illustrates, doesn’t it, the incredible complexity of supply chains? This also illustrates the incredible complexity of the world we live in. We had President Trump at the United Nations talking about risks. I mean, it strikes me that if you’re in a world of such incredible complexity and you’re going to add AI on
00:20:54
top of that to make it even more complex, that really to have people who are actively going out there to mess the system up to actually try and wreak havoc in the system, you should actually have some significant sanctions upon them because of the ramifications of what it is that they’re doing. You know, you’re going to you could see people and and let’s face it too, quite often they don’t know what they’re doing when they’re launching one of these things with the not Peter attack, for example,
00:21:27
that was aimed at a part of the electricity infrastructure and nearly took out the mask shipping line. To be perfectly honest, we you’re in a situation where there’s this incredibly complex machine and you’ve got these lunatics with hammers breaking bits of it, not knowing what on earth they’re doing. We’ve got to deter this. But this is this you you’ve hit the nail of the nail on the head in terms of the problem there, Pete. So when you look at it comes back to my point about the
00:21:56
development of technology and you picked on AI and it’s it’s and it’s a good topic just to sort of um shuffle into for a moment because we’ve seen coming out of the US this very much sort of this messaging very strongly against regulating and stifling innovation and the development of technology. It’s all about the speed of development. It’s about the R&D race and the commercial advantage that that actually brings for the US. In Europe, by contrast, we’ve seen a much more
00:22:25
cautious approach, a desire to to focus on the the consequences of this technology, the potential unintended consequences, and then the security of it as a result. So, you have this sort of this competing tension. And we are still seeing technology come to market um which doesn’t have the levels of security which really it ought to. and we end up then with situations like we’ve we we’ve seen recently where security isn’t isn’t totally in um infallible. In fact, it is fallible. So
00:22:57
that’s that’s the one thing. It’s this sort of R&D sort of this this this race to be able to to win the battle in terms of who has sort of dominance over commercial markets in terms of technology. Then on the other side we have increasingly reducing barriers to entry for those who may be tempted to enter into criminal enterprise. Um, you know, it’s quite interesting if you think about operation Kronos, which was the the NCA operation or the the the sort of the the collaborative operation
00:23:28
that was undertaken against lockbit, but operation Kronos here in the UK and was the NCA component. They identified no less than 800 affiliates who were effectively engaged in as a service activity using Lockbit ransomware. Um, and that’s the problem that we really have. Once upon a time, engaging in cyber criminality was the preserve of a limited number of people in, let’s say, hostile geographies, geographies with low or non-existent regulation and with either law enforcement turning a blind eye or
00:24:09
actively the state being involved. We can speculate, we can talk about Russia, we can talk about all of that, but I don’t think that really is on point. What’s transitioned and where we are now is the fact that people here in this country are able to engage in similar criminal activity because they have access now to the tools and the resources almost as a turnkey opportunity. And yet at the same time the relative anonymity that they enjoy if they engage in that activity sort of the relative risk that they face
00:24:45
anonymity high and risk low which means that many more are inclined to have a go it could be a one-time payday that sets you up for the rest of your life. And we’ve seen with the arrests which are now making it into the news and most recently in the context of what’s happened with Collins over the weekend. was a guy here in the UK not far from Heathrow who’s been arrested in connection with the particular impairment at Heathro. We don’t know where in that cyber crime ecosystem he
00:25:12
sits. No details about that are currently available. But I think for a lot of people it’s quite startling when you hear initially the Leb Dems coming out and saying it’s Russia, it’s Putin when suddenly we have an arrest of a UK national just outside of Heithro. That’s the contrast that we’re seeing. And the reality is there are many more people now engaged in this because it’s just easy to do. you paint a very worrying picture and and I think this is something that we need to revisit because uh it’s a topic
00:25:42
and it’s a subject that’s going to roll and roll and and there will be further um uh revelations in terms of some of the recent attacks and there will be further attacks to come and therefore this isn’t going to go away and we hope you’ll come back again soon and discuss this with us further. Um, in the meantime, um, we just wanted, and you touched on AI, uh, we just wanted to to move on to what is a, I don’t know, it’s a light-hearted p story or or something to end on, but,
00:26:14
uh, Pete, I I know that we’ve heard from uh, our friend Mark Zuckerberg that um, there are further developments in terms of the meta AI glasses that we have um, that could potentially introduce some worrying concerns about the information it’s gathering. It’s our lives. It’s our experiences that we’re capturing here. But whose data is it? >> Well, obviously it’s Metas. I mean, this is this this this friendly bloke that you inviting to your home? He he’s he’s
00:26:51
the face of Facebook that’s now meted into Meta, isn’t he? I mean, look, I’m not being funny, but Mark Mark’s not exactly the He’s not exactly your mate, is he? I mean, this is the guy who at one stage was very very he was going to be great. He he was going to look after your kids. He was going to have all of these people checking through to make sure that there weren’t any predators out there because of his access into your home. And now he’s come up with these glasses. Yeah, I mean, you know,
00:27:25
the these they’re wonderful, aren’t they? Um I mean, if you go onto the internet, you’ll find there are so many experts who are talking about this as this terrible surveillance device because he knows what you’re looking at. And if you think about that, yeah, there are some people who look at things that they shouldn’t really be looking at. All of that information is there. This is this is this is a man who he will be able to know who you let you know. Think about it. >> Well, it’s not just your life it’s
00:27:56
capturing. It’s everyone around you. It’s your friends and family who you’re interacting with when you’re wearing these glasses. I I think there are some major concerns here. And when you overlay some of the AI and the way it’s capturing information, storing, and then using it in ways that you possibly couldn’t predict, I I think there’s some major concerns here. >> Well, just just think about this, Bill. I I you know you’re a major privacy expert. You work with Max Shrems on
00:28:26
actually some some work against Facebook. Um which which resulted in a significant I mean they know your name uh um and um I was interviewing Mark Weinstein yesterday who’s a top privacy expert who’s just brought out a book um and he was making the point that Facebook and he says this is well documented in his book but lots of other people have pointed it out. Facebook actually knows who the people who aren’t on Facebook are. It has these shadow accounts for people because it can work
00:28:59
out the holes that there are. Now, if you’ve you’ve got these glasses on, they’re augmenting the gaps in their knowledge about other people. I I genuinely think that funny as it is and I mean how uh just think about it, how comfortable would you be if you were in a pub and somebody walked in wearing those glasses? I mean this is this is like you couldn’t even come up with this in a 1960s sort of uh thing like the prisoner or the saint. I mean it’s just weird. But I >> my concern here is not just what it’s
00:29:37
capturing. It’s the protections and it’s whether you trust Facebook and I’m one who doesn’t um and whether their protections are any red address. And whilst I uh helped support Max and and others in the European stage, I actually was part of a team that tried to bring a case here in the UK against Facebook. And unfortunately that the legal frameworks around representative action and and other things here in the UK are inadequate. It’s it’s actually impossible or practically impossible to
00:30:08
bring a claim or or to bring a case against these tech giants or anyone who um uh uh uh uh leaks or abuses your data. And I think we need more protections and we need people reacting to this sort of thing with um far greater concern rather than casually throwing on a pair of glasses without thinking of the implications. Anyway, That’s that’s the point, isn’t it? They don’t think about the implications. I mean, you know, we’ve we’ve got uh to Tim Berners Lee, he’s got a project at
00:30:42
the moment where he wants to get you to get your data back. He doesn’t want it um centrally. He’s trying to push this this idea. There’s our friend uh Professor Irene. She’s been pushing this as a concept as well. I think that that’s that’s the way you get it back. You actually say the only way that you get some understanding of what is being done with your data is if you are running it yourself. If you own it yourself, if you have control over it, if you say my data can be used for this
00:31:14
or that, then that’s where that’s that’s when you start to understand it because you will also get a bit of revenue from there. Whereas and so you’ll get an interest in actually sort of saying what it is that can be done with your data. And you know there there’s several other factors in in in all of this too which is really you do own your data. It is about you. Um and we need to begin to understand a data and and and what what it actually represents in this world. Until we start
00:31:49
to do that, Bill, you know, we we’ve got a bit of a problem. The blind way that people tick out the terms and conditions is just it’s it’s ridiculous and foolish. We interviewed uh the head of AI and ethics at Cambridge University and he was saying, “Come on, think about it. Why are they putting all of this money into AI? They’re putting all of this money into AI because they want to get right into your head because they want to understand your your demands, what it is that you want.” Yeah, that’s
00:32:22
and so this is yet a further extension of that process. And as the uh professor at Cambridge was saying, the only reason they want to do that is because they want to make money out of it. It’s why people want to actually put that money into this AI research. I mean, why don’t we go back to our guest? He uh he’s he >> well I I I I think I think the message here both in terms of our main story around cyber security and around this meta story is considering the implications the implications of wearing
00:32:55
these glasses and the implications of whether you have adequate cyber security whether you have cyber insurance. Um, Edward, I don’t know what your thoughts are on the implications of either or whether you’d ever wear a a pair of meta glasses. >> There’s a few things that were going through my head there as you were talking. And the the first and most obvious certainly in the context of AI is that if you have a tech product that’s given to you for free, typically you are the product, not what’s actually
00:33:28
been given to you. So um and that was true with the with the first edition of Facebook. I mean really this is about what are the what what are the use cases? What are the consequences of use that we haven’t yet identified? Everybody thought Facebook when it first came out was a great way of being able to reconnect with people you’d lost contact with. It was the the better version of friends reunited. Nobody was talking about data manipulation or mass processing, farming of data to be able
00:33:55
to control behaviors. But now we know actually what goes on. We’ve got the same scenario here with these glasses. And I think all I would say about it because again I don’t want to speculate but um just sort of trying to keep it relatively light-hearted. If your glasses are smarter than your trust model then generally speaking I think you’re in trouble and that’s what we’re facing here. >> Well wise words indeed. And Edward thank you so much for joining us. Thanks for all of your contribution. We’d love to
00:34:24
welcome you back in future because these stories aren’t going to go away. They’re going to run and run. Uh Pete, thank you. Edward, thank you. Everyone, please uh have a look at some of our other stories here because there’s a quite a lot that we’re being covered uh in many of our different interviews and we welcome you all back soon. >> And also remember, we’ll be able to add to this cyber insurance debate quite significantly. >> Yep. We’ve got reports coming up, so
00:34:54
keep your eyes open for more.




