Thank you for Subscribing to Insurance Business Review Weekly Brief

Innovation, Cybersecurity and the Future of Insurance


John Del Grande is Senior Vice President of Business Innovation at Ecclesiastical Insurance. He leads strategic innovation initiatives that advance digital transformation, improve customer experiences and drive operational excellence, helping the organization deliver forward-looking insurance solutions while adapting to evolving market needs and emerging technologies.
After more than two decades working across technology, operations, cybersecurity, and business transformation, I have seen the financial services & insurance industry evolve from paper-based processes and isolated systems to today's world of digital ecosystems, cloud platforms, artificial intelligence, and real-time customer expectations.
What has not changed is the importance of trust.
Whether we are underwriting a policy, handling a claim, or implementing emerging technology, our customers trust us with their information and expect us to be there when they need us most. That responsibility has shaped my perspective on innovation, cybersecurity, and resilience throughout my career.
The Balancing Act: Innovation without Unnecessary Risk
One of the biggest misconceptions I encounter is that innovation and security compete with one another. In reality, they are most effective when they work together.
Early in my career, technology projects often treated security as a final review step. Teams would build solutions first and then ask security whether they could proceed. More often than not, that resulted in rework, delays, and frustration for everyone involved.
Over time, I learned that the most successful initiatives bring risk, security, compliance, and business teams together from the beginning. The conversation changes from "Can we do this?" to "How can we do this safely?"
That simple shift in mindset improves outcomes dramatically. Security becomes an enabler of innovation rather than an obstacle to it, and organizations can move forward with greater confidence.
The Cybersecurity Challenges That Matter Most
Cybersecurity challenges have evolved significantly over the years. When I started in technology, threats were often limited in scale and sophistication. Today, organizations face a highly organized and well-funded threat landscape.
One of the greatest challenges is the sheer interconnectedness of our industry. Insurance companies rely on cloud providers, brokers, vendors, business partners, and data-sharing platforms. Every connection creates opportunity, but it also expands the attack surface.
Artificial intelligence represents another significant opportunity and challenge. Like many leaders, I am excited about AI's potential to improve productivity, customer experience, and decision-making. At the same time, I have watched threat actors quickly embrace the same technologies to create increasingly sophisticated phishing and social engineering attacks.
Most importantly, I believe resilience has become as critical as prevention. Despite our best efforts, incidents will occur. The organizations that perform best are not necessarily those that avoid every disruption, but those that can respond quickly, recover effectively, and continue serving customers when it matters most.
Building a Culture That Encourages Innovation and Security
In my experience, culture is often the deciding factor between success and failure.
Security becomes an enabler of innovation rather than an obstacle.
I have worked with highly capable teams where the technology was excellent but collaboration was lacking. I have also seen teams achieve extraordinary results because they shared a common purpose and were willing to challenge traditional thinking.
Creating that culture starts with trust and accountability. People need the freedom to test new ideas, but they also need to understand the potential risks associated with those decisions.
One lesson I have learned as a leader is that cybersecurity cannot belong solely to the cybersecurity team. Every employee influences the organization's security posture through the decisions they make each day. When people understand the "why" behind controls and processes, they become partners in protecting the organization instead of simply complying with requirements.
Cyber-security’s Expanding Role in Business Strategy
Perhaps the biggest change I have witnessed during my career is the evolution of cybersecurity from a technical discipline into a business discipline.
Years ago, cybersecurity discussions were often confined to server rooms and technology meetings. Today, they take place in boardrooms and executive strategy sessions.
That evolution reflects an important reality: cyber-risk is business risk. Decisions involving artificial intelligence, digital transformation, third-party partnerships, operational resilience, and customer trust all have cybersecurity implications.
The cybersecurity leaders of tomorrow must understand not only technology but also business strategy, risk management, and organizational objectives. Equally, business leaders must become more comfortable discussing cyber-risk as part of everyday decision-making.
Advice for the Next Generation
For professionals considering a career at the intersection of innovation and cybersecurity, my advice is simple: remain curious.
The most successful people I have worked with were not necessarily the most technical. They were the ones who never stopped learning. They asked questions, sought new perspectives, and took the time to understand both the technology and the business problems they were trying to solve.
Develop strong technical foundations, but also learn how businesses operate, how decisions are made, and how value is delivered to customers. The ability to translate between technical and business audiences will become increasingly valuable.
Throughout my career, one principle has remained constant: trust is earned, not assumed. Innovation creates opportunity, cybersecurity protects that opportunity, and resilience ensures it can withstand disruption.
The future of insurance will belong to organizations and leaders that can successfully bring all three together.