There is a version of digital transformation that is familiar to every technology executive in insurance: the grinding, multi-year effort to drag a business built on paper, legacy platforms, and manual process into something resembling the modern age. Steve Penney (pictured) knows that version well. He spent years in it, at large established carriers and in consulting, before joining a small Canadian startup where the challenge was, in his words, something else entirely.
“There were no legacy systems, no paper process,” said Penney, chief technology officer at BOXX Insurance, acquired by Zurich in 2025. “Everything was starting from digital.”
It sounds like an advantage. In many ways, it was. But, as Penney explained, building from scratch inside a capital-constrained startup introduces its own category of pressure, one that demands a different kind of discipline from the outset.
Penney’s path into the insurance industry was, by his own account, not a matter of grand design. Shortly after completing his master’s degree, a chance referral from a friend led him to a role in insurance, an industry he would spend the better part of the next two decades navigating in one form or another.
After seven years, he left for the telco sector and management consulting, experiences that would sharpen his perspective on large-scale technology transformation and the structural challenges facing established organizations. The decision to return to insurance was, it seems, as much about recognizing where the most interesting problems were as anything else.
When Penney arrived at BOXX, the company was finding its footing in the Canadian personal and small business cyber insurance market. The team was small, he recalls being around the 10th person through the door and the technology team numbered just two people. The temptation in such circumstances is to move fast and defer the harder structural questions. Penney made the opposite call.
He pushed, from early on, for investment in a microservices and API architecture and for the careful definition of a unified data model across the business.
Neither was an easy argument to make at the time as the company was under pressure to deliver growth. “It’s a hard argument to make when you’re a small company,” he acknowledged. “But a few years later, it seemed like a good idea.”
The data model proved prescient. As artificial intelligence has moved to the top of every insurer’s strategic agenda, the condition of underlying data has emerged as the defining variable between those who can act and those who cannot. Penney’s team spent time standardizing terminology, harmonizing calculation methodologies across jurisdictions, and creating a structure that would prove scalable as BOXX moved into the United States, Europe, India, and Australia.
“You read LinkedIn or any AI news, they all stress that it starts with the data,” he observed.
The commercial logic underpinning BOXX’s technology investment was straightforward, if not simple to execute. Cyber insurance, Penney argues, had long been in place for large corporate buyers. Small businesses, sole traders, families, and individuals, the overwhelming majority of potential policyholders, had been effectively designed out of the market.
The company’s proposition was to invert that assumption. Technology was not merely a delivery mechanism but how a product could be made genuinely accessible to underserved segments. In Canada, the first focus fell on speed of issuance: how quickly a broker or customer could move from enquiry to a bindable policy. Getting that process under a minute was, at the time, a meaningful achievement.
In the United States and other markets, the ambition has since been radically extended. BOXX’s underwriting logic is now available via API, allowing distribution partners like mShift and Herald to embed quote and bind functionality directly into their own workflows. The result, Penney said, is policy issuance in under one second, a figure that would have been difficult to imagine even a decade ago in most lines of insurance.
BOXX’s international expansion brought a different class of challenge. Entering a new market is never solely a technology exercise; it is a compliance and regulatory one.
The cloud, he said, has made the infrastructure component of geographical expansion straightforward. The harder work, understanding local regulatory requirements, supporting data residency obligations, and demonstrating security governance to the standard demanded by prospective partners, is something no amount of cloud elasticity resolves automatically.
“Setting up infrastructure in other regions is easy,” he said. “It’s ensuring that you’re doing business according to the local requirements, that’s the harder part.”
On security posture, Penney is characteristically direct. As a cyber insurer, BOXX’s credibility in the market is inseparable from the robustness of its own controls. Earning the right to work with certain distribution and capacity partners needed demonstrable proof of strong governance.
Artificial intelligence sits at the heart of BOXX’s current operations, though Penney is notably unsentimental about the parts of the story that have become cliché.
AI-assisted underwriting and claims processing, he suggests, is no longer a differentiator. “I think everyone has accepted that at this point,” he said. The more substantive opportunity beyond back-office automation, in his view, lies in the application of continuous, real-time risk signals across an entire book of business, a model that cyber insurance, by necessity, has pioneered ahead of other lines.
In property, motor, and life, the industry has long talked about dynamic underwriting informed by live data. In cyber, it is already happening. Every serious participant in the sector is monitoring its policyholders in real time, scanning for vulnerabilities, open ports, and indicators of exposure. That’s why BOXX’s technology product, Cyberboxx® Assist, bundled with every policy, provides a comprehensive suite of cybersecurity tools and services designed to help individuals and businesses predict, prevent, and respond to cyber threats through risk assessments, compliance tools, and expert support. This service, paired with a virtual Chief Information Security Officer (vCISO) program, through which it proactively determines potential risks before they crystallize into claims.
The application development implications of AI are, Penney believes, more immediately transformative than much of the commentary acknowledges. His engineering team has materially accelerated its output through AI tooling, though he is careful to note that the additional governance and security compliance burden that comes with those tools is real and cannot be wished away.
The other side of the coin is less comfortable. Hackers are deploying the same technology to infiltrate businesses with a sophistication and scale that was not possible previously. Remote working has extended the human attack surface considerably. “Every company is trying to figure out how do you embrace the speed and promise of AI without facing the downside risk,” Penney said.
It is a tension his own industry is uniquely placed both to suffer and to help resolve.
Penney reflects with some candor on what he might do differently, were he to begin again. The shift from a small team, where informal alignment substitutes for structured communication, to a growing organization with distinct functional disciplines is, he suggests, one of the less-discussed difficulties of scaling a technology business.
“Communicating the priorities, communicating the why, the vision and the journey, is something you never had to do in a small company for a long time, until it starts to grow,” he said. The creation of dedicated role families in security, infrastructure, DevOps, and product management has been necessary and welcome; but ensuring those functions maintain the company’s innovative and agile culture whilst remaining aligned with commercial outcomes requires active management that earlier informality did not demand.
His other observation concerns the cadence of change. Introducing innovative technology at a pace the organization can genuinely absorb is, he argues, a more sophisticated judgement than it appears. Moving quickly to implement a lighter solution may delay a more valuable intervention by only weeks. Getting the balance right, and ensuring that every technology initiative has a named business owner accountable for its outcome is something he has become increasingly focused on.
“When you’re first starting off you can have many small technology tests,” he said. “But you have to make sure there is somebody championing that business outcome.”
Penney is measured but clear-eyed about the trajectory of the industry. The API ecosystem for distribution and policy issuance, he believes, is still in its early stages in Canada relative to the United States and the United Kingdom. Adoption will accelerate. Continuous underwriting, informed by real-time risk data, will extend beyond cyber into other personal and commercial lines. And cyber risk itself, as an operational reality for every business, regardless of sector, will remain a board-level concern for the foreseeable future.
“Cyber is something that will continue to be a board level imperative for all companies,” he said, “whether they’re customers of ours or any company in the public landscape.”
For an insurer that was built, from its earliest days, around precisely that conviction, the road ahead looks familiar.
Away from the demands of building and scaling a global technology business, Penney is, by his own description, firmly outdoors. He lives in Ontario, near the Blue Mountains, where he skis regularly with his family and son. Skiing, hiking, and cycling form the backbone of his leisure time, a trio that reflects a broader preference for open air over screens once the working day is done.
For a man who has spent a quarter of a century in technology, and who jokes, with self-awareness, that he once tried to leave the insurance industry and simply couldn’t, the balance appears hard-won and deliberately maintained.