What it takes to make an SME insurance-ready for cyber
To view full transcript, please click here

00:00:00 We've completely turned the industry on its head. It's ground-breaking. There is nothing that I've seen at the moment on the market. >> Hello and welcome to Insurance Business TV. I'm Danny Wood, [music] news editor with Insurance Business. Cyber insurance platform Torth Sec is recognized in our five-star insurance innovators 2026 report as one of the most innovative companies in the insurance industry across Australia and New Zealand. Torth Sec offers SMEs cyber certification and insurance in one

00:00:29 digital platform. Warren Zeitzman is CEO and based in North Sydney. Welcome, Warren. >> Thanks, Danny. Great to be on the show. Thank you. >> Yeah, nice to have you. And And firstly, congratulations on being named a five-star insurance innovator. What does this recognition mean for your team? >> Danny, I think this is a fantastic recognition for the team. It's a It's a testament to what the team have managed to build over the last couple of years. It's It's built within an environment

00:00:56 that's been completely changing. You know, when this journey started, AI wasn't as prevalent as it is now. And today, everything is built using AI. So, I think for the team to have been able to deliver a platform that can provide both insurance and assurance in a single format, I think is unique. It's completely unique in that the way it's delivered has not been under traditional norms. It's been delivered in such a way that makes it very easy for SMEs to accept, to be quoted, and buy insurance

00:01:24 either online or through a broker. But, it It's revolutionizing the way small companies can put aside all the noise that they often encounter when trying to buy cyber insurance and buy cyber quite easily. >> Hm, take me back to the the decision to combine cybersecurity awareness, risk visit visibility, and cyber insurance in in the one offering. Um, what were you seeing in the market that told you that these pieces needed to sit together? >> Yeah, Danny, that's a That's a very

00:01:52 pertinent question. Um, I think historically and and bearing in mind, look, I've only been with the company for over a month, but I think the original founders, especially the engineers behind this, identified a gap in the market where very often the market was looking for something that was simplistic, but also a way that they could try and not only get the protection through insurance, but but also get the the prevention through the assurance side. And what I mean by that is very often you can get cyber

00:02:18 protection, you can get some cyber insurance, but that that's a policy that you pick up at a certain point in time. And then you've got the rest of the year to run before that policy renews. And every day you carry out business, you suddenly come under threat, you come under attack, and so forth. So, what we recognize is is the protection was one arm, but but the prevention was the other arm that was missing. And what we saw in the marketplace is you could get them in different places, in different

00:02:42 bundles, but very often they weren't connected, they were disjointed. It almost made it like a bolt-on. What we recognize in the market is that the SME market, especially here in Australia, was looking for something where they could actively prevent during any given calendar year or financial year or fiscal year the threats that hit them, but at the same time make sure they've got the backup protection from the insurance side. So, it made it a lot easier for SMEs to understand and to manage the protection and prevention if

00:03:10 it was being provided under a single offering. >> What does cyber insurance ready actually mean for a business that comes to you not ready? And can you walk me through what changes for a client between that first conversation and the point where they can actually go to market? >> Yeah, certainly. So, I I think, you know, when a customer comes to us and or comes to Tesserac, or comes through a broker, very often there's some basic things they need to have in place. They need to have MFA in place, they need to have

00:03:35 email scanning in place, they need to have they need to have patch management in place. So, there are five key controls that generally decide whether any underwriter will insure a company or not, all right? And if you go through our platform, you go through competitors' platform, there are generally these four to five questions that an underwriter will want any broker or any front end online company to ensure that the customer has tagged these as a yes. And largely that gets you insurance ready. So I think you

00:04:03 know, what we're Talsik is differentiating itself and this is really big thing in the market at the moment. We've created a platform that allows you to receive a quote and bind that insurance with three simple inputs. All right. We're talking inputting your web address, your revenue and an email address. From that we can actually generate an entire quote, all right, which is bindable provided you confirm the questions that we've pre-populated for you. So to bring it back to your question

00:04:30 around what is insurance ready versus not insurance ready mean? When a broker now has a conversation with a customer, very often at the moment they need to go through pages and pages of questions and queries. Talsik has narrowed this down to three questions. From those questions, literally we can populate a form and the individual or the company behind it can look at this and confirm whether those the the outputs of of the software is actually correct. What that means though is if they're not

00:04:56 actually insurance ready, um Talsik, the the assurance part, we the software behind this business is called Cyber Pilot, right? That's the actual software package behind this. That's the the second part of the equation. So the insurance is one part, the Cyber Pilot, the assurance software is the other part. What a person will get is they'll actually get a foundation level of the software which will indicate what they need to change in order to become insurance ready. So no longer the days where your

00:05:25 insurance would just be declined and a broker would say, "Look, I'll have to refer it back to the underwriter to understand why it's being declined." Effectively now a broker can pre-populate these this information with the three inputs. It will take it as given that these five questions have been tagged and off the back of that a broker will sit with somebody, have a conversation and say, "Can I just confirm you've You've MFA in place, you've got patch work management place,

00:05:48 etc. etc. email scanning. Assuming the customer says yes, that gets them ready. But where this becomes very powerful is the customer actually for free, we we add this in, will get the use of the software for at least a year where they get a dashboard that runs the scan monthly for them against those five core controls. And that's that's really the the fundamental rudimentary of what you need to be in order to be cyber ready for insurance. And ultimately, it's the foundation level of protection that

00:06:16 would then be able to maintain during the course of a year. >> Yeah, definitely. And I mean, what do you see is the hardest part about bringing this platform to market? And I mean, was there a point where you thought it might not work? >> I've joined this journey just over a month, and I think, you know, if I look back to the engineers and the founders and that, I think they went through ups and downs. When I when I was interviewing for this role and and coming into the role, these were some of

00:06:39 the questions I asked. I said, you know, what are the hindrances you face? I think some of the biggest hindrances were getting the industry's head around the fact that assurance and insurance are two separate things, but they have to go together, okay? I think what was happening is SMEs were looking at this and thinking, okay, if I just take my insurance, I'm fine. But then that doesn't stop or prevent the turmoil that happens during the year. And then they have to claim on the insurance and so forth. So I think I

00:07:05 think educating the market around the concept of buying a whole offering which includes the insurance and assurance was a key part. >> [sighs] >> I think the second thing that that really was challenging was traditionally in this world, you would find a lot of the cyber protection and the cyber resilience scans that would happen would be done by, you know, some of the the big consultancies, some of the big sort of the MSPs. And ultimately, this would involve quite laborious, quite expensive consulting

00:07:33 fees, consulting projects, all right? Because effectively, what would happen is they would apply the frameworks of the essential eight or NIST or ISO 27001 to these companies. What we've managed to do is we've managed to build a product that can dynamically pull from any one of those risk platforms, cyber risk platforms. So, the Australian essential eight, the European ISO 27,001, the US NIST. It can pull those controls and apply the framework that you've chosen to apply, all right? In a single piece of software

00:08:05 without having to have the laborious consultancy fees. So, I think the trick was building that building something that could take those controls depending on which particular framework you chose to assess yourself by and building it so that we could apply that into an environment for SMEs. Taking away the challenge and expense often associated with consultancies and long consulting, I guess, engagements to try and find out are you cyber ready? Are you resilient? What is galvanized? What's not? Etc. etc. So, we've

00:08:35 completely turned the industry on its head with Tactic in that we've now got a product that can do this initial scan using just three inputs. Most of our competitors or competitors that are classified as insurtechs will still do this online, but they'll be a five to 10, sometimes 15-minute process of going through questions and pages, etc. etc. Tactic has narrowed this down to three questions. Once you've got the questions, we've got the input and you're able to be onboarded onto the

00:09:03 Cyber Pilot product. You can then utilize this product to run all your vulnerability analysis as well as your third-party supply chain analysis dynamically under a single dashboard. It's it's groundbreaking. There is nothing that I've seen at the moment on the market, and look, I stand up to be corrected, but from what I've seen in this time that has that level of management against the global frameworks for cyber protection. >> Mm. Looking at you mentioned SMEs in the market, what do you see as the one thing

 

00:09:33 that Australian businesses are still getting wrong about cyber risk? and and what do you hope that Tott Sec will be doing over the next 12 months to I guess solve that problem? >> Look, I think education is a big challenge at the moment. Everybody knows about AI, everybody's heard cyber. So, every board meeting I attend or I've sat on in the past in my past life both of season over here, cyber comes on the table and AI comes on the table in the last couple of months. I think Australian businesses are seeing

 

00:10:01 a bit of a cloud of, you know, sort of mystery and and over this whole thing of cyber. Some are seeing it as necessary at all and some are seeing it as hold on, it's too complex. You know, every time I get on a call with a broker, it's normally an add-on. So, a broker will talk about PI cover, key man insurance, property insurance, whatever it might be. They, by the way, do have cyber. So, it's often a a bolt-on. So, I think the biggest challenge at the moment is there needs to be an education process within

 

00:10:25 the insurance industry and within the actual SME market. This can't be a bolt-on, number one. And number two, I think very often there's this cloud of complex and cost associated with anything to do with cyber. And what were My plan to do is to enable the brokers to understand just how easy it is to quote and bind insurance using our platform and to educate customers on around how easy it is to actually receive insurance and with ongoing prevention through the use of cyber pilot, which is the

 

00:10:57 software product that Tott Secs is built on. So, I think at the end of the day, you know, my focus for the next 12 months is to educate the broker community around the use of the platform and to educate the SMEs that this is not an expensive, laborious, tedious process. That fundamentally this is something that they need, it's something that's real and it's something that they can work with in order to reduce the risk of cyber attacks. >> Warren, congratulations again and thanks

 

00:11:23 for talking to us at Insurance Business TV. >> That's been a pleasure. Thank you for hosting us. I really appreciate that. >> And Warren Eatsman is CEO of Tott Sec, one of the firms in our five-star insurance innovators report, one of the top firms. And that report covers insurance innovators across Australia and New Zealand. Thanks for watching Insurance Business TV. Bye for now. >> [music]

 

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB NZ.