Expertise

1. Post-Quantum Transition

Quantum computing capable of undermining current asymmetric cryptography is realistically expected within a five-to-eight year window — not necessarily full “Q-Day” capability, but enough to matter for underwriting decisions today. This work, developed over three years and more with InfosecGlobal (now part of KeyFactor), addresses that transition from the insurer's side: how to assess an insured's cryptographic preparedness, how that translates into renewal and new-business decisions, and how exposure differs by sector — with financial services, particularly banking, expected to lead the transition and set the pace others will be measured against.

2. Agentic AI & Silent AI

Before Silent Cyber became a recognised market priority, the London Market carried substantial cyber exposure in policies never written to contemplate it — and paid for that gap when losses arrived as surprises. Silent AI is the same structural problem, one step on: policy wordings written before agentic AI systems could act autonomously across system boundaries contain no explicit treatment of AI-caused loss. This work, developed as an initiative within the London Market, sets out why that exposure is urgent, what's driving it, and what a considered market response looks like.

3. Cyber-Physical Damage (CYPD)

Cyber events increasingly cause real physical damage and extended operational shutdown — outcomes traditional cyber and property insurance were never designed to address together. This work centres on a single underwriting insight: that the credibility of a catastrophic physical-damage scenario depends less on whether automation is present than on whether an insured's safety systems are genuinely independent of the networks a cyber event could compromise. That distinction — independence of Safety Instrumented Systems — is what allows severity to be assessed and capital to be deployed with confidence, rather than treating cyber-physical risk as unbounded.

4. Robotics & Physical AI Governance

As robots move into more varied, dynamic, human-centred environments, capability claims that don't carry consistent meaning across vendors become a problem for everyone trying to assess risk — customers, integrators, regulators, and insurers alike. Peter contributed to and is quoted in the launch of Arm's Robotics Capability Framework — issued as a manifesto for a common reference describing what an intelligent robotic system can actually do.

A related, newer line of thinking — not yet published — extends this further: the case for a genuinely common lexicon and a shared accountability model for robotics, comparable to what the OSI seven-layer model did for networking, or what shared responsibility models did for cloud adoption. Where those models let unrelated parties agree on who is answerable for what, a similar model for robotics would let insurers, integrators, and operators agree on where supervision, assurance, and liability actually sit as systems become more autonomous.

5. Risk Capital Provisioning in Data Centre Build Lifecycle

Digital infrastructure now sits at the centre of the capital markets' largest current build-out, and a data centre's risk profile changes fundamentally as it moves from construction through to long-term operation. Construction-phase financing is typically non-recourse project debt layered with sponsor equity, priced against completion and technical risk. Once a facility is energised, tested, and generating contracted cash flow, that debt is refinanced — into infrastructure term loans, private placements, or securitised structures — and ownership frequently transitions toward infrastructure funds and other long-duration institutional capital. Each transition brings a different risk appetite and a different understanding of the digital risk embedded in the asset: cyber exposure, AI-workload liability, and cyber-physical damage to power and cooling systems all need re-underwriting as the capital behind the asset changes hands, not merely as the technology inside it does.
Search