Estimated reading time: 8 minutes
Since March, this publication has covered at least six proposals to wire continuous monitoring into cyber underwriting. Sophos and Spektrum Labs. Jessica Newman on the podcast. Marsh and Resilience. CyberCube. Silent Push. Black Kite. All vendors pitching to carriers.
Mosaic Insurance launched HALO on 17 September. It is a carrier that built the thing itself, runs it in-house, and keeps it running after the policy binds.
What Mosaic Actually Launched
HALO is a digital underwriting system for small and midsize enterprise specialty business, built as modular AI infrastructure rather than a quoting portal for one product. It combines broker trading activity, underwriting decisions, and portfolio outcomes in a single operating environment.
The first product is HALO Cyber, a combined cyber and technology errors and omissions offering available through Mosaic’s North America wholesale broker partners. Eligible risks move through automated quote, bind, and issuance in minutes. Exceptions and complex risks route to underwriters.
Brokers submit through email, API integration or a portal, whichever fits their existing workflow. The system structures, enriches, and organizes the submission data on arrival, which Mosaic says cuts the follow-up questions and repeat touchpoints that slow a file down.
Pricing, appetite, coverage rules and broker configurations can be tested and recalibrated within 24 to 48 hours. Recurring broker and client requests can be assessed and, if agreed, built into the product without generating further manual referrals.
“This represents a quantum transformation for Mosaic in capability, market reach, and opportunity, all enabled by AI,” said Mitch Blaser, co-founder and co-chief executive.
Liam Jones, chief executive of Mosaic’s agency business, put the ambition in terms the market will recognize. “True digital trading, genuine augmentation of information, and real-time active portfolio management is the progress we’ve all been seeking for many years,” he said.
That last phrase is the one to hold onto. Real-time active portfolio management is not a distribution claim. It is an accumulation claim.
The underwriting sits behind Lloyd’s Syndicate 1609, with in-house claims authority and 24-hour incident response attached. Mosaic passed five years in business in February and now writes eight specialty lines, including cyber, environmental liability, political risk, political violence, financial institutions, professional liability, specialty casualty and transactional liability.
Take The Cyber Insurance News Survey
Respondents get the results first.
The Line That Matters Is About Accumulation
George Cole, who leads Mosaic’s SME cyber insurance business, dismisses the obvious framing outright.
“Quote, bind, and issue is not the innovation,” he said. “The difference is the connection between workflow and portfolio. We can define the portfolio we want to build, compare it with what’s entering the funnel, and adjust the rules shaping the next submission.”
His second point is the consequential one.
“HALO gives us a clear view of the portfolio as it develops and helps identify where exposure may be accumulating across industries, technologies, service providers and other exposure units,” Cole said.
“The visibility HALO gives us is particularly important in cyber, where a single event or vulnerability can affect multiple insureds at the same time,” he said. “It will also be increasingly relevant as we expand HALO into our other specialty products with their own aggregation and concentration risks.”
That is a carrier saying it has built infrastructure to watch accumulation form while it is forming.
Three Reports In Six Weeks Said This Was The Problem
The timing is worth laying out, because the market has spent August and September naming exactly this gap.
Allianz Commercial reported in August that high insured values and geographic clustering were increasing accumulation risk across locations, perils and lines of business, and that a single event at a hyperscale campus could trigger claims across property, construction, business interruption, liability, cyber and financial lines.
CyberCube published on 2 September, arguing that concentration across compute infrastructure, cloud platforms and foundation model providers turns shared dependencies into shared exposure across insureds. It mapped six AI event families against eleven policy types and left the entire coverage grid blank for carriers to fill in themselves.
RAND published on 16 September, one day before Mosaic. It named common model dependency as one of five AI accumulation mechanisms, found that carriers cannot yet reliably estimate AI loss frequency or severity, and recommended that insurers and reinsurers run dependency-aware scenario analysis focused on shared model dependency, infrastructure failure and regulatory shock.
Three serious pieces of work in six weeks, all pointing at accumulation visibility as the unsolved problem. Mosaic has announced a system built to address it. Whether it does is a separate question, but the sequencing is not coincidence.
Inside-Out Or Outside-In
One technical detail determines how much of the above HALO can actually deliver, and the release does not answer it.
HALO extends past the point of bind. Brokers and insureds can access cyber risk intelligence and telemetry monitoring before binding and throughout the policy period, to identify and respond to changes in exposure while the policy is live.
The question is what that telemetry sees.
Mosaic has used real-time security data in primary cyber underwriting since 2023, through a partnership with Safe Security that was described at launch as offering inside-out evaluation. That phrasing matters. CyberCube’s central criticism of external scanning is that an outside-in telemetry scan can establish that a company uses a given tool but cannot establish what it uses it for. The same limit applies to the Marsh and Resilience program launched across Asia this month, which requires no software installation and no internal system access.
If HALO’s post-bind monitoring inherits Safe Security’s inside-out position, Mosaic has something materially different from the external scanning propositions. If it is outside-in, it carries the same constraint every other continuous monitoring offer does.
Mosaic has not said which.
What Nobody Has Published Yet
The recalibration claim is the sort of thing that should be easy to evidence and has not been.
Testing and recalibrating pricing, appetite and coverage rules within 24 to 48 hours is a capability. Whether faster recalibration produces better loss experience is an outcome, and no carrier has published data connecting the two.
That gap is now familiar. Sophos and Spektrum converted control status into verifiable tokens without publishing claims impact. Silent Push cited detection lead times averaging 104 days without loss data behind them. Black Kite reported that companies scoring above 0.8 on its susceptibility index are far likelier to be attacked, which is a correlation with attack probability rather than a demonstrated reduction in claims cost.
Mosaic is better positioned than any of them to close it. A carrier holds its own loss data. If the feedback loop works, Mosaic will know before anyone else does, and it will be able to prove it.
The questions worth putting to them now are narrow. Has the 24-to-48-hour loop actually changed a rate, and what happened to the business written after it changed? Does post-bind telemetry affect a live policy, through mid-term action, renewal pricing, or notification only? That last one is the difference between an underwriting control and a value-added service.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
The Other Half Of Mosaic’s AI Position
There is a second thread here that the HALO release does not mention.
In February, Mosaic partnered with Munich Re on aiSure, providing up to $15m in coverage for defined AI performance failures that traditional cyber and technology errors and omissions policies may not address.
So Mosaic is using AI to underwrite cyber while separately underwriting the risk that AI fails. Both positions, in the same year, from the same carrier.
RAND’s report places Munich Re among the small group of carriers offering affirmative AI coverage, against a market where most remain silent on whether AI losses are covered at all. Mosaic sits in that group by association, and has now built AI infrastructure into its own underwriting operation.
Whether those two positions reinforce each other or eventually collide is the interesting question. A carrier that underwrites AI failure has a commercial interest in AI performing well. A carrier that underwrites through AI has an operational dependency on it.
FAQ – Digital Cyber Insurance Underwriting
What is Mosaic HALO?
A digital underwriting system for small and midsize enterprise specialty business, launched 17 September 2026. It combines broker trading activity, underwriting decisions and portfolio outcomes in one environment. The first product is a combined cyber and technology errors and omissions offering through North America wholesale brokers.
How is HALO different from other digital cyber underwriting platforms?
Mosaic’s head of SME cyber, George Cole, says quote, bind and issue is not the innovation. The difference is the connection between workflow and portfolio, allowing Mosaic to compare what enters the submission funnel against the portfolio it wants and adjust the rules accordingly.
What does HALO do after a policy binds?
Brokers and insureds can access cyber risk intelligence and telemetry monitoring throughout the policy period, to identify changes in exposure while cover is live. Mosaic has not specified whether that monitoring is inside-out or external scanning.
Why does accumulation visibility matter for cyber underwriting?
Because a single event or vulnerability can affect many insureds simultaneously. Allianz, CyberCube and RAND all published work in August and September identifying accumulation visibility as an unsolved problem for cyber and AI exposure.
Does Mosaic also insure AI failure?
Yes. In February it partnered with Munich Re on aiSure, providing up to 15 million dollars in coverage for defined AI performance failures that traditional cyber and technology errors and omissions policies may not address.
Related Cyber Insurance Posts
- RAND Read The Filings. Most Carriers Are Silent On AI Losses, And That Is The Problem.
- Mosaic: We’re Going Global with Primary Cyber Insurance (Opens in a new browser tab)
- Mosaic, Incyde Risk, and Safe Security Partner to Strengthen Cybersecurity in Financial Sector(Opens in a new browser tab)
- CISA’S Jen Easterly: Federal Cloud Security Must Evolve to Thwart Modern Threats(Opens in a new browser tab)
- Mosaic Launches Cyber and Financial Institutions Insurance for Digital Assets(Opens in a new browser tab)