Skip to content

Cybersecurity Insurance with Doug Kreitzberg of SeedPod Cyber

Cybersecurity Insurance with Doug Kreitzberg of SeedPod Cyber
9:15
Cybersecurity Insurance with Doug Kreitzberg of SeedPod Cyber

AI adoption inside most businesses is not happening according to a carefully designed five-year technology plan.

Someone discovers ChatGPT can save 30 minutes writing a proposal. Marketing finds a tool that creates content faster. An employee uploads a spreadsheet to an AI assistant to analyze it. Another team starts experimenting with an AI agent to automate part of a workflow.

Nobody sends out a companywide memo announcing that the AI transformation has begun.

It just happens.

That creates an interesting problem for business owners. AI can deliver legitimate productivity gains, but employees may be adopting it faster than leadership can establish rules for its use.

The bigger surprise is that this is becoming more than an IT problem. It can affect cybersecurity, compliance, intellectual property, customer data, and even your insurance coverage.

In a recent episode of Shh... IT Happens, we spoke with Doug Kreitzberg of SeedPod Cyber about how businesses can take advantage of AI without quietly creating risks they do not understand.

One of the most important points from the conversation was simple: AI adoption should start with intention.

AI may already be inside your business

Business owners sometimes talk about AI adoption as something they are considering for the future.

Your employees may have already made that decision for you.

That does not mean they are doing anything malicious. Usually, they are trying to work faster.

An employee discovers an AI tool that summarizes meetings. Someone uses a personal ChatGPT account to draft customer communications. Another employee uploads information because they want help analyzing it.

Each decision may seem harmless by itself.

The problem is that leadership may have no idea which tools are being used, what information employees are putting into them, or where that information goes afterward.

Doug described this as adoption happening before intention.

That distinction matters.

Businesses have spent years creating rules around employees. People have job descriptions. They have permissions. They have managers. They have processes for escalating decisions. They have limits on what information they can access.

Doug suggested businesses start thinking about AI tools in a similar way.

What is this tool's job?

What information does it need access to?

What decisions can it make?

When does a human need to approve its work?

Those questions become even more important as businesses move from simple AI assistants toward AI agents capable of taking actions across multiple systems.

Your cyber insurance policy may be changing too

Cyber insurance has already become considerably more complicated.

Businesses that remember filling out relatively simple applications years ago are now answering detailed questions about multifactor authentication, endpoint security, backups, employee training, phishing simulations, and incident response.

AI is beginning to enter that conversation.

Doug explained that some insurers are responding to AI risk in a predictable way: if they cannot adequately understand or price the risk, they may limit or exclude it.

The issue also reaches beyond standalone cyber insurance.

AI can potentially affect product liability, general liability, employment practices, and other forms of coverage depending on how a business uses it.

Larger companies are already seeing more detailed questions from underwriters about AI governance. According to Doug, that level of questioning has not fully reached small businesses yet, but businesses should expect insurers to pay increasing attention as the risks become better defined.

That creates a good reason to get ahead of the issue.

You do not want to discover what your insurance policy thinks about AI for the first time while filing a claim.

Governance does not need to mean bureaucracy

Mention "AI governance" and it is easy to picture a 73-page policy document quietly aging in a shared drive.

That is not particularly useful.

Governance can start with a few practical decisions.

First, figure out which AI tools employees are already using.

Then determine what information those tools should and should not receive.

Customer records, financial information, contracts, employee information, intellectual property, passwords, healthcare information, and other sensitive data should not casually find their way into an unapproved AI platform.

From there, establish which tools are approved for company use.

This is where the difference between personal and business AI accounts becomes important.

During the episode, John Ohlwiler raised an example that should get any business owner's attention. If an employee builds important workflows, prompts, or business knowledge inside a personal AI account, what happens when that employee leaves?

The account leaves too.

Your new AI-powered business process may suddenly belong to somebody who no longer works for you.

Company-managed AI accounts give businesses more control over access, data, administration, and offboarding. They also make it easier to establish consistent rules instead of asking employees to improvise.

Data classification is becoming much more important

AI also exposes a problem many companies have ignored for years.

They do not actually know what data they have.

Businesses accumulate enormous amounts of information. Some of it is public. Some is internal. Some is confidential. Some should have been archived years ago but continues sitting around because nobody wants to be the person who deletes the wrong folder.

AI makes those distinctions more important.

Eddie Clark discussed the value of data classification during the episode. A business can begin by separating information into practical categories.

Public information may be appropriate for broader use. Internal information may require restrictions. Confidential information should have much tighter controls.

Once information is classified, security tools and AI systems have a better chance of enforcing those rules.

This also forces the business to answer an important question: who is allowed to make exceptions?

Technology can enforce a rule, but leadership still has to create it.

Human first. Human last.

AI-generated "work slop" has become its own category of business problem.

An employee gives an AI tool a weak prompt, gets an authoritative-sounding answer, copies it into an email, and sends it without checking the output.

Efficiency achieved.

Accuracy pending.

Eddie made a useful point during the episode: AI should be human first and human last.

A person determines what the tool is being asked to accomplish. A person should also remain responsible for reviewing the result.

That becomes particularly important when AI is creating customer communications, analyzing sensitive information, recommending decisions, or taking actions inside other systems.

AI can help employees spend less time on repetitive work and more time on judgment, relationships, strategy, and problem solving.

That is where some of its greatest value lies.

Removing human oversight to squeeze another few minutes out of a process can create far more expensive problems later.

Small businesses need technology leadership too

There was another important thread in the conversation that extends beyond AI.

Large organizations increasingly have executives responsible for information technology, cybersecurity, compliance, privacy, and now AI.

Small and midsize businesses usually do not have that luxury.

The owner, CFO, operations leader, or IT manager may be wearing several of those hats at once.

That does not make the decisions less important.

Doug pointed out that virtually every company is now a digital business whether leadership thinks of it that way or not.

Technology affects how you communicate, collect money, store information, serve customers, manage employees, and protect intellectual property.

AI only increases that dependency.

Small businesses therefore need access to technology strategy even when hiring several specialized executives makes no financial sense.

That may come from an internal IT leader, a managed IT provider, a virtual CIO, outside cybersecurity expertise, insurance advisors, or some combination of those resources.

The important part is getting the right people into the conversation before major decisions are made.

Your attorney advises you on legal risk. Your accountant advises you on financial risk.

Technology deserves the same level of attention.

Start small, but start now

You do not need an AI committee with matching polo shirts by Friday.

You do need visibility.

A practical starting point is to:

  • Find out which AI tools employees are already using.
  • Ask what business problems they are using those tools to solve.
  • Identify what company information should never be entered into an unapproved AI system.
  • Move employees toward company-approved business or enterprise AI accounts.
  • Establish a basic acceptable use policy for AI.
  • Decide where human review and approval are required.
  • Classify sensitive business data and control who can access it.
  • Review your insurance policies and renewal questionnaires for AI-related exclusions or requirements.
  • Include IT, leadership, security, and insurance advisors in the conversation.
  • Train employees instead of expecting them to figure this out on their own.

The policy does not have to be perfect on day one.

AI is moving too quickly for any policy to remain perfect for long anyway.

The goal is to create enough structure that employees can experiment productively without everyone inventing their own rules.

AI should create leverage, not invisible risk

Doug emphasized something worth remembering throughout the conversation: AI represents a major opportunity for small businesses.

A smaller company can use these tools to expand what its existing team is capable of accomplishing. Employees can automate repetitive work, analyze information faster, improve workflows, and spend more time on the work that actually requires their experience.

That opportunity is worth pursuing.

It is also worth protecting.

At Solve iT, we help businesses understand what is happening across their technology environment before small gaps become expensive surprises.

That includes cybersecurity, Microsoft 365, backups, identity and access, employee security awareness, data protection, technology planning, and the policies that connect those systems to how people actually work.

AI belongs in that conversation now too.

If employees are already experimenting with AI and you are not sure what company information is being shared, what tools are approved, or whether your current cybersecurity controls and insurance requirements are keeping pace, this is a good time to find out.

Our free threat assessment provides a practical look at your current risk profile, including cybersecurity gaps, dark web exposure, phishing risk, and cyber insurance readiness.

Book your free threat assessment, and get a clearer picture of the risks your business knows about and the ones quietly taking shape in the background.