Hartmut Mai, Group President of CyberWrite
Insurance Doesn’t Actually Have a Failure Culture. Make a Big Mistake as an Underwriter and Nobody Says “Thank You for Learning.”
Hartmut Mai’s insurance career started almost by accident, in the way careers built on genuine scarcity often do. Trained as a lawyer in Germany and the US, he worked D&O litigation at a US law firm — a niche barely known in Germany at the time. When he moved back, one company was hiring D&O underwriters, and almost nobody in the German market actually understood the line. He researched the company on microfiche, since there was no usable internet search yet, and discovered it was AIG, then the largest insurer in the world. That’s how he became a D&O underwriter, quickly specializing in dual-listed German companies seeking a second listing in the US — a niche with dramatically elevated exposure that required genuine creative underwriting to make marketable at all.
From AIG he moved to Marsh as a broker — wanting to understand the client-facing side of the business he’d only underwritten from the carrier seat — and then to Allianz, where he spent 14 years: building the Global Financial Lines unit, launching Allianz’s first standalone cyber policy and cyber program in Germany in 2012 (and building the group’s Cyber Excellence Center), then rising to the board as Chief Underwriting Officer and CEO of the large corporate business, and later Chief Regions & Markets Officer covering the EMEA time zone.
He first met Neil Cohen — who would go on to found CyberWrite a year later — in 2016, while running a large cyber underwriting tender at Allianz. Hartmut no longer wanted cyber underwriting to run on paper the way it had in 2012, and Cohen had a mockup of a platform that pointed toward something better. Years later, after Hartmut left Allianz, Cohen reached out, and Hartmut joined CyberWrite.
In Episode 112 of InsurTechTalk, Hartmut and I covered what genuinely differs between underwriting at a blue-chip carrier and building product at a startup, and how CyberWrite’s algorithm actually scores cyber risk and delivers underwriting-ready reports in real time.
About Hartmut Mai
Hartmut Mai is Group President of CyberWrite, a cyber risk analytics and underwriting platform. Before CyberWrite, he spent 14 years at Allianz — building the Global Financial Lines unit, launching Allianz’s first standalone cyber insurance program in 2012, serving as Chief Underwriting Officer and CEO of the large corporate business, and later as Chief Regions & Markets Officer for EMEA. Earlier in his career he was a D&O underwriter at AIG and a broker at Marsh. He is a trained lawyer, educated in Germany and the US.
Why He Actually Left a Board Seat for a Startup
Hartmut was candid that the decision wasn’t really about escaping large companies — he’d already moved between three (AIG, Marsh, Allianz) across more than two decades and found each genuinely interesting. The real question, after that long a career, was different: did he want to trade one blue-chip logo for another and keep doing fundamentally the same work, or actually do something different while still drawing on everything he’d built. He spent time advising several startups — including one in quantum computing and one building standardized risk models for large corporate business — before CyberWrite’s relationship, built on that earlier 2016 connection with Cohen, developed into a full-time role.
What a Startup Actually Teaches a 20-Year Underwriter
Asked directly what large-corporate experience translates into at a startup, and what doesn’t, Hartmut’s answer centered on two structural differences.
Speed of decision-making, and a genuine failure culture. His observation on the gap between what large insurers say about failure culture and what actually happens: insurance talks about embracing failure, but when an underwriter makes a major mistake, the result is real losses — nobody says “thank you for the lesson, please don’t do it again.” A startup, by contrast, genuinely allows testing ideas with real clients and adjusting quickly, which he considers a structurally different and more honest relationship with failure.
Laser-sharp focus on a single, precisely defined problem. Before CyberWrite built its product, the team ran hundreds if not thousands of market conversations specifically to nail down what problem actually needed solving. Seven years ago, the core problem wasn’t underwriting sophistication — it was that cyber insurance simply wasn’t marketable, because almost nobody on the intermediary or underwriting side understood the risk well enough to sell or price it confidently.
The Problem Evolved: From “Nobody Understands Cyber” to Aggregated Exposure
Hartmut traced how the actual underwriting problem shifted over CyberWrite’s seven years:
- The initial problem was education and marketability — closing the knowledge gap that made cyber hard to sell or underwrite confidently at all
- A later, structurally harder problem emerged: aggregated exposure — the fact that a single cyber event can trigger not one policy but hundreds or thousands simultaneously, which almost nobody was discussing seriously seven years ago
- Solving aggregation requires portfolio-level data infrastructure, not just single-risk underwriting tools — CyberWrite now works with reinsurance clients screening and profiling up to a million accounts annually, delivering both aggregated portfolio-level exposure data and individual policy-level detail
The intermediary side has its own version of the same underlying problem: brokers and agencies historically struggled to have a credible, informed conversation with clients about their actual cyber exposure. Hartmut’s observation, backed by client performance data rather than just anecdote: brokers using CyberWrite’s profiling reports become genuinely more effective and trusted advisors, measurably improving their sales success, because they can walk a client through specific findings rather than a generic pitch.
How the Platform Actually Scores Risk
CyberWrite’s core technology is a patented algorithm Hartmut called “Foresight” (referenced in the conversation as their proprietary scoring engine).
- The platform gathers information — potentially hundreds of thousands of data points — from the public internet and dark web about a given company
- That data feeds into a model that compares the target company against a reference set of 300,000 other firms matched by segment, size, and jurisdiction — some of which have experienced breaches, some of which haven’t, with each breach broken down by underlying cause
- The output is a Cyber Insurance Risk Score from 0 to 100 (100 being best), benchmarked directly against comparable peer companies, not scored in isolation
- Beyond the score, the report lists specific vulnerabilities (technology stack weaknesses, credentials found exposed on the dark web, etc.), an economic impact analysis (estimated cost of a breach, broken out by policy coverage section), and — notably — a list of regulatory violations the company is already exposed to before any breach occurs
- Every report is designed to be actionable and understandable without requiring cyber expertise to interpret — a broker can walk a client through the findings directly
Real-Time, Global, and 99.97% Coverage
The operational claim Hartmut was most emphatic about: CyberWrite doesn’t pre-build and shelve reports on a fixed universe of large, well-known companies. Every request runs in real time against live data, which is what allows the platform to actually find and score small businesses that wouldn’t appear in a static database — his example being a small business “around the block in Brunei or in India,” not just easily searchable large enterprises.
- The platform operates in eight languages, with the ability to add more as needed
- Clients span Asia (including the Philippines and India), the US, Europe, and Latin America
- Report generation succeeds 99.97% of the time for companies queried on the platform — a figure Hartmut positioned as a genuine market differentiator, since most competitors’ data coverage skews heavily toward easily-searchable large enterprises
Wins That Matter More Than Awards
Asked about recent recognition, Hartmut redirected toward client wins as the more meaningful signal: MS Amlin as a new client, the largest global broking house in India (a market he described as growing rapidly for cyber insurance interest, beyond the more commonly discussed US market), and a renewed, competitively re-tendered contract with HSB/Munich Re in the US — beating out roughly 14 other players in that tender after six years as their partner. His framing: an award is nice, but a client renewing after publicly re-competing the business is real proof the technology performs.
The Future of Insurtech: A Longer Arc Than Next Year
Asked to forecast 2024 for insurtech, Hartmut instead offered a longer historical arc. Early insurtech pitches to large carriers were frequently met with polite interest followed by “we’ll just build it ourselves” — and when CyberWrite’s team followed up with some of those carriers years later, little had actually been built. His pointed observation: it took CyberWrite seven years to build what exists today; carriers assuming they can compress that into a fraction of the time internally are generally mistaken.
What genuinely changed the landscape, in his view, was the emergence of dedicated corporate venture arms (AllianzX, and similar structures at other large carriers and brokers) — once large insurers began treating startup investment as both strategically and financially motivated rather than a “nice to hear about” conversation, the ecosystem shifted from talk to genuine partnership and acquisition activity.
His segment-by-segment read on where digitalization still has the most room to run: personal lines is comparatively mature; mid-corp and upper-mid-corp have made real progress; large corporate remains substantially underdeveloped, with genuine room for new ideas and new solutions — and, in his assessment, today’s market is far more receptive to outside innovation than it was even a decade ago.
Advice: Don’t Fear It, Because It’s Happening Either Way
Asked for advice specifically for underwriters navigating AI and GenAI adoption, Hartmut’s answer was a single line: don’t fear it, embrace it — because whether you fear it or not, it’s going to happen regardless.
Key Takeaways
- Insurance doesn’t have a genuine failure culture despite the rhetoric — real losses follow underwriting mistakes, which is part of why startups can iterate in ways large carriers structurally cannot
- CyberWrite’s core problem shifted over seven years from basic cyber risk education and marketability to solving aggregated exposure — the fact that one event can trigger thousands of policies simultaneously
- Scoring risk against a 300,000-company benchmark set, rather than in isolation, gives underwriters genuine comparative context, not just an absolute number
- Real-time data gathering (rather than a static, pre-built database) is what lets the platform find and accurately score small businesses in markets like India and the Philippines that competitors’ shelf-based data typically misses
- A 99.97% report-delivery success rate is a meaningful differentiator specifically because most cyber risk platforms struggle to cover small and mid-market accounts outside the largest, most searchable enterprises
- Corporate venture arms genuinely changed carrier-startup dynamics — before their emergence, “we’ll build it ourselves” pitches from carriers rarely materialized into real internal products
- Large corporate insurance remains the least digitized segment of the market relative to personal lines and mid-corp, representing the biggest remaining opportunity for new insurtech solutions