

Turning Cyber Risk Into a Decision You Can Defend
Patrick Miller sits down with Scott Kannry, co-founder and CEO of Axio, to work through cyber risk quantification as a security decision tool for OT and critical infrastructure. Scott came up in the insurance industry at Aon in the early days of cyber coverage. He founded Axio with Dave White to close the gap between a technical security program and a number a CFO and a board can act on. The conversation stays practical. Why you start on the impact side instead of arguing about probability. How NERC CIP already thinks in consequence. Why the events that matter most are rare, huge, and short on data. How to compare controls, insurance, and compliance spend on the same dollar scale. What AI and quantum do to the "it will never happen" excuse. And a new D&O option for CISOs built on top of consistent quantification. Full show notes, links, and the episode transcript are on the Ampyx Cyber episode page at ampyxcyber.com/podcast. Topics covered: The founding of Axio and the insurance-meets-frameworks origin A short history of cyber insurance, from data breach to business interruption to cyber-physical The four loss categories Axio uses, first and third party, financial and tangible Coverage gaps for industrial facilities and the danger of assumed coverage Impact-first quantification versus probability-first modeling NERC CIP and consequence-only risk rating Fiduciary duty, duty of care, and defensible decisions Security decision support versus vanity security metrics The art and science of pricing control ROI AI and quantum, and why low-probability high-impact events deserve attention now A D&O insurance option for CISOs tied to consistent quantification











