The insurer’s head of commercial claims says that although employees are the ‘most important assets’ within an organisation, they are also ‘one of the points of greatest weakness’
Employee risk “is definitely higher up the agenda” for corporate risk managers as cost of living challenges, greater artificial intelligence (AI) utilisation and evolving geopolitical linked cyber threats create a tripartite of drivers for “very significant losses” linked to people practices, according to Charles Bush, head of commercial claims at insurer Zurich.
Speaking exclusively to Insurance Times, Bush highlighted that although “employees are the most important assets within your organisation, they are also one of the points of greatest weakness”, with five key trends emerging from Zurich’s commercial claims data that pinpoint people related pain points.

These include social engineering, employee theft of money, data and intellectual property, cyber linked incidents, employment practices and the increasing usage of AI – which interlinks with all risk vectors as well as being a standalone threat.
For Bush, social engineering – where criminals trick employees into providing confidential data, passwords or organisational system access through fraudulent emails or text messages, for example – is the risk threat “that sticks out most” from this list.
The reason for this, continued Bush, is that although social engineering linked claims were not presenting “a volume issue” for the insurer, “the values at risk are very, very significant”, with Zurich seeing “two very significant losses in excess of £10m” this year alone – on top of “a number of smaller losses”.
He added: “There might be a challenge here.”
One particular tactic that Bush is seeing employed by criminals against organisations is what he described as “fake president fraud”.
He explained: “This is where threat actors are masquerading as chief executives and sending very targeted, often WhatsApp, messages to other very senior people within the business, stating that they’re involved in a highly confidential piece of M&A or some [other] kind of transaction and they need somebody to start paying a law firm, for instance.
“The way in which these scams are structured are highly sophisticated, so if you dial the telephone number that the WhatsApp message has come in from, [the criminals are] able to put voices through synthesisers to make it sound exactly like the person who is alleged to have sent the message to you, so that you build up a confidence level that means you should now pay the £100,000 of legal fees to that company, helping [the supposed] chief executive with that transaction.
“[This] then acts as the Trojan horse for future payments to be made. The people being targeted are all very busy and they’re saying ‘I went through the due diligence process for the first payment, so therefore the next payment must be legitimate [too]’.”
Bush additionally warned that phishing emails are becoming increasingly tricky for employees to spot due to AI.
He continued: “I can’t underestimate the level of sophistication which some of these threat actors now have, so their own use of AI to remove grammatical errors or spelling mistakes.
“Their ability to now deploy AI to ensure that emails coming into our organisations are really smart, with all the correct branding, and taking information which they can find on open sources like LinkedIn and then making the email very targeted to you, looking as if it knows who you are [in order] to lure you in, to then clicking on the [provided] link.
“It only takes one employee in an organisation to click on a link to suddenly compromise your entire network and your system.”
‘Prevention is better than cure’
Bush recommended a number of mitigating actions that organisations could take forward to reduce these types of employee risks from occurring.
Read: Insurer use of agentic AI creating ‘new generation of conduct risk’
Explore more risk management related articles here, or discover more news here
The most important of these is “having a really open and honest culture within your organisation” that empowers staff to “pick the phone up [and use] the number that’s saved in your mobile phone for that particular individual and phone them directly rather than through the number which the [fraudulent] messages [have] come in from”.
Other risk management approaches companies could use to combat people risk include:
- Multiple level payment verification processes to reduce fake president fraud.
- Introducing robust procedures around AI usage to ensure ethical practice.
- Thorough onboarding processes for new starters.
- Regular phishing exercises for staff to practice spotting fake emails.
Bush said: “I would suggest that the cost to prevent [people related risks] from happening is a very worthwhile investment compared to the cost of dealing with the consequences of not managing businesses properly, which is very much around this prevention and mitigation point.
“Prevention is better than cure. The cost of preventing something from happening is often far less than the cost of fixing the problem once it’s happened. And we must not just think of this as a financial cost. This is also a significant reputational cost.”

Bush additionally believes that claims data can be a vital tool to drive risk management strategy too, with the insurer, its risk consulting arm Zurich Resilience Solutions, partner brokers and end customers all learning from claims trends and using the findings to implement mitigating measures.
“My personal ambition is to move the industry’s claims functions from being seen as a back office function to something which is absolutely critical to why our customers want to place business with us,” he said.
“So much of what we see where [employee linked] losses have occurred is relatively simple things either being breached or processes not being in place [within] those organisations, so we’re trying to identify either through data or anecdotally where things have failed and then trying to draw attention to those particular areas, so that we don’t just help our customers that have suffered losses, but ideally moving our claims function to support all of our customers – not just those that are unfortunate to suffer losses.”
Healthy habits
One area of employee related risk that Bush believes “is starting to emerge” more strongly this year is around “the health of the workplace” – he had numerous conversations on this subject during June 2026’s Airmic Conference in Birmingham, for example.
For him, it is becoming increasingly important that organisations consider their resilience in terms of the physical, mental and financial health of their workforce, exploring in greater detail how to “tie HR functions and risk management functions together because we know that healthy workplaces are often more productive workplaces”.
He continued: “So, how do we ensure we’re using all the data that’s available to us in the most effective way? [It comes] back to that resilience point [and building] a really resilient organisation that has more of a focus on physical [and] mental health.
“We were even talking about financial health and making sure that people understand what good financial health looks like, so that they come to work really positively.
“That’s probably an area which is starting to emerge.”

Since joining Insurance Times, Katie has successfully obtained a number of industry accolades. At trade body Biba's 2025 Journalist and Media Awards, for example, Katie was named the overall winner and received the Journalist of the Year trophy, alongside the Best Thought Leadership Award for her briefing article on reproductive health MGA Juniper and how insurance can be used to positively impact taboo subjects.View full Profile













































No comments yet