
Turning Cyber Risk Into a Decision You Can Defend
Patrick Miller sits down with Scott Kannry, co-founder and CEO of Axio, to work through cyber risk quantification as a security decision tool for OT and critical infrastructure. Scott came up in the insurance industry at Aon in the early days of cyber coverage. He founded Axio with Dave White to close the gap between a technical security program and a number a CFO and a board can act on.The conversation stays practical. Why you start on the impact side instead of arguing about probability. How NERC CIP already thinks in consequence. Why the events that matter most are rare, huge, and short on data. How to compare controls, insurance, and compliance spend on the same dollar scale. What AI and quantum do to the "it will never happen" excuse. And a new D&O option for CISOs built on top of consistent quantification.Full show notes, links, and the episode transcript are on the Ampyx Cyber episode page at ampyxcyber.com/podcast.Topics covered:The founding of Axio and the insurance-meets-frameworks originA short history of cyber insurance, from data breach to business interruption to cyber-physicalThe four loss categories Axio uses, first and third party, financial and tangibleCoverage gaps for industrial facilities and the danger of assumed coverageImpact-first quantification versus probability-first modelingNERC CIP and consequence-only risk ratingFiduciary duty, duty of care, and defensible decisionsSecurity decision support versus vanity security metricsThe art and science of pricing control ROIAI and quantum, and why low-probability high-impact events deserve attention nowA D&O insurance option for CISOs tied to consistent quantification














