A photo from yesterday, versus a livestream: with Helvetia Baloise at Insurers’ Day

How can insurers and other financial-sector companies meet rising regulatory requirements for cybersecurity? “With the Cyber Resilience Shield,” answered Sandra Känzig, CISO of the Helvetia Baloise Group, and Sandro Nafzger, in a joint presentation to members of the Swiss Insurance Association (SIA). 

by Isaak Mtizwa, Published on 22. June 2026 4 min Reading time

Companies that rely on occasional penetration tests today are working from snapshots – yesterday’s photos, so to speak – while their attack surface behaves like a livestream, changing daily with every new release, new service, and new interface. That was the central message of Sandra Känzig and Sandro Nafzger’s joint presentation at Tag der Versicherer (“Insurers’ Day”). 

How much security does a company need, and how much risk is it willing to bear? That was the question posed at this event, organized by the SIA at the Tonhalle in St. Gallen, which examined insurability from a cybersecurity perspective, among other topics. 

Nafzger set the tone from the start: with AI, attackers can find vulnerabilities at the push of a button, while defenders are still handling vulnerabilities manually – a slow process by comparison. “Attackers today are a whopping one hundred times faster at finding and exploiting vulnerabilities than defenders,” he said. His call to defenders: “Use intelligent and autonomous systems – just like the attackers do!” 

Sandra Känzig agrees that most companies in this field still rely on traditional testing methods like penetration tests. These have their place, she argues, but they’re far from sufficient. “If we take a snapshot twice a year, we may be compliant, but we’re not secure.” The problem: today’s penetration tests don’t scale. Traditional testing is time-consuming and therefore expensive, while automated scanners are superficial and inflexible. Yet since January 2025, the EU’s Digital Operational Resilience Act (DORA) has required financial-sector companies – and their critical third-party IT providers, such as cloud providers – to conduct continuous, threat-based testing. 

To meet these high standards, the Helvetia Baloise Group has maintained a proven partnership with Bug Bounty Switzerland since 2021, and since 2025 has also relied on the Cyber Resilience Shield. Känzig illustrated the concrete benefits with a few figures: 450 of the Group’s assets are continuously tested by around 500 ethical hackers, who have so far found more than a hundred validated security vulnerabilities, including six highly critical ones – and the number keeps rising. In the first half of 2026 alone, more than forty additional vulnerabilities have already been found. 

One example: a critical vulnerability discovered in the production e-banking system. “An ethical hacker found it before an unethical one could,” Känzig explained. For her, the conclusion is clear: checking the compliance box once or twice a year with conventional methods may have been enough in the past, but in the age of AI, it no longer is. “This isn’t a compliance issue. It’s about survival.” Her message to the audience: “Have your systems continuously tested by ethical hackers – before the unethical ones do.” 

Or as Sandro Nafzger put it at the end: in cybersecurity, there are two ways to find a previously unknown vulnerability – either before an attack, or after. 

We all prefer “before.”

We'll help you, let's chat about how!

Let's meet for a virtual coffee. Via calendly you can book yourself directly into our calendar. Try it out.

Schedule meeting