On the morning of March 20, 1905, in the basement of the R.B. Grover shoe factory in Brockton, Massachusetts, a boiler exploded. The blast tore through four floors, killed 58 people and injured 150 more. Workers were buried under brick and timber. The boiler had not been inspected. Nobody had required it to be. There was no law, no standard, no insurance mandate that said a factory owner in Massachusetts had to prove his pressure vessels would not kill the people standing above them. The boiler was a known risk. The explosion was a known possibility. And yet, because nobody had been forced to quantify that risk in a way that cost money, it remained -- in the language of the balance sheet -- invisible.
That explosion changed the world. Not immediately. Not through outrage alone. Through insurance.
The Hartford Steam Boiler Inspection and Insurance Company had been founded in 1866, nearly four decades before Brockton, by industrialists who understood something most of their contemporaries did not: you cannot manage what you do not measure, and you will not measure what you are not forced to pay for. Hartford's model was elegant. They would insure your boiler. But before they insured it, they would inspect it. And the inspection would determine the premium. A well-maintained boiler with a competent operator cost less to insure than a corroded tank in a damp cellar with a drunk at the valve. The insurance created the incentive. The incentive created the inspection. The inspection created the standard.
This was not a theory. It was an industry. Hartford's inspectors -- engineers, not salesmen -- examined tens of thousands of boilers across the United States. They rejected the dangerous ones. They prescribed improvements for the marginal ones. And the data they gathered fed directly into the ASME Boiler and Pressure Vessel Code, first published in 1914.
The pattern was not unique to steam. In 1835, Zachariah Allen built a fire-resistant factory in Rhode Island and could not get a cheaper premium for it -- so he founded Factory Mutual, a cooperative that rewarded mitigation. Members who installed sprinklers and maintained clear egress paid up to 50% less. Factory Mutual did not merely insure against fire. It invented the discipline of fire protection engineering. Insurers subsequently funded Underwriters Laboratories in 1894 to certify electrical products. And Lloyd's Register, established in 1760, graded every vessel that sought insurance -- hull, rigging, condition of timber. "A1" entered the English language from that scheme.
Technologies change. Human nature does not. The pattern is 270 years old. Insurance creates inspection. Inspection creates standards. Standards create safety. Not the other way around. Not because people suddenly decide to be responsible. Because the cost of irresponsibility lands on someone's balance sheet.
Then Like Now
I keep looking for this pattern in the technology industry. I keep not finding it.
I see organisations running bespoke, artisanal infrastructure that nobody outside the building can understand, let alone inspect. I see authentication, encryption, and web application firewalls -- components that Wardley Mapping would place firmly in the commodity zone -- being hand-crafted like Victorian furniture by teams who should be consuming them as utilities. I see Artisanal Frankenstein architectures stitched together from custom components that exist because someone once needed them, not because anyone still understands them. And I see an industry that treats all of this as normal.
It is not normal. It is unquantified risk masquerading as operational maturity.
The digital industry is the only major sector that does not put risk on the balance sheet. Aviation does it. Shipping does it. Construction does it. In the 1980s, the American Society of Anesthesiologists confronted a crisis: malpractice premiums were making it impossible to practise. The response was not to lobby for cheaper insurance. It was to adopt mandatory monitoring standards -- pulse oximetry, capnography, blood pressure monitoring -- that made anaesthesia measurably safer. Premiums fell by 66% between 1985 and 1991. The same pattern. Again.
Digital and technology? Nothing. The balance sheet is blank.
What we have instead is security theatre. The CISO is the person we hire to make risk visible, and then we give them every incentive to make it invisible again. They are measured on reducing rows in a risk spreadsheet. Not risk. Rows. The distinction is everything. A CISO who investigates deeply will find more risks, which means more rows, which means they look worse. A CISO who minimises, who recategorises, who declines to investigate -- that CISO's spreadsheet looks clean. The system rewards the appearance of safety over the fact of it. EY's 2025 study found that CISOs can generate $36 million per strategic initiative -- yet only 13% are involved early enough to influence the architecture. They are brought in after the decisions have been made, handed a spreadsheet, and told to make it shorter.
The role, as currently constituted, is structurally broken. Gartner reports that the average CISO tenure is 26 months. Seventy-six per cent report burnout. These are not the numbers of a profession that is working. These are the numbers of a profession designed to absorb blame, not reduce risk.
And beneath all of this sits the most dangerous assumption of all -- what I call the zero baseline fallacy. The zero baseline treats standing still as zero risk. It says: we have not changed anything, therefore our risk has not changed. This is a lie. Every day you do not update a dependency, every month you do not patch a vulnerability, every quarter you do not review an architecture decision made three years ago by someone who no longer works here -- risk is accumulating. You are not standing still. You are falling behind. The zero baseline is not zero. It is unquantified risk accumulation, compounding silently like debt you refuse to open the statements for.
This is where insurance enters. Not as a luxury. As a forcing function.
Think of it as locks on doors. Better locks mean cheaper premiums. The premium reduction pays back the investment -- you spend money on security, your insurance costs go down, and the net position improves. But the return is larger than the premium alone. The organisation that becomes insurable also becomes certifiable, auditable, contractable. It can operate in regulated markets. It can survive an incident without existential consequences. Insurability is not a cost. It is a capability that unlocks options you cannot access without it.
The mechanism only works if the insurance is mandatory. Optional insurance creates adverse selection: the companies that buy it are the ones that least need it. The ones that need it most -- the ones with Artisanal Frankenstein architectures, bespoke authentication, hand-rolled encryption -- will not buy it voluntarily because doing so would require them to admit what they have.
Forty-one per cent of cyber insurance applications are already being denied. Eighty-two per cent of denied applicants lacked multi-factor authentication. The insurers are already doing what Lloyd's did in 1760: looking at the hull and refusing to insure the ships that cannot demonstrate basic seaworthiness. The difference is that in shipping, you cannot operate without insurance. In technology, you can. And millions do.
The prescription is not complicated. It is politically difficult. But it is historically proven. What I am proposing is a maturity spectrum -- a way to understand where your organisation sits on the path from uninsurable to insurable, and what it costs to stay where you are.
At the bottom: uninsurable. No MFA. No patching cadence. No architecture documentation. No incident response plan. Bespoke authentication hand-rolled by a developer who left two years ago. This is the corroded boiler in the damp cellar. This is where most of the industry sits, and most of the industry does not know it. The cost of staying here is not zero -- it is the full, unpriced exposure to every breach, every regulatory action, every contract you cannot bid for because you cannot demonstrate basic hygiene.
In the middle: conditionally insurable. MFA deployed. Patching happens, if irregularly. Architecture documentation exists but is eighteen months out of date. Incident response plans have been written but never tested. The insurer will cover you, but the premium reflects the gap between what you claim and what you can demonstrate. This is where the inspection begins to bite.
At the top: insurable. MFA universal. Patching cadence documented and auditable. Architecture comprehensible to an external inspector. Incident response tested annually. Commodity components consumed as utilities, not hand-crafted. The premium reflects genuine risk reduction, not theatre. This is Hartford's well-maintained boiler with a competent operator.
The regulatory scaffolding for this already exists in outline. The UK Cyber Security and Resilience Bill is heading in the right direction -- penalties up to 17 million pounds or 4% of turnover. The ICO has shown its willingness to act -- the 14 million pound fine on Capita for a 58-hour delay on a security alert proves the teeth exist. And an MOT-equivalent inspection regime -- not a one-off audit but a periodic assessment where an accredited inspector examines your architecture and certifies it as comprehensible, maintained, and insurable -- would complete the picture. The MOT test was introduced in 1960, initially checking only brakes, lights, and steering. It has expanded over six decades as vehicles and risks have changed. The key insight of the MOT is not that it catches every fault. It is that it creates a regular forcing function -- a moment when the owner must confront the condition of the machine.
Where the Analogy Gets Hard
I believe the argument I have just made. But I am not certain the historical parallels carry it all the way home, and I owe you honesty about where they strain.
The first difficulty is pace. A boiler sits in a basement. It does not redeploy itself fifty times a day. Software systems in a CI/CD pipeline are not static objects awaiting periodic inspection -- they are continuously changing artefacts whose risk profile shifts with every commit. What does an "annual MOT" mean for a system that transforms itself weekly? I do not have a clean answer. The inspection may need to target the pipeline and the controls rather than the artefact -- examining not the code but the process that governs how code changes, how dependencies are tracked, how rollbacks work. That is a different kind of inspection from anything Hartford's engineers performed, and I am not certain we know how to do it well yet.
The second difficulty is boundaries. Hartford's inspectors could walk into a basement and see the boiler. The boiler had edges. Modern software systems do not. They depend on third-party APIs, open-source libraries maintained by volunteers, cloud services that abstract away the infrastructure entirely. What is the inspectable unit when your authentication depends on a provider who depends on a library whose maintainer is one burnt-out volunteer away from abandoning the project? The boundary problem is real, and pretending it is not would make me guilty of the same wishful thinking I have spent this piece criticising.
The third difficulty is regulatory capture. I have argued that mandatory insurance creates inspection and inspection creates standards. But it can also create a compliance industry -- checkbox auditors, certification mills, premium-optimisation consultants -- that produces the appearance of safety without the substance. This happened with SOX. It happened with PCI-DSS. It is arguably happening right now with GDPR cookie consent banners that everyone clicks through without reading. My own analysis of CISOs reducing rows rather than risk applies with uncomfortable precision to the insurance model I am advocating. If the inspection becomes a box-ticking exercise, we will have replaced one form of theatre with another. The difference -- and I concede this is a bet rather than a certainty -- is that insurers have a financial incentive to get the assessment right in a way that compliance auditors do not. An insurer who underprices risk loses money. A compliance auditor who issues a certificate does not.
I do not think these objections are fatal. The GAO has examined the moral hazard question in the context of federal cyber insurance backstops and found the concern legitimate but manageable -- experience-rated premiums, mandatory inspections, and coverage limits can mitigate the worst outcomes. The Insurance Institute for Highway Safety, founded by insurers in 1959, showed how this works in practice: insurers funded crash testing, crash testing created safety ratings, safety ratings changed what people bought, and the cars got safer. The mechanism works. Whether it can be adapted to software at scale is a bet. I think it is the right bet. But it is a bet.
The Lie We Tell Ourselves
I know the objection. "This will slow us down. This will increase costs. This will make us less competitive." Yes. Boiler codes slowed down boiler manufacturers. MOTs slowed down car owners. Lloyd's Register slowed down shipbuilders. And in every single case, the industries that survived were the ones that submitted to inspection, not the ones that ran from it. The uninsurable ship did not compete with the insured one. It sank.
The technology industry has spent three decades telling itself that speed is the only metric that matters. Move fast and break things. But Brockton showed us what happens when the thing that breaks is a boiler with 400 people standing above it. The question is not whether your systems will fail. They will. The question is whether, when they fail, anyone can explain why -- and whether the cost of that failure sits on your balance sheet or on the bodies of the people your systems were supposed to serve.
The zero baseline is not zero. The spreadsheet is not risk. The architecture nobody can explain to an insurer is not an asset. It is a liability, accumulating silently, waiting for its Brockton moment.
Hartford Steam Boiler understood this in 1866. Zachariah Allen understood it in 1835. Lloyd's understood it in 1760. The pattern is old enough to be beyond dispute. The only industry still pretending it does not apply is ours.
That pretence is about to end. The question is whether it ends because we chose to act, or because the next explosion chose for us.
(Views in this article are my own.)