ONE Conference 2026: We Cannot Defeat AI Hackers Without Collaboration

Some thoughts from your Insurance Edge Editor Alastair Walker, after a few days in The Hague, at the ONE Conference, listening to views from politicians, Police, security agencies, cyber experts, supplier vendors and ethical hackers. Let’s get into it.

TAKEDOWNS ARE ONLY HALF THE STORY

Sitting in on the Dutch Police/Europol session describing how they accessed and then took down the Hansa dark web trading site, a kind of FB Marketplace for organised criminals, was illuminating. As the presentation went on I began to understand how a simple mistake by one of the players involved with running Hansa proved to be a physical back door into a network. A man transports his wife into the EU for medical treatment after a ski accident, because she doesn’t trust local hospitals. He’s arrested, phones seized and unlocked.

Incredibly, despite telling his fellow gangsters that he deletes all the logs from the Hansa site, he hasn’t. This proves to be a goldmine of data on transactions for Bitcoin, guns, gold, property, drugs – you name it. So Europol runs the site for a month, gathers more evidence on who is active, then takes Hansa down, places a “This site has been seized” notice on the home page.

That obviously creates mistrust, a touch of panic perhaps, as criminals realise they have been compromised.

Listening closely, I tried to think like a gangster and decide what to do next. Move assets, changes passwords, new burner phones, set up some new couriers/cuckoos in different locations, maybe move to a different nation myself. But in a digital world all that chess play leaves a trace here and there. Europol can keep gathering data, joining the dots, building spreadsheets, looking for connections. We really are in a connected world now and unless your criminal enterprise is selling bows and arrows to remote tribes in the Amazon, you’re going to pop up on a dataset or Encrochat somewhere.

So the takedown is just the start of an investigation, the moment when you clean the whiteboard and start to stick photos and add names to your new target network. To build a case, you need international collabs. Not just from fellow Police departments, but agencies like the FBI, CIA, Mossad, plus govt departments that pay benefits, allocate housing, driving licences, ID cards, passports etc.

Then you could add insurers, especially brokers or Specie firms, who often cover HNW individuals for private healthcare ( yeah a “hunting accident” bullet wound might need urgent care ) luxury Hublot watches, holiday villas, Bugattis, private aircraft, auction bought artworks and so on.

I’m not saying that insurers do that kind of co-operation, but just speculating that it MIGHT be a good idea. In certain cases. Where the correct warrants or paperwork were approved. Adding layers of data from collaborative teamwork can track and trace cyber hackers, particularly ransomware specialists because they HAVE to spend that coin somewhere. In short collabs at these levels need some kind of tweaks to existing privacy laws, so perhaps the answer is a kind of automated, anonymised tracking of unusual movements, purchases, claims etc. This is a matter for politicians and law enforcement agencies, plus regulatory bodies, to work out a new paradigm on data sharing, utilising AI analytics.

See where I’m going? Good, let’s move onto the grey, claggy water of the North Sea, there’s more urgent thinking ahead to be done.

THE NETWORK BENEATH THE WAVES SUSTAINS US ALL

Most modern States are really just a series of pipes and cables. Without electricity, gas, oil, sewers, fibre data cables, tunnels and even field drainage pipes, civilisation would collapse in a short period. Most readers know about Nord Stream gas pipelines exploding, or maybe Red Sea data cables being cut a few years back. But did you know that six nations are working together in the North Sea to make vital ports, energy pipelines and electricity cables more secure? No, me neither, the project is called SeaSEC and a presentation explained more details;

SeaSec has a test zone in the North Sea, just off the coast of the Netherlands, where various new tech can be put into real world scenarios, like defending ships, wind farms or gas/oil rigs from cyber, or physical attacks. Indeed ONE Conference delegates learned that MODAT had ethically hacked several commercial wind farms and could have taken control of the turbines. Speeding them up, turning them to face the wrong way so electricity levels dropped, or potentially causing a blackout by shutting them. MODAT found themselves looking at buttons marked START and STOP. Not good. One more nugget from MODAT for you; when they checked how old the PC network was from one wind farm they found Siemens computers being used way past their projected lifespan.

Yep, I nearly bought a Siemens phone in 90s too. Pretty cool.

SeaSEC have a challenge week every year, bringing together tech companies who want to try out the latest gadgets which can venture undersea and try to make infrastructure secure, or detect unknown actors nearby. If a ship turns off its GPS tracker (MMSI number) near a cable or pipe then you want a quicker response that sending some guys out in a small boat or fast Rib. Some of these gadgets are autonomous by the way, so the same terrain recognition that is being developed for cars in California could be used to map the seabed in real time. Well maybe, as a SeaSEC spokesperson noted, the North Sea is pretty much like mudpie soup, in fact one gadget designed to “walk” on the seabed got stuck in the mud.

In another session I learned about a cyber attack from a harbour. A ship has its MMSI signal jammed, which is annoying when you are waiting for a Pilot to arrive and guide you safely into port. It took the authorities a week to figure out where the jamming signal was coming from. No, not a Russian satellite hovering overhead, but a cheap e-scooter parked dockside in the cycle bay. Something that looked part of the everyday street furniture was literally stopping a cargo ship in its tracks. On a sidenote, a fellow press team member speculated that the jamming device could be adapted from the sort of “field zone” tech used in hired e-bikes, so you can’t just ride home on it. A tweaked version could tell the ship it couldn’t function outside of its “home zone” if you see what we mean?

Hey, we are just media types second guessing this stuff, so who knows how they did the e-scooter jamming thing. Maybe old school pedal cycles are safer? This is how nice The Hague was in October by the way. Beautiful.

MULTI AGENCY, MULTI CORPORATE APPROACH

But all this shows what SeaSEC, and other security agencies are up against. State actors trying to wage asymmetric warfare, ransomware gangs looking to get rich, or a clusterf*ck of Simpson Comic Book Store guys who love to hack at 2am because they’ve run out of cheesy potato chips and feel grouchy. This diversity of hacking and attacking is out there, constantly innovating and utilising Agentic AI to ramp up the speed of their attacks.

The key theme of the ONE Conference was collaboration, working together to prevent incidents

and ultimately secure modern society from being picked apart, one data cable at a time. SeaSEC would like the UK to join and I agree, we should. It’s a vital investment and would boost expertise in dozens of UK GOV departments.

But let’s imagine a deeper partnership; Lloyd’s of London remains one of the biggest global insurers of vessels, cargo, port infrastructure and big stuff like Wind Farms, pipelines and power stations. There is so much that all underwriters in Cyber, Commercial, Marine and Cat events could learn from getting involved with SeaSEC, MODAT, DIVD and of course, attending the ONE Conference in 2027. Test your underwriting and renewal platforms with DIVD and MODAT for weaknesses, get your toes wet in the North Sea, work with Europol via the IFB/City of London Police – it’s all good baby.

No, I’m not on commission promoting the event, I just want the lights to stay on, gas and oil to flow and charge my devices when I need to. Regardless of the angst surrounding Brexit, this protection of our online systems, the physical infrastructure that connects us all, is reason enough to collaborate, invest time and money, plus share data and learn valuable lessons for the future.

A spokesperson from ethical hacking club DIVD summed things up for me;

“We have get beyond the data breach shaming, the blame game. Learn hard lessons from the trauma of being hacked. We must admit every platform or site has weak points…and accept that sometimes hacks are a betrayal from within our own networks. Move on and work together to make systems more secure. Only way forwards.”

Do you agree? Like and share if you can.

 

 

About alastair walker 21005 Articles
20 years experience as a journalist and magazine editor. I'm your contact for press releases, events, news and commercial opportunities at Insurance-Edge.Net

Be the first to comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.