THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for finance technology leaders, nominated by our subscribers and vetted by the Insurance CIO Outlook Editorial Board.



George is an experienced venture capitalist, management consultant, lecturer, and entrepreneur.
With over two decades of experience in the venture capital industry, George is a Managing Director at AV8 Ventures, an early-stage venture firm based in Silicon Valley. Prior to AV8, George worked at IBM Ventures where, as Managing Director, he headed up its strategic investment division.
Before IBM, George worked at ACM, an early stage venture fund, where he was General Partner, managing investments across big data infrastructure, cloud computing and analytics. George started his investment career at Apax Partners, a global venture firm where he invested in early-stage technology companies. Prior to Apax, Dr. Ugras was with McKinsey & Co. in New York advising Fortune 500 companies on growth strategy.
George has founded and run start-ups and served as an advisor and director to many venture-backed companies. He is also the founder of life sciences company CyteGen.
George has lectured on entrepreneurship at Carnegie Mellon, UCLA, and Stanford, as well as advising faculty on technology spin-offs at other universities. He also provided oversight on the Space Electronics Group at CalTech and NASA’s Jet Propulsion Laboratory.
Dr. Ugras holds a B.S. in Engineering Physics from Fairleigh Dickinson, a Ph.D. in Applied Physics from Yale, and was a research fellow at CalTech in Physics.
Through this article, Ugras emphasizes the importance of automating security tasks to reduce human error and integrate disconnected applications into identity management systems.
Over my 25-year career in venture capital, focusing on enterprise startups, I’ve encountered countless CIOs—some as potential or existing customers for one of our portfolio companies. During my time at IBM, leading the Venture Capital team, I gained additional exposure to CIOs through numerous partnerships. That experience broadened my perspective on their varied approaches.
“We do not touch customer data. Our system operates in controlled environments, often within the customer’s cloud infrastructure, ensuring data privacy and compliance.”
On one end of the spectrum, some CIOs perceive insurmountable risk at the mere mention of a startup—whether raised by a colleague or appearing on a vendor list. On the other, some CIOs actively seek innovation. These are the ones who explore the far corners of industry convention centers, stopping at smaller booths to uncover fresh solutions. They are willing to take calculated risks on smaller vendors to address challenges and future-proof their organizations. In my experience, these forward-thinking CIOs consistently rise to meet challenges and drive meaningful improvements in their organization’s performance over time.
When asked to contribute to this publication focused on the insurance industry, I thought it might be relevant to spotlight start-ups impacting IT organizations within the industry. These real-world examples will hopefully provide more insight than laying out a formulaic approach. To this end, I interviewed several CEOs of technology start-ups who have successfully partnered with CIOs in the insurance industry.
The goal is to provide the audience with pragmatic insights—offering guidance on maximizing the benefits of such collaborations while effectively managing the risks involved. I hope you will find it informative and valuable.
The first company we highlight is Cerby, which sits at the intersection of IT and cybersecurity. It addresses a topical issue, providing seamless application access while protecting critical information. I spoke to Bel Lepe, the CEO and founder of Cerby. Prior to founding Cerby, Bel led product teams at industry-leading start-ups. He began his career at Google after getting his Computer Science degree at Stanford University.
The Founding Story of Cerby
Vidal and I founded Cerby in 2020. A customer of a prior company flagged to us the problem of disconnected applications within their environment. This exploration of disconnected applications resulted in our building of the Cerby automation platform and our focus on Agents for the Last Mile of Identity.
Solving Security Challenges for CIOs in the Insurance Industry
We automate everyday security tasks often left to end users, such as enrolling in 2FA, removing user access and implementing manual compensating controls. This is particularly valuable for legacy systems and modern SaaS applications that lack support for identity access and governance standards. These apps rely heavily on human intervention to maintain their security posture, which we eliminate by automating these processes.
Leveraging AI to Strengthen Security
68 percent of all security incidents are due to the human element. We use AI to automate away this dependency on the human end user. Our system of agents can jump in at key moments and carry out tasks that would otherwise fall to the end user. These agents operate across browser-based, mobile-based and on-premise environments, ensuring an agent is ready to correct and get the job done everywhere the human element can be exploited.
Managing Privacy and Compliance
We do not touch customer data. Our system operates in controlled environments, often within the customer’s cloud infrastructure, ensuring data privacy and compliance.
Real-World Use Cases and Customer Impact
We partner with one of the largest insurance companies in the U.S. to secure their marketing stack, including their executives’ online social presence. We ensure that identities within their marketing stack—many of which do not natively support SSO—are connected to a central identity provider. This includes providing a complete audit trail of access and applying standard security controls like password rotation, session termination and 2FA enrollment. As a result, this part of the marketing stack, which would otherwise operate outside the corporate identity perimeter, is now fully managed and compliant.
The Role of GenAI in Scaling Security Solutions
GenAI has revolutionized our ability to scale. It allows us to rapidly expand our library of automated security tasks and the applications we can protect. This improvement in application coverage enables our customers to achieve 100% coverage across their environments.
Key Learnings for CIOs
Threat actors have increasingly targeted the weakest points in an organization’s identity perimeter. Applications that remain disconnected from identity management and governance systems. Regardless of the initial entry point, these unmanaged apps often become conduits for lateral movement within the corporate environment. Strengthening this weak link significantly enhances the overall security of your identity perimeter.