AND-E is a motor and mobility insurance provider with a sprawling attack surface. Operating across 30+ markets in Europe and Africa, the company manages over 8 million active motor policies. That scale means protecting vast amounts of sensitive data - from standard PII in life and private motor insurance to the 14 billion kilometers of driving data collected through its insurethebox telematics platform. As Toyota's strategic insurance partner and centre of excellence since 1999, AND-E's infrastructure underpins products spanning commercial fleet coverage and specialised services for Japanese businesses operating internationally.
The technical threat model here is multidimensional. Securing telematics pipelines - real-time vehicle data ingestion, driver behavior analytics, and the privacy implications that follow - is a core challenge. The company also runs the AIOI R&D Lab in Oxford, focused on cutting-edge AI research, which introduces distinct security considerations around model integrity, data poisoning, and research IP protection. With over 1,000 colleagues, the operation is large enough to demand mature security engineering across cloud infrastructure, application security, and data governance, but specialized enough in insurtech and automotive that generic playbooks won't suffice.
For cybersecurity professionals, the draw is the intersection of regulated financial services, mobility IoT, and applied AI - domains where the stakes around data integrity and availability are tangible. The company's positioning within Toyota's broader ambitions to build sustainable mobility ecosystems adds layers of strategic complexity. This isn't a startup with a flat network and an S3 bucket; it's a multinational insurer whose core product increasingly runs on data pipelines and machine learning models that need defending at every layer.






