Evolve MGA
π’ Evolve MGA is a California-incorporated managing general agent specializing in cyber liability and technology E&O for SMEs with cyber risk exposures up to $250 million, distributing through over 3,000 retail broking partners across all 50 U.S. states. Founded in 2015 by brothers Michael and Patrick Costello β described as fourth-generation insurance professionals β the firm was acquired by Nexus Underwriting in July 2023 and subsequently became part of Brown & Brown, Inc. through the Kentro Capital acquisition completed in October 2023. The operating legal entity is Evolve Cyber Insurance Services LLC, incorporated in California.
π Scale and financials. At the time of acquisition, Evolve reported approximately 6,000 policyholders and over 3,000 retail broking partners. A 2020 trade profile references a team of roughly 30 cyber specialists. No venture funding rounds were identified; the sole disclosed capital event is the Nexus acquisition, whose financial terms were not published. Statutory financial statements and GWP figures are not publicly available.
π‘οΈ Coverage architecture. The post-acquisition Evolved NexGen cyber policy, supported by Lloyd's of London, covers first-party breach response costs, cybercrime and social engineering, business interruption with a six-hour waiting period, reputational loss over 12 months, and hardware replacement. Third-party insuring clauses include network security liability, privacy liability, regulatory penalties, PCI liability, and media liability. The historical EVO4.0 specimen shows claims-made structural features including an unlimited retroactive date and an optional extended reporting period.
π³ Cybercrime sublimits. The EVO4.0 specimen provides granular sublimits including funds transfer fraud at $250,000, theft of funds held in escrow at $250,000, extortion at $3,000,000, corporate identity theft at $250,000, telephone hacking at $250,000, and push payment fraud at $50,000. The current product page emphasizes social engineering, invoice manipulation, impersonation fraud, and electronic theft of third-party funds as key covered perils.
π¦ Capacity and panel. The current NexGen policy is marketed as Lloyd's-supported across all 50 states. The 2021 EVO4.0 specimen evidences a co-insurance panel spanning Lloyd's syndicates with percentage participations alongside non-Lloyd's insurers Zurich Insurance plc, HDI Global Specialty SE, XL Catlin Insurance Company UK Limited (now AXA XL), and Fidelis Underwriting Limited. CFC Underwriting Limited served as coverholder and cyber incident manager under a Lloyd's delegated authority binding agreement.
π± Insurtech services. Evolve supplements underwriting with a proprietary mobile app offering 24/7 dark web monitoring, network deep scanning, phishing simulation campaigns, and instant claims notification. A Data Breach Calculator built on NetDiligence/eRiskHub infrastructure supports risk education. Vendor partnerships with Upfort, Avail, BlackFog, ControlCase, eSentire, and Coro form a curated cybersecurity marketplace for policyholders.
π Distribution model. Evolve operates a direct-to-retail broker model, with its production team historically active in agency education through training, marketing materials, and in-person seminars. The Florida Association of Insurance Agents partnered with Evolve to distribute the EVO 3.0 policy to its membership. The company's licensing approach combines a California insurance license with surplus-lines placements and Lloyd's delegated authority via CFC as coverholder.
π Competitive position. Evolve's differentiators center on coverage breadth β including unlimited reinstatement on first-party coverage, breach response costs outside the limit, and full prior acts β rather than the proprietary security telemetry emphasized by full-stack competitors such as Coalition and At-Bay. Cowbell Cyber and Corvus Insurance emphasize analytics-driven underwriting, while Evolve's strengths lean toward broker education, claims ecosystem design, and cybercrime coverage depth. The historical CFC relationship positions Evolve structurally close to CFC's delegated-authority-plus-managed-response archetype.
β οΈ Risk factors. Key risks include Lloyd's capacity concentration and potential appetite shifts, operational dependency on third-party claims and vendor ecosystems, systemic cyber aggregation exposure from a large SME portfolio, and key-person continuity risk following co-founder Patrick Costello's departure in late 2025. Multi-state licensing confirmation and administrative action history were not located in accessible regulator registers.
π§© Strategic outlook. The Nexus acquisition and Kentro integration into Brown & Brown signal a platform strategy aimed at consolidated specialty underwriting and cross-geographic distribution leverage. Core pillars include defending retail broker scale, maintaining product differentiation through broad cybercrime coverage and claims response capabilities, and extending value through curated cybersecurity services and policyholder tooling. The three-time Cyber MGA of the Year distinction at the Advisen/Zywave awards underscores market recognition within the U.S. SME cyber segment.
The following sections provide further details.
Corporate and regulatory profile
π’ Legal entity. The operating legal entity is Evolve Cyber Insurance Services LLC, trading as Evolve MGA.[1][2] A Rhode Island Department of State annual report filed in 2021 lists California as the state of formation and San Rafael as the principal office address.[2] The company's website identifies San Diego as the headquarters location, while a 2023 acquisition announcement lists Dallas, Los Angeles, New York, and Texas as operating locations, indicating a multi-site U.S. footprint.[3][4]
π Year founded. Evolve MGA has specialized in underwriting SME cyber insurance since 2015.[3] A 2019 trade profile corroborates a circa-2015 launch and states the firm had doubled its book annually in the years following (historical claim, not independently validated).[5]
π‘οΈ Business model and licensing. Evolve MGA positions itself as a cyber-focused MGA with full underwriting authority, offering cyber liability and technology E&O products.[6] The company publishes a California insurance license number (0K40961) on its website.[4] A publicly filed 2021 surplus-lines policy document shows insurance effected through CFC Underwriting Limited as coverholder, with a binding authority structure tied to a Unique Market Reference, providing direct evidence of Lloyd's delegated authority distribution for at least part of the historical book.[1]
ποΈ Ownership and acquisition. Evolve MGA was acquired by Nexus Underwriting, with completion announced in July 2023.[3] At the time of announcement, Nexus was described as a wholly owned subsidiary of Kentro Capital Limited.[3] Brown & Brown, Inc. subsequently completed its acquisition of Kentro in October 2023, integrating Kentro into Brown & Brown Europe operations and placing Evolve MGA within a larger broker-controlled specialty platform.[7]
π Scale indicators. The acquisition announcement disclosed over 3,000 retail broking partners and approximately 6,000 policyholders, and stated that the acquisition introduced the Evolved NexGen cyber policy supported by Lloyd's of London across all 50 U.S. states.[3] The 2021 Rhode Island annual report lists Dan Carraher and Bryan Costello as managers of the entity.[2]
Leadership and governance
π₯ Founders. Brothers Michael Costello and Patrick Costello co-founded Evolve MGA and are described as fourth-generation insurance professionals.[3] A 2020 agent-association profile states Patrick obtained a property and casualty license in college, interned at Lloyd's, trained at ACE Group, earned the CPCU designation, and worked as a professional liability underwriter before focusing on cyber; Michael worked as a retail producer and received multi-year cyber specialty training at Lloyd's.[8]
ποΈ Underwriting philosophy. A 2019 trade interview quotes Patrick emphasizing wire transfer fraud and social engineering coverage while criticizing cyber policy "warranty statements" as a claims-denial risk; the same interview claims eight U.S. offices at the time and annual book doublings since 2015.[5] The acquisition announcement quotes Adam Kembrooke as CEO and President of Nexus Underwriting U.S. in connection with the transaction.[3]
β οΈ Leadership continuity. A 2025 public post from Patrick states it was his last day with the company, indicating at least one founder departure post-acquisition.[9]
Funding, ownership, and financial signals
π Ownership pathway. Evolve MGA was acquired by Nexus Underwriting in July 2023; Nexus was then owned by Kentro Capital Limited, which was subsequently acquired by Brown & Brown, Inc. in October 2023.[3][7] No venture rounds, valuations, or equity raises were identified in primary sources reviewed; the sole disclosed capital event is the acquisition, whose financial terms were not published.[3]
| Round | Date | Amount raised | Lead investor(s) | Post-money valuation | Cumulative funding |
|---|---|---|---|---|---|
| Acquired | July 2023 | β | Nexus Underwriting | β | β |
π Awards as commercial signal. Evolve has received multiple Advisen (Zywave) Cyber Risk Awards: "Cyber Newcomer of the Year" in 2019,[10] "Cyber Risk MGA" winner and Patrick as "Cyber Risk Industry Person of the Year β Americas" in 2021,[11] and "Cyber MGA of the Year" in 2022.[12] The acquisition announcement describes Evolve as a three-time Cyber MGA of the Year winner.[3]
| KPI | Most recent figure | Prior year |
|---|---|---|
| Gross Written Premium (GWP) | β | β |
| GWP growth rate (YoY) | β | β |
| Policy count (in force) | ~6,000 policyholders (July 2023) | β |
| Net loss ratio | β | β |
| Revenue | β | β |
| Net income / net loss | β | β |
| MGA commission rate (% of GWP) | β | β |
| Headcount | ~30 cyber specialists (2020) | β |
| GWP per employee | β | β |
Product suite and coverage analysis
π― Customer segments. Evolve MGA markets to SMEs with cyber risk exposures up to $250 million, with some classes up to $500 million, spanning a broad industry appetite including banks, credit unions, hospitals, physician practices, municipalities, local government, private equity, venture capital, insurance intermediaries, and various professional services.[6][4] This breadth suggests a generalist SME and lower mid-market underwriting posture rather than a narrow vertical specialization.
π Policy form and structure. Post-acquisition, Evolve offers the Evolved NexGen cyber policy supported by Lloyd's across all 50 states.[3] A publicly filed 2021 policy specimen references wording version "EVO4.0" and provides a cyber incident response line associated with CFC.[1] The historical specimen includes an unlimited retroactive date and an optional 12-month extended reporting period at 100% of applicable annualized premium, both typical claims-made structural elements.[1]
π First-party coverages. The EVO4.0 schedule includes cyber incident response sections for incident response costs, legal and regulatory costs, IT security and forensic costs, crisis communications, and privacy breach management costs, each at a $3,000,000 each-and-every-claim limit with varying deductibles, plus a $50,000 post-breach remediation sublimit.[1] The current product page lists 24/7 hotline support, breach costs, forensic costs, legal breach advice, and PR/crisis management as included features.[4]
π³ Cybercrime and social engineering. The current product page lists social engineering, invoice manipulation and impersonation fraud, electronic theft of third-party funds, theft of funds held in escrow, cyber extortion, and telephone hacking as covered perils.[4] The EVO4.0 specimen provides explicit sublimits including funds transfer fraud ($250,000), theft of funds held in escrow ($250,000), theft of personal funds ($250,000), extortion ($3,000,000), corporate identity theft ($250,000), telephone hacking ($250,000), push payment fraud ($50,000), and unauthorized use of computer resources ($250,000).[1]
ποΈ Business interruption and system failure. The current product page indicates business income loss with a stated six-hour waiting period, 12-month reputational loss coverage, supplemental extra expense, and "bricking" coverage.[4] The EVO4.0 schedule shows system damage and business interruption at $3,000,000 limits for system damage/rectification and income loss/extra expense, with a $1,000,000 sublimit for system failure; dependent business interruption at the same structure; reputational harm at $3,000,000; claim preparation costs at $25,000; and hardware replacement costs at $3,000,000.[1]
βοΈ Third-party coverages. Network security liability, privacy liability, regulatory penalties, and PCI liability are included per the current product page.[4] The EVO4.0 schedule shows these as aggregate-limit insuring clauses at $3,000,000 with a $5,000 deductible, alongside management liability, regulatory fines, and PCI fines/penalties/assessments.[1] Media liability and intellectual property rights infringement appear in the historical specimen within an aggregate-limit framework.[1]
π» Technology E&O. The EVO4.0 specimen explicitly states "Technology Errors and Omissions: NO COVER GIVEN" within that policy form.[1] Evolve separately markets a standalone Technology E&O product covering IT consulting, MSPs, SaaS, software development, telecom services, and related technology operations.[13]
Breach response and cybersecurity services
π¨ Historical claims ecosystem. The 2021 EVO4.0 specimen designates CFC Underwriting Limited as cyber incident manager and lists an approved claims panel including Wilson Elser, Context Security, Kivu Consulting, CrowdStrike, DOSarrest, Mullen Coughlin, and Clyde & Co, signaling a structured managed-response model.[1]
π Current claims handling. The current product page states rapid response claims handling through McDonald Hopkins and provides a dedicated incident email for NexGen policyholders.[4][6]
π Pre-bind services. Evolve provides risk vulnerability scans and reports and states that each policyholder receives a comprehensive risk assessment with their quote.[4]
π± Policyholder tooling. An in-house mobile app offers 24/7 dark web monitoring, network deep scanning, phishing simulation campaigns, free forensic expert advice, and instant claims notification.[14] The cyber product page links to a Data Breach Calculator hosted on eRiskHub infrastructure, based on a proprietary formula developed by NetDiligence and its insurance industry partners.[4][6]
π€ Vendor partnerships. The policyholder risk management page lists vendor relationships including Upfort (Upfort Shield trial and discount), Avail, BlackFog, ControlCase, eSentire, and Coro, forming a curated cybersecurity partner marketplace for policyholders.[15]
Distribution and geographic expansion
π Retail broker model. Evolve operates a direct-to-retail broker distribution architecture, with the acquisition announcement citing over 3,000 retail broking partners.[3] A 2020 association profile describes outreach through broker training, marketing materials, and in-person seminars, with a production team spending significant time in retail agencies.[8] The company's appointment page targets brokers directly, framing itself as "trusted by thousands of brokers across the country."[16]
πΊπΈ Geographic footprint. Evolve states nationwide U.S. availability across all 50 states for the post-acquisition NexGen policy supported by Lloyd's.[3] No evidence of non-U.S. underwriting operations under the Evolve MGA brand was found in reviewed sources.
π Licensing and authorization. The company publicly displays a California insurance license number and operates through national broker relationships.[4] The 2021 policy specimen is classified as surplus lines, with Patrick listed as surplus lines broker.[1] The policy certificate evidences a Lloyd's delegated authority pathway via CFC as coverholder.[1]
Carrier capacity and strategic partnerships
π¦ Current capacity. Post-acquisition, Evolve states the NexGen policy is supported by Lloyd's of London across all 50 U.S. states.[3]
π Historical panel. A 2021 surplus-lines tax filing page within the EVO4.0 specimen provides granular evidence of a co-insurance structure spanning Lloyd's syndicates (with percentage participations) and non-Lloyd's insurers including Zurich Insurance plc, HDI Global Specialty SE, XL Catlin Insurance Company UK Limited, and Fidelis Underwriting Limited.[1] CFC Underwriting Limited served as coverholder and cyber incident manager, a role typically paired with delegated underwriting authority and controlled claims response.[1]
π AXA relationship. The 2021 specimen lists XL Catlin Insurance Company UK Limited as an insurer participant; AXA XL identifies AXA XL Insurance Company UK Limited as formerly XL Catlin Insurance Company UK Limited, following AXA's completion of the XL Group acquisition in 2018.[1][17] No evidence was found of AXA Venture Partners, Kamet, or AXA-entity distribution partnerships, nor of founder employment ties to AXA.[8]
π€ Broker association partnerships. The Florida Association of Insurance Agents partnered with Evolve to provide coverage through the EVO 3.0 cyber policy to its members, listing specific coverage highlights as part of that arrangement.[18]
Competitive positioning
π§ Category positioning. Evolve is classified as a U.S. cyber-focused MGA built around retail broker distribution at scale, packaged coverage emphasizing broad first-party protection and cybercrime/social engineering scenarios, and bundled cybersecurity partner resources with an incident-response workflow.[3]
π‘ Claimed differentiators. Evolve's product comparison table highlights unlimited reinstatement on first-party coverage, breach response costs outside the limit, and full prior acts as distinguishing features.[4] The historical specimen corroborates these claims through its unlimited retroactive date, defined waiting period mechanics, and multiple cybercrime sublimits.[1] The partner ecosystem and mobile app reflect an insurtech-adjacent service layer.[14]
π Peer benchmarking. Full-stack cyber platforms such as Coalition and At-Bay typically emphasize proprietary security telemetry and continuous control monitoring as underwriting differentiators β capabilities not demonstrated as proprietary by Evolve in public materials.[4][19] Cowbell Cyber and Corvus Insurance are positioned around analytics-driven underwriting, whereas Evolve's strengths appear more anchored in broker education, claims ecosystem breadth, and coverage design.[19] Evolve's historical linkage to CFC as coverholder and incident manager implies structural proximity to CFC's operating model of delegated authority plus managed response.[1]
Risk factors
β‘ Capacity concentration. While the 2021 specimen evidences a diversified panel spanning Lloyd's and non-Lloyd's insurers, the current positioning emphasizes Lloyd's support; a shift in Lloyd's appetite, delegated authority performance management, or capacity retrenchment could create volatility in available limits, pricing, and underwriting guidelines.[3][1]
π§ Claims and response dependency. The EVO4.0 specimen shows a structured response model centered on CFC, while the current NexGen process references McDonald Hopkins, creating operational dependency on third-party claims and vendor ecosystems across policy generations.[1][4]
π Aggregation and systemic exposure. The portfolio is described as one of the larger SME cyber portfolios in the U.S., implying exposure to correlated events such as ransomware waves, supplier outages, and systemic vulnerabilities.[3]
π€ Key-person risk. Patrick Costello's public departure creates key-person continuity risk given the founder-led identity prominent in earlier materials and awards, raising questions about underwriting philosophy continuity and distribution retention.[9]
π Regulatory and compliance risk. Evolve publicly discloses a California insurance license number and operates across states including surplus lines placements; formal multi-state licensing confirmation and any administrative action history were not located in accessible regulator registers.[4]
Strategy and outlook
π§© M&A-driven trajectory. The acquisition by Nexus and subsequent integration of Kentro into Brown & Brown indicates a platform strategy oriented toward consolidated specialty underwriting capabilities and distribution leverage across geographies and lines.[3][7]
π’ Distribution scale. A core strategic pillar is building and defending retail broker distribution scale, anchored by the disclosed base of over 3,000 broking partners.[3]
π‘οΈ Product differentiation. Evolve seeks to maintain differentiation through broad cybercrime and first-party coverage features and claims response capabilities, complemented by curated cybersecurity services, policyholder tooling, and vendor partnerships.[4][15]
Company timeline
| Date | Event |
|---|---|
| 2015 | Specialized SME cyber underwriting operations begin.[3] |
| June 2019 | Advisen Cyber Risk Awards name Evolve MGA "Cyber Newcomer of the Year."[10] |
| June 2020 | Advisen Cyber Risk Awards recognize Evolve as "Cyber MGA of the Year" and name the founders as Cyber Person of the Year (USA).[19] |
| June 2021 | Advisen awards Evolve "Cyber Risk MGA" winner; Patrick named Industry Person of the Year (Americas).[11] |
| June 2022 | Zywave/Advisen announce Evolve MGA as "Cyber MGA of the Year" winner.[12] |
| July 2023 | Nexus Underwriting completes acquisition of Evolve; Evolved NexGen policy launched across all 50 U.S. states; scale disclosed at 3,000+ broking partners and approximately 6,000 policyholders.[3] |
| October 2023 | Brown & Brown completes acquisition of Kentro Capital Limited, integrating Kentro into Brown & Brown Europe operations.[7] |
| Late 2025 | Patrick Costello publicly announces departure from the company.[9] |
See also
References
- β 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 1.11 1.12 1.13 1.14 1.15 1.16 1.17 1.18 1.19 "Surplus-lines cyber policy document (specimen)" (PDF). Eglavator. Retrieved 2026-03-09.
- β 2.0 2.1 2.2 "Evolve Cyber Insurance Services LLC β Annual report" (PDF). Rhode Island Department of State. 2021. Retrieved 2026-03-09.
- β 3.00 3.01 3.02 3.03 3.04 3.05 3.06 3.07 3.08 3.09 3.10 3.11 3.12 3.13 3.14 3.15 3.16 3.17 3.18 3.19 3.20 "Evolve joins Nexus". Evolve MGA. July 2023. Retrieved 2026-03-09.
- β 4.00 4.01 4.02 4.03 4.04 4.05 4.06 4.07 4.08 4.09 4.10 4.11 4.12 4.13 4.14 4.15 "Cyber insurance". Evolve MGA. Retrieved 2026-03-09.
- β 5.0 5.1 "Evolve MGA β shedding some light on quality cyber insurance policies". Insurance Business Magazine. 2019. Retrieved 2026-03-09.
- β 6.0 6.1 6.2 6.3 "Evolve MGA β homepage". Evolve MGA. Retrieved 2026-03-09.
- β 7.0 7.1 7.2 7.3 "Brown & Brown, Inc. completes acquisition of Kentro Capital Limited". Brown & Brown, Inc. 10 October 2023. Retrieved 2026-03-09.
- β 8.0 8.1 8.2 "Evolve highlight". Professional Insurance Agents of Connecticut. 2020. Retrieved 2026-03-09.
- β 9.0 9.1 9.2 "Patrick Costello β departure announcement". LinkedIn. 2025. Retrieved 2026-03-09.
- β 10.0 10.1 "Advisen announces 2019 Cyber Risk Award winners". Advisen. June 2019. Retrieved 2026-03-09.
- β 11.0 11.1 "Advisen announces 2021 Cyber Risk Award winners". Advisen. June 2021. Retrieved 2026-03-09.
- β 12.0 12.1 "Zywave & Advisen announce 2022 Cyber Risk Award winners". PR Newswire / Zywave. June 2022. Retrieved 2026-03-09.
- β "Technology E&O". Evolve MGA. Retrieved 2026-03-09.
- β 14.0 14.1 "Evolve mobile app". Evolve MGA. Retrieved 2026-03-09.
- β 15.0 15.1 "Cybersecurity risk management tools for policyholders". Evolve MGA. Retrieved 2026-03-09.
- β "Get appointed". Evolve MGA. Retrieved 2026-03-09.
- β "Our companies". AXA XL. Retrieved 2026-03-09.
- β "Cyber coverage". Florida Association of Insurance Agents. Retrieved 2026-03-09.
- β 19.0 19.1 19.2 "Evolve wins Advisen Cyber Awards 2020". Evolve MGA. 2020. Retrieved 2026-03-09.