Englishالعربية Soon
Under attack?
Insurance

You hold the most personal data of any sector outside healthcare, for decades.

Insurers accumulate medical histories, financial records and identity documents, then keep them for the life of the policy. The exposure compounds every year, and the systems holding it are often the oldest in the building.

Why insurers are targeted
Rich personal and medical data
Long retention periods by obligation
Large external broker networks
Legacy core platforms
High cost of service interruption
Exposure register

Five exposures, rated and matched to a control

This is the shape of the register we usually hand back after an insurance assessment. Yours will differ in the detail, rarely in the categories.

Policyholder data at rest

Medical histories, financial details and identity documents held for the life of the policy and years beyond it.

High
Treatment

Data classification, database security and leakage prevention around the records themselves.

Broker and agent access

Hundreds of external users reaching quotation and policy systems from devices you do not manage.

High
Treatment

Brokered access with least privilege, device posture checks and full session recording for third parties.

Claims fraud and manipulation

Business logic in claims and quotation systems abused rather than broken, which no signature detects.

Medium
Treatment

Application testing focused on logic and authorisation, plus monitoring for anomalous account behaviour.

Legacy core systems

Policy administration platforms that cannot be patched on anyone else’s schedule.

High
Treatment

Compensating controls: segmentation, virtual patching and monitoring around the system rather than inside it.

Regulatory exposure

Data protection law, central bank requirements and the reporting obligations that follow a breach.

Medium
Treatment

A live risk register, defined incident reporting and evidence maintained continuously.

Outcomes

What the programme is actually for

Three outcomes an insurance board can hold us to, none of which are a dashboard.

01

Data stays where it belongs

Policyholder records classified, monitored and prevented from leaving by any of the routes that normally carry them out.

02

Access is provable

Every privileged and third-party session brokered, recorded and searchable, which answers the regulator and the internal auditor at once.

03

Interruption is survivable

Detection, containment and a rehearsed response, so a claims platform outage is measured in hours rather than trust.

Related

Usually the first three engagements

Risk assessment

Turn the register above into your register, with owners, ratings and a funded plan.

Data classification

You cannot protect policyholder data selectively until you know where it is.

Managed SOC

Monitoring for a team that does not have analysts on a night shift.

Get the register before the incident writes it for you.

A scoping call, then an assessment that produces a rated register and a treatment plan your board can approve.