Five exposures, rated and matched to a control
This is the shape of the register we usually hand back after an insurance assessment. Yours will differ in the detail, rarely in the categories.
Policyholder data at rest
Medical histories, financial details and identity documents held for the life of the policy and years beyond it.
Data classification, database security and leakage prevention around the records themselves.
Broker and agent access
Hundreds of external users reaching quotation and policy systems from devices you do not manage.
Brokered access with least privilege, device posture checks and full session recording for third parties.
Claims fraud and manipulation
Business logic in claims and quotation systems abused rather than broken, which no signature detects.
Application testing focused on logic and authorisation, plus monitoring for anomalous account behaviour.
Legacy core systems
Policy administration platforms that cannot be patched on anyone else’s schedule.
Compensating controls: segmentation, virtual patching and monitoring around the system rather than inside it.
Regulatory exposure
Data protection law, central bank requirements and the reporting obligations that follow a breach.
A live risk register, defined incident reporting and evidence maintained continuously.
Usually the first three engagements
Risk assessment
Turn the register above into your register, with owners, ratings and a funded plan.
Data classification
You cannot protect policyholder data selectively until you know where it is.
Managed SOC
Monitoring for a team that does not have analysts on a night shift.
