Skip to content
Clear Infosec

Cybersecurity for Insurance Providers

Insurers hold large volumes of personal, financial and health-related data and depend on complex networks of agents, brokers and third-party administrators. As underwriters of cyber risk themselves, insurance organizations are expected to hold their own security to a high and demonstrable standard.

Request a scoping call

Security concerns in Insurance

Sensitive policyholder data exposure

Applications, claims and underwriting hold personal, financial and sometimes health data, making data protection and access control central concerns.

Agent, broker and portal risk

Distributed agent and broker access to systems and shared portals expands the attack surface and requires strong identity and authorization controls.

Fraud and claims manipulation

Attackers and insiders may target claims and payment workflows, so business logic testing and monitoring of sensitive transactions matter.

Third-party administrator and vendor risk

Reliance on TPAs, data enrichment and cloud services means vendor risk management and contractual safeguards are important.

Legacy systems and data sprawl

Long-lived policy and legacy platforms can accumulate sensitive data and unpatched components that require careful assessment.

Relevant regulations and frameworks

NYDFS 23 NYCRR 500 ↗: New York cybersecurity regulation that applies to covered entities including many insurers and licensees operating in New York.

NAIC Insurance Data Security Model Law ↗: A model law developed by the National Association of Insurance Commissioners that many US states have adopted to set data security requirements for insurers.

GDPR ↗: The EU General Data Protection Regulation applies to insurers handling EU personal data and imposes accountability and security obligations.

GLBA ↗: The US Gramm-Leach-Bliley Act sets privacy and safeguarding requirements for financial institutions, which can include insurance providers.

ISO 27001 ↗: An international information security management standard used by insurers to structure and evidence their control environment.

Assessments for Insurance

Ongoing protection

How Clear Infosec engages Insurance

Clear Infosec helps insurers and brokers assess and strengthen controls around policyholder data and distributed access, aligned to NYDFS, NAIC-based state requirements and GDPR where relevant, and provides ongoing detection and response. Programs are tailored to the organization's data footprint and partner ecosystem.

Related frameworks

Frequently asked questions

Which cybersecurity rules apply to US insurers?

Many US states have adopted requirements based on the NAIC Insurance Data Security Model Law, and insurers operating in New York may be subject to NYDFS 23 NYCRR 500. Applicable rules depend on the states in which you are licensed.

Do you help with vendor and third-party administrator risk?

Yes. We provide third-party risk management and audit support to help you assess TPAs, data providers and cloud vendors and address concentration and contractual security concerns.

How does GDPR affect an insurance company?

If you process personal data of individuals in the EU, GDPR imposes accountability, security and breach notification obligations. We help assess technical and organizational measures relevant to those obligations.

General information, not legal or regulatory advice. Requirements are set by the relevant authorities linked above.

Securing a insurance organization?

Clear Infosec delivers assessments, advisory, and managed security for regulated industries across five countries.

Contact us