Skip to content
Cybersecurity

Insurance cybersecurity checklist 2026 — complete control list

Complete cybersecurity checklist for insurance companies in 2026. DORA, NIS2, data protection, SOC, penetration testing, vendor management.

Governance and ICT risk management

Effective cybersecurity in an insurance company starts with governance. The following items should be completed or planned for 2026.

Board and accountability: designated board member responsible for cybersecurity, regular (minimum quarterly) ICT security status reporting to the board, board-approved ICT risk management framework compliant with DORA, cybersecurity budget adequate to the risk profile.

Policies and procedures: current information security policy, data classification policy covering medical data, policies, and claims, access management policy (principle of least privilege), incident management policy with escalation procedures, business continuity and disaster recovery policy, ICT vendor risk management policy.

ICT risk register: identified and assessed risks for all critical systems (core insurance, claims management, broker integrations), regular register reviews and updates (minimum semi-annually), mitigation plans for high and critical risk levels.

Infrastructure and network protection

The insurer’s network infrastructure requires multi-layered protection.

Network segmentation: core insurance system networks isolated from the office network, separate segments for claims management, underwriting, and customer portal systems, microsegmentation limiting lateral movement, DMZ for externally exposed systems (portals, broker APIs).

Perimeter security: next-generation firewall (NGFW) with SSL/TLS traffic inspection, IDS/IPS system with financial sector-specific rules, Web Application Firewall (WAF) for customer and agent portals, DDoS protection for publicly accessible systems.

Vulnerability management: regular vulnerability scanning (minimum monthly), patching critical vulnerabilities within 24-48 hours, operating system and application hardening, shadow IT inventory and elimination.

Endpoint and identity protection

Endpoints and identities are the most common attack vectors against insurers.

Endpoint protection: EDR (Endpoint Detection and Response) on all workstations and servers, anti-malware with heuristic and behavioral analysis mechanisms, application control (whitelisting) on critical stations, disk encryption on all devices, Mobile Device Management (MDM) for field employees.

Identity management: MFA (multi-factor authentication) for all users, SSO (Single Sign-On) with centralized management, Privileged Access Management (PAM) for administrative accounts, regular privilege reviews (minimum quarterly), automatic disabling of inactive accounts (after 30 days of inactivity).

Employee training: regular cybersecurity training (minimum twice yearly), phishing simulations (minimum quarterly), dedicated training for claims and underwriting departments (due to specific threats), board-level cybersecurity training (NIS2 requirement).

Data protection and privacy

Insurance data requires special protection due to its sensitivity.

Data Loss Prevention: DLP across three layers — network, endpoint, cloud, DLP policies specific to medical data, policies, and claims, monitoring data transfer to external systems (including broker APIs), automatic encryption of sensitive data in transit and at rest.

GDPR compliance: processing activity records covering all insurance data categories, Data Protection Impact Assessment (DPIA) for systems processing medical data, procedures for data subject rights (access, deletion, portability), data processing agreements with all processors, appointed Data Protection Officer.

Encryption: data at rest encryption in databases (AES-256), communication encryption (TLS 1.2+ for all connections), backup encryption, cryptographic key management (HSM or cloud KMS).

Monitoring and incident response

The ability to detect and respond to incidents is crucial for DORA compliance.

Security Operations Center: SOC operating 24/7/365 (in-house or managed), SIEM integrating logs from all critical systems, correlation rules specific to the insurance sector, SOAR automating standard response procedures, financial sector threat intelligence feeds.

Incident response: tested incident response plan (tests minimum annually), defined roles and responsibilities in the IR team, escalation procedures compliant with DORA requirements (4h/72h/1m), regulator notification procedures, crisis communication — templates and procedures, forensics firm retainer for serious incidents.

Business continuity: business continuity plan (BCP) for cyberattack scenarios, disaster recovery plan (DRP) with regular tests, backup following the 3-2-1-1 rule (3 copies, 2 media, 1 off-site, 1 immutable), RTO and RPO defined for all critical systems.

Digital resilience testing

DORA requires regular resilience testing — the following tests should be planned and executed.

Penetration testing: infrastructure penetration tests (minimum annually), web application penetration tests (portals, APIs) — minimum annually, broker API penetration tests — after every significant change, red team exercises (for insurers designated as significant entities), TLPT (Threat-Led Penetration Testing) every 3 years (for significant entities).

Other tests: vulnerability assessments — minimum monthly, network security tests — minimum quarterly, performance tests for DDoS resilience, scenario-based tests (tabletop exercises) — minimum twice yearly, backup restoration tests — minimum quarterly, incident response plan tests — minimum annually.

Documentation: all test results documented and archived, remediation plans for identified gaps, remediation status tracking, test results reporting to the board and supervisory authority (on request).

ICT vendor management

The insurance sector is heavily dependent on vendors — managing this risk is a DORA requirement.

Inventory and assessment: up-to-date register of all ICT vendor agreements, vendor classification (critical, important, standard), security due diligence before contract signing, regular security audits of critical vendors (minimum annually).

Contracts and SLAs: security clauses in vendor contracts, right to audit vendor security, vendor incident reporting obligations, SLAs covering security aspects, exit clauses (exit strategy for vendor changes).

Continuous monitoring: security posture monitoring of critical vendors, tracking vulnerabilities in vendor products, continuity plans for vendor failure, regular verification of vendor certifications (ISO 27001, SOC 2).

How nFlo helps complete the checklist

nFlo offers comprehensive support in completing the cybersecurity checklist for insurers. Our services cover all areas listed in this control list.

Assessment and gap analysis: we identify gaps in the current security posture against DORA, NIS2, and sector best practices. We design an implementation roadmap with action prioritization.

Implementation: managed SOC 24/7 with insurance-specific rules, DLP across three layers, penetration testing and red team exercises, vulnerability management and hardening, vendor security audits.

Continuous improvement: monitoring and reporting, employee and board training, regular policy reviews and updates. With over 500 projects and 98% client retention, nFlo is a proven cybersecurity partner for the insurance sector.


Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:


See also:

Our services

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist