Governance and ICT risk management
Effective cybersecurity in an insurance company starts with governance. The following items should be completed or planned for 2026.
Board and accountability: designated board member responsible for cybersecurity, regular (minimum quarterly) ICT security status reporting to the board, board-approved ICT risk management framework compliant with DORA, cybersecurity budget adequate to the risk profile.
Policies and procedures: current information security policy, data classification policy covering medical data, policies, and claims, access management policy (principle of least privilege), incident management policy with escalation procedures, business continuity and disaster recovery policy, ICT vendor risk management policy.
ICT risk register: identified and assessed risks for all critical systems (core insurance, claims management, broker integrations), regular register reviews and updates (minimum semi-annually), mitigation plans for high and critical risk levels.
Infrastructure and network protection
The insurer’s network infrastructure requires multi-layered protection.
Network segmentation: core insurance system networks isolated from the office network, separate segments for claims management, underwriting, and customer portal systems, microsegmentation limiting lateral movement, DMZ for externally exposed systems (portals, broker APIs).
Perimeter security: next-generation firewall (NGFW) with SSL/TLS traffic inspection, IDS/IPS system with financial sector-specific rules, Web Application Firewall (WAF) for customer and agent portals, DDoS protection for publicly accessible systems.
Vulnerability management: regular vulnerability scanning (minimum monthly), patching critical vulnerabilities within 24-48 hours, operating system and application hardening, shadow IT inventory and elimination.
Endpoint and identity protection
Endpoints and identities are the most common attack vectors against insurers.
Endpoint protection: EDR (Endpoint Detection and Response) on all workstations and servers, anti-malware with heuristic and behavioral analysis mechanisms, application control (whitelisting) on critical stations, disk encryption on all devices, Mobile Device Management (MDM) for field employees.
Identity management: MFA (multi-factor authentication) for all users, SSO (Single Sign-On) with centralized management, Privileged Access Management (PAM) for administrative accounts, regular privilege reviews (minimum quarterly), automatic disabling of inactive accounts (after 30 days of inactivity).
Employee training: regular cybersecurity training (minimum twice yearly), phishing simulations (minimum quarterly), dedicated training for claims and underwriting departments (due to specific threats), board-level cybersecurity training (NIS2 requirement).
Data protection and privacy
Insurance data requires special protection due to its sensitivity.
Data Loss Prevention: DLP across three layers — network, endpoint, cloud, DLP policies specific to medical data, policies, and claims, monitoring data transfer to external systems (including broker APIs), automatic encryption of sensitive data in transit and at rest.
GDPR compliance: processing activity records covering all insurance data categories, Data Protection Impact Assessment (DPIA) for systems processing medical data, procedures for data subject rights (access, deletion, portability), data processing agreements with all processors, appointed Data Protection Officer.
Encryption: data at rest encryption in databases (AES-256), communication encryption (TLS 1.2+ for all connections), backup encryption, cryptographic key management (HSM or cloud KMS).
Monitoring and incident response
The ability to detect and respond to incidents is crucial for DORA compliance.
Security Operations Center: SOC operating 24/7/365 (in-house or managed), SIEM integrating logs from all critical systems, correlation rules specific to the insurance sector, SOAR automating standard response procedures, financial sector threat intelligence feeds.
Incident response: tested incident response plan (tests minimum annually), defined roles and responsibilities in the IR team, escalation procedures compliant with DORA requirements (4h/72h/1m), regulator notification procedures, crisis communication — templates and procedures, forensics firm retainer for serious incidents.
Business continuity: business continuity plan (BCP) for cyberattack scenarios, disaster recovery plan (DRP) with regular tests, backup following the 3-2-1-1 rule (3 copies, 2 media, 1 off-site, 1 immutable), RTO and RPO defined for all critical systems.
Digital resilience testing
DORA requires regular resilience testing — the following tests should be planned and executed.
Penetration testing: infrastructure penetration tests (minimum annually), web application penetration tests (portals, APIs) — minimum annually, broker API penetration tests — after every significant change, red team exercises (for insurers designated as significant entities), TLPT (Threat-Led Penetration Testing) every 3 years (for significant entities).
Other tests: vulnerability assessments — minimum monthly, network security tests — minimum quarterly, performance tests for DDoS resilience, scenario-based tests (tabletop exercises) — minimum twice yearly, backup restoration tests — minimum quarterly, incident response plan tests — minimum annually.
Documentation: all test results documented and archived, remediation plans for identified gaps, remediation status tracking, test results reporting to the board and supervisory authority (on request).
ICT vendor management
The insurance sector is heavily dependent on vendors — managing this risk is a DORA requirement.
Inventory and assessment: up-to-date register of all ICT vendor agreements, vendor classification (critical, important, standard), security due diligence before contract signing, regular security audits of critical vendors (minimum annually).
Contracts and SLAs: security clauses in vendor contracts, right to audit vendor security, vendor incident reporting obligations, SLAs covering security aspects, exit clauses (exit strategy for vendor changes).
Continuous monitoring: security posture monitoring of critical vendors, tracking vulnerabilities in vendor products, continuity plans for vendor failure, regular verification of vendor certifications (ISO 27001, SOC 2).
How nFlo helps complete the checklist
nFlo offers comprehensive support in completing the cybersecurity checklist for insurers. Our services cover all areas listed in this control list.
Assessment and gap analysis: we identify gaps in the current security posture against DORA, NIS2, and sector best practices. We design an implementation roadmap with action prioritization.
Implementation: managed SOC 24/7 with insurance-specific rules, DLP across three layers, penetration testing and red team exercises, vulnerability management and hardening, vendor security audits.
Continuous improvement: monitoring and reporting, employee and board training, regular policy reviews and updates. With over 500 projects and 98% client retention, nFlo is a proven cybersecurity partner for the insurance sector.
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Related topics
See also:
Related terms
Our services
- NIS2 for hospitals — implementation and compliance
- NIS2 for local government — municipalities implementation
