Insurance Cybersecurity
CERT-In empanelled cybersecurity services for Insurance organisations. 6,700+ assessments delivered since 2006.
Challenges
Security challenges in Insurance
IRDAI cybersecurity and ISNP audit compliance for insurers and intermediaries
Policyholder PII at scale — health records, financial data, nominee information
Agent and broker portal security with thousands of external users
Legacy policy administration systems running on mainframe or unsupported platforms
Bancassurance and partner integrations multiplying the third-party risk surface
Trusted by
The estate
An insurer's exposure is mostly other people's systems
Underwriting, distribution, servicing and claims each reach outside the organisation, and each carries policyholder data with them.
The distribution network
Agents, brokers, bancassurance partners and web aggregators — thousands of external users holding credentials into your systems, governed by a contract rather than by your HR process.
Policy administration
The core system of record, its integrations, and the change history on a policy — where an integrity failure is worth more to an attacker than a disclosure.
Claims
Assessment, settlement and payout, plus the document intake around them. This is the money path and it is the one fraud actually targets.
Underwriting inputs
Medical records, financial data and third-party enrichment. Some of the most sensitive data an insurer holds arrives here, from parties who are not your employees.
Policyholder digital
Portals and applications for buying, servicing and claiming — the surface reachable by anyone, and the one carrying the brand.
Third-party administrators
Health claims are frequently administered outside the insurer entirely, on infrastructure you do not run, holding data you remain answerable for.
The regime
Insurance has its own instrument, and it is not the banking one
Group security functions built around a banking programme routinely apply it here. The supervisor, the instrument and the expectations are all different.
IRDAI issued Information and Cyber Security Guidelines, 2026 on 6 April 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026), addressed to all insurers, insurance intermediaries and the IIB, replacing the guidelines issued in April 2023. That is the instrument to work from, and it reaches intermediaries as well as insurers — which matters, because the distribution network is where an insurer's user population actually lives. A programme designed against the RBI Directions or against SEBI CSCRF may be a strong programme and still be answering the wrong supervisor. Establish which instrument binds each entity in the group before standardising anything across it.
What we test
The four questions worth answering first
Ordered by what an assessment of an insurer most often finds, rather than by what a scope template lists.
| Question | Why it comes first |
|---|---|
| What can one agent login reach? | Distribution credentials are issued in volume to people outside the organisation, rarely rotated, and frequently able to retrieve policyholder records well beyond the agent's own book. Authorisation testing between agent contexts is the single highest-yield test on an insurer. |
| Can a claim be altered outside the claims workflow? | Settlement is the money path. The controls that matter are the ones standing between a claim record and a payout instruction, including the exception handling that exists to fix stuck claims. |
| Where does policyholder data leave the perimeter? | Third-party administrators, enrichment providers and document processors all hold it. The interface is yours to test even when their systems are not, and the contract is where the testing right has to already exist. |
| What does the policyholder app expose? | It is the reachable-by-anyone surface, it is shipped as an artefact that can be examined offline, and it is the one that carries your brand into an app store where impersonations of it also live. |
What can one agent login reach?
- Why it comes first
- Distribution credentials are issued in volume to people outside the organisation, rarely rotated, and frequently able to retrieve policyholder records well beyond the agent's own book. Authorisation testing between agent contexts is the single highest-yield test on an insurer.
Can a claim be altered outside the claims workflow?
- Why it comes first
- Settlement is the money path. The controls that matter are the ones standing between a claim record and a payout instruction, including the exception handling that exists to fix stuck claims.
Where does policyholder data leave the perimeter?
- Why it comes first
- Third-party administrators, enrichment providers and document processors all hold it. The interface is yours to test even when their systems are not, and the contract is where the testing right has to already exist.
What does the policyholder app expose?
- Why it comes first
- It is the reachable-by-anyone surface, it is shipped as an artefact that can be examined offline, and it is the one that carries your brand into an app store where impersonations of it also live.
Where this goes wrong
The intermediary is inside your perimeter and outside your control
Almost every insurer assessment produces the same finding in some form: an external user population, governed contractually, with access broader than anyone intended and lifecycle management that lags the commercial relationship. Agents leave and credentials persist. A broker's staff turn over without anyone telling the insurer. An aggregator integration issued for one purpose accumulates scope. None of it is exotic and none of it is caught by testing the perimeter, because these users are legitimately inside it. The test that finds it is authorisation testing between intermediary contexts, plus a hard look at what the joiner-mover-leaver process actually does when the leaver is not your employee.
Services
Recommended Services for Insurance
IRDAI-aligned security services for insurers, brokers, and insuretech
Web Application Penetration Testing
Security testing for policy admin portals, claims processing systems, agent/broker platforms, and customer self-service portals.
Learn More →API Security Testing
IRDAI-mandated API security for policy issuance, claims, underwriting, and partner integration endpoints.
Learn More →Secure Code Review
Source code analysis for legacy policy admin systems and modern insuretech platforms undergoing digital transformation.
Learn More →Red Team Assessment
Adversary simulation targeting insurance-specific threat models — fraud detection bypass, claims manipulation, and agent portal abuse.
Learn More →Cloud Security Assessment
Security posture review for insurance core systems migration, agent portals, and customer engagement platforms on cloud.
Learn More →Compliance
Frameworks that matter to Insurance
Frequently Asked Questions
Our IT is largely outsourced. What is left for us to test?
The interfaces, the configuration you own inside somebody else's platform, and the access model across both. A hosted policy administration or claims platform is delivered by the vendor, but the tenant is yours: user entitlements, segregation between books, API credentials, report exposure and the integrations you enabled. Testing that is neither testing the vendor's product nor duplicating their assurance, and in practice it is where the findings are.
Does the IRDAI instrument reach our intermediaries too?
The 2026 guidelines are addressed to insurers, insurance intermediaries and the IIB, so intermediaries are named recipients rather than an extension of the insurer's obligation. That is worth checking against your own distribution arrangements, because the population of people holding access to your systems is largely made up of those intermediaries.
Secure Your Insurance Organisation
One scoping call to align on scope, methodology, and timing.
Request a Scoping Call →