Skip to main content
Insurance

Insurance Cybersecurity

CERT-In empanelled cybersecurity services for Insurance organisations. 6,700+ assessments delivered since 2006.

6,700+
Assessments Delivered
1,000+
Enterprise Clients
150+
Security Professionals
Since 2006
Founded · CERT-In 2008

Challenges

Security challenges in Insurance

1

IRDAI cybersecurity and ISNP audit compliance for insurers and intermediaries

2

Policyholder PII at scale — health records, financial data, nominee information

3

Agent and broker portal security with thousands of external users

4

Legacy policy administration systems running on mainframe or unsupported platforms

5

Bancassurance and partner integrations multiplying the third-party risk surface

Trusted by

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The estate

An insurer's exposure is mostly other people's systems

Underwriting, distribution, servicing and claims each reach outside the organisation, and each carries policyholder data with them.

The distribution network

Agents, brokers, bancassurance partners and web aggregators — thousands of external users holding credentials into your systems, governed by a contract rather than by your HR process.

Policy administration

The core system of record, its integrations, and the change history on a policy — where an integrity failure is worth more to an attacker than a disclosure.

Claims

Assessment, settlement and payout, plus the document intake around them. This is the money path and it is the one fraud actually targets.

Underwriting inputs

Medical records, financial data and third-party enrichment. Some of the most sensitive data an insurer holds arrives here, from parties who are not your employees.

Policyholder digital

Portals and applications for buying, servicing and claiming — the surface reachable by anyone, and the one carrying the brand.

Third-party administrators

Health claims are frequently administered outside the insurer entirely, on infrastructure you do not run, holding data you remain answerable for.

The regime

Insurance has its own instrument, and it is not the banking one

Group security functions built around a banking programme routinely apply it here. The supervisor, the instrument and the expectations are all different.

IRDAI issued Information and Cyber Security Guidelines, 2026 on 6 April 2026 (IRDAI/GA&HR/CIR/MISC/51/4/2026), addressed to all insurers, insurance intermediaries and the IIB, replacing the guidelines issued in April 2023. That is the instrument to work from, and it reaches intermediaries as well as insurers — which matters, because the distribution network is where an insurer's user population actually lives. A programme designed against the RBI Directions or against SEBI CSCRF may be a strong programme and still be answering the wrong supervisor. Establish which instrument binds each entity in the group before standardising anything across it.

What we test

The four questions worth answering first

Ordered by what an assessment of an insurer most often finds, rather than by what a scope template lists.

QuestionWhy it comes first
What can one agent login reach? Distribution credentials are issued in volume to people outside the organisation, rarely rotated, and frequently able to retrieve policyholder records well beyond the agent's own book. Authorisation testing between agent contexts is the single highest-yield test on an insurer.
Can a claim be altered outside the claims workflow? Settlement is the money path. The controls that matter are the ones standing between a claim record and a payout instruction, including the exception handling that exists to fix stuck claims.
Where does policyholder data leave the perimeter? Third-party administrators, enrichment providers and document processors all hold it. The interface is yours to test even when their systems are not, and the contract is where the testing right has to already exist.
What does the policyholder app expose? It is the reachable-by-anyone surface, it is shipped as an artefact that can be examined offline, and it is the one that carries your brand into an app store where impersonations of it also live.

What can one agent login reach?

Why it comes first
Distribution credentials are issued in volume to people outside the organisation, rarely rotated, and frequently able to retrieve policyholder records well beyond the agent's own book. Authorisation testing between agent contexts is the single highest-yield test on an insurer.

Can a claim be altered outside the claims workflow?

Why it comes first
Settlement is the money path. The controls that matter are the ones standing between a claim record and a payout instruction, including the exception handling that exists to fix stuck claims.

Where does policyholder data leave the perimeter?

Why it comes first
Third-party administrators, enrichment providers and document processors all hold it. The interface is yours to test even when their systems are not, and the contract is where the testing right has to already exist.

What does the policyholder app expose?

Why it comes first
It is the reachable-by-anyone surface, it is shipped as an artefact that can be examined offline, and it is the one that carries your brand into an app store where impersonations of it also live.

Where this goes wrong

The intermediary is inside your perimeter and outside your control

Almost every insurer assessment produces the same finding in some form: an external user population, governed contractually, with access broader than anyone intended and lifecycle management that lags the commercial relationship. Agents leave and credentials persist. A broker's staff turn over without anyone telling the insurer. An aggregator integration issued for one purpose accumulates scope. None of it is exotic and none of it is caught by testing the perimeter, because these users are legitimately inside it. The test that finds it is authorisation testing between intermediary contexts, plus a hard look at what the joiner-mover-leaver process actually does when the leaver is not your employee.

Frequently Asked Questions

Our IT is largely outsourced. What is left for us to test?

The interfaces, the configuration you own inside somebody else's platform, and the access model across both. A hosted policy administration or claims platform is delivered by the vendor, but the tenant is yours: user entitlements, segregation between books, API credentials, report exposure and the integrations you enabled. Testing that is neither testing the vendor's product nor duplicating their assurance, and in practice it is where the findings are.

Does the IRDAI instrument reach our intermediaries too?

The 2026 guidelines are addressed to insurers, insurance intermediaries and the IIB, so intermediaries are named recipients rather than an extension of the insurer's obligation. That is worth checking against your own distribution arrangements, because the population of people holding access to your systems is largely made up of those intermediaries.

Secure Your Insurance Organisation

One scoping call to align on scope, methodology, and timing.

Request a Scoping Call →