Insurance Cybersecurity Challenges
Insurance carriers, brokers, and agencies sit on vast troves of personal, financial, and health information, exchanged constantly across a distributed network of agents and third parties. That combination makes the sector a magnet for data theft, business email compromise, and ransomware. This page outlines the threats facing insurance organizations and the endpoint-centered defenses that address them, as part of our industry security coverage.
Why Insurers Are Targeted
Few industries concentrate as much sensitive data as insurance. Applications and claims contain identity, financial, and often health details for millions of policyholders — a one-stop source for fraud. The industry’s reliance on independent agents, brokers, and third-party administrators multiplies the number of endpoints that touch that data.
- Business email compromise and wire fraud. Premium payments, claims disbursements, and settlement transfers make insurers a prime target for business email compromise.
- Ransomware and data extortion. Attackers encrypt claims systems and threaten to leak policyholder data — see ransomware protection and response.

Key Challenges
Concentrated Sensitive Data
Policies and claims combine PII, financial data, and frequently PHI, giving attackers everything needed for identity theft in one place.
Distributed Agent and Broker Networks
Independent agents and third-party administrators access carrier systems from endpoints the carrier does not fully control.
Legacy Core Systems
Policy administration and claims platforms are often decades old and difficult to secure or replace.
Claims and Payment Fraud
Attackers exploit both technical weaknesses and process gaps to redirect payments or file fraudulent claims.
Third-Party and Vendor Risk
Reinsurers, adjusters, and technology vendors extend the data footprint well beyond the carrier’s own walls.
Compliance and Regulatory Context
Insurance security is shaped by a growing set of state and federal rules:
- NAIC Insurance Data Security Model Law has been adopted by many states, requiring a formal information-security program and incident response.
- NY DFS 500 sets detailed cybersecurity requirements for entities operating in New York, influencing standards nationwide.
- GLBA governs the protection of customers’ nonpublic financial information, and health insurers also handle PHI under HIPAA.
- A SOC 2 attestation and our compliance consulting help demonstrate and align these obligations.
Protection Strategies
- Deploy endpoint detection and response (EDR) across carrier, agent, and remote devices.
- Add out-of-band verification for changes to payment or banking instructions to stop wire fraud.
- Enforce multi-factor authentication and privileged access management on core and email systems.
- Apply least-privilege access for agents and third parties, with strong onboarding and offboarding.
- Encrypt policyholder data at rest and in transit.
- Maintain a tested incident response plan and add managed detection and response with 24/7 monitoring.
Frequently Asked Questions
What cybersecurity regulations apply to insurance companies?
Many states have adopted the NAIC Insurance Data Security Model Law, New York enforces NY DFS 500, GLBA governs financial data, and HIPAA applies to health insurers.
Why is business email compromise a major insurance threat?
Insurers move large payments for premiums, claims, and settlements, so attackers hijack email to redirect those funds — often without deploying any malware.
How do you secure independent agents and brokers?
Endpoint protection, multi-factor authentication, least-privilege access, and monitoring reduce the risk introduced by agents connecting from devices the carrier does not directly manage.
Does endpoint security help meet NY DFS 500 and NAIC requirements?
Yes. EDR, access controls, encryption, monitoring, and incident response map directly to the core requirements of both frameworks.
Protect policyholder data and payment integrity. Related sectors include financial services and healthcare. Request a security consultation for your organization.