Insurance Information Cybersecurity Programs: Building a Defensible Cybersecurity Program Under Insurance Regulatory Expectations
Live CPE Webinar • Tuesday, October 27, 2026
Insurance organizations hold exactly the kind of information cybercriminals want.
They may possess:
Personally identifiable information
Financial information
Claims information
Medical and health-related information
Driver information
Policyholder records
Banking and payment information
Employee information
Producer information
At the same time, insurers increasingly rely on interconnected systems, cloud services, third-party administrators, vendors, agents, artificial intelligence, and other technology providers.
That combination creates significant cybersecurity exposure.
For insurance organizations, cybersecurity is no longer simply an IT issue.
It is a governance, compliance, internal control, operational resilience, third-party risk, and regulatory issue.
Corporate Compliance Seminars' Insurance Information Cybersecurity Programs CPE event is designed to help insurance professionals understand how to develop, operate, assess, and improve an information-security program appropriate for the insurance regulatory environment.
The next program is scheduled for Tuesday, October 27, 2026.
Cybersecurity Is an Enterprise Risk
A common mistake is assigning cybersecurity entirely to Information Technology.
IT certainly plays a major role.
But cybersecurity failures can affect:
Operations
Compliance
Finance
Claims
Underwriting
Customer service
Reputation
Regulatory relationships
A ransomware attack, for example, may not merely shut down servers.
It could prevent an insurer from:
Processing claims
Accessing policy information
Communicating with policyholders
Paying vendors
Performing financial reporting
Meeting regulatory obligations
The appropriate question for management is therefore not:
“Does IT have cybersecurity covered?”
It is:
“Does the organization have an effective system for identifying, assessing, controlling, monitoring, and responding to information-security risk?”
That is an enterprise-risk-management question.
Start With a Cybersecurity Risk Assessment
A strong cybersecurity program should begin with risk.
Before selecting controls, management needs to understand:
What information it possesses
Where that information resides
Which systems process it
Who can access it
Which third parties receive it
Which threats could affect it
What the consequences of compromise would be
The logic should be:
Information Assets
↓
Threats
↓
Vulnerabilities
↓
Risk
↓
Controls
↓
Monitoring
↓
Response
Without a meaningful risk assessment, organizations can spend substantial amounts of money on cybersecurity while failing to address their most important exposures.
Know Where the Sensitive Information Is
An insurance company cannot protect information it does not know it has.
Sensitive information may exist in:
Core insurance applications
Claims systems
Underwriting applications
Email
Shared drives
Cloud applications
Laptops
Mobile devices
Third-party platforms
Organizations need to understand the information lifecycle:
Collection → Use → Storage → Transmission → Retention → Destruction
Each stage creates different risks.
That is why information governance and cybersecurity increasingly need to operate together.
Access Control Is One of the Fundamental Defenses
A basic cybersecurity question is:
Who can access what?
Access should generally reflect business need.
Important control areas include:
User provisioning
Authentication
Multifactor authentication
Privileged access
Transfers
Terminations
Periodic access reviews
Segregation of duties
The organization should also ask whether access that was appropriate when initially granted remains appropriate today.
An employee who changes responsibilities may accumulate access over time.
That can create unnecessary exposure.
Privileged Access Creates Concentrated Risk
Administrators and other privileged users may possess extensive capabilities.
Depending on the environment, they might be able to:
Create users
Reset passwords
Change configurations
Access sensitive information
Modify applications
Change security settings
Those capabilities require stronger controls.
Management should understand:
Who has privileged access
Why they need it
Who approved it
Whether activities are monitored
How access is periodically reviewed
How unnecessary privileges are removed
Privileged access should never become invisible simply because it belongs to technical personnel.
Third-Party Risk Is Insurance Cybersecurity Risk
Insurance organizations frequently depend on external organizations including:
Claims administrators
Producers
Brokers
Cloud service providers
Data processors
Software vendors
Consultants
Call centers
Payment processors
That means the organization's data-security perimeter extends beyond its own network.
A cybersecurity program should therefore address:
Vendor selection
↓
Due diligence
↓
Contract requirements
↓
Security expectations
↓
Ongoing monitoring
↓
Incident notification
↓
Termination
The question is not merely:
“Does the vendor have a cybersecurity policy?”
The better question is:
“What evidence gives us reasonable confidence that this third party is appropriately protecting our information?”
Cybersecurity Governance Starts at the Top
Technology teams can implement security controls.
They cannot alone establish enterprise governance.
Senior management and appropriate governance bodies should understand:
Significant cyber risks
Major incidents
Material control weaknesses
Third-party exposure
Remediation progress
Resource needs
Effective governance requires useful information.
A dashboard containing 75 technical statistics may impress people without helping them govern.
Leadership needs to understand:
What could hurt the organization, how exposed are we, and what are we doing about it?
Internal Audit Has an Important Role
Internal Audit should not own cybersecurity.
Management owns the risk and controls.
Internal Audit can independently assess:
Governance
Risk assessment
Access controls
Change management
Vendor risk
Incident management
Information protection
Monitoring
Corrective action
The key assurance question is:
Can management and the Board rely upon the organization's cybersecurity program?
That is a natural Internal Audit responsibility.
Test Design Effectiveness Before Operating Effectiveness
Consider this cybersecurity control:
“Management reviews privileged access quarterly.”
The auditor obtains four signed reviews.
Did the control work?
Not necessarily.
First determine whether the control is properly designed.
Ask:
Is the access population complete?
Does the reviewer understand appropriate access?
Is the reviewer sufficiently independent?
Are exceptions investigated?
Is inappropriate access removed?
Only after establishing design effectiveness should the auditor determine whether the control actually operated.
A perfectly performed bad control remains a bad control.
Cybersecurity Policies Are Not Cybersecurity Controls
Insurance organizations may maintain impressive documentation:
Information-security policies
Incident-response plans
Access-control procedures
Vendor-security policies
Acceptable-use standards
Those documents establish expectations.
They do not prove execution.
The auditor should ask:
Show me.
Show me:
The most recent privileged-access review
The last terminated employee
The most recent cybersecurity incident
The latest third-party assessment
The last recovery test
Move from policy to evidence.
Incident Response Must Work Under Pressure
Every organization should assume that cybersecurity incidents are possible.
The question becomes:
What happens next?
A credible incident-response program should address:
Detection
Escalation
Containment
Investigation
Recovery
Communication
Regulatory notification
Lessons learned
An incident-response plan sitting on a shared drive is not enough.
Organizations should test whether the plan can actually work.
Ransomware Turns Cybersecurity Into Business Continuity
Ransomware illustrates why cybersecurity cannot be isolated from operational resilience.
If critical information is encrypted or systems become unavailable, the organization needs to know:
Which systems are critical
How quickly they must be restored
How much data can be lost
Whether backups exist
Whether backups are protected
Whether restoration has been tested
A backup is only valuable when it can actually be restored.
Cybersecurity Monitoring Should Produce Action
Organizations can generate enormous volumes of cybersecurity information.
Alerts alone create little value.
There must be a process:
Alert
↓
Analysis
↓
Investigation
↓
Escalation
↓
Response
↓
Corrective Action
A sophisticated monitoring platform combined with weak follow-up is still a weak control
environment.
Human Behavior Remains a Cybersecurity Risk
Cybersecurity professionals sometimes focus heavily on technology.
People remain critical.
Employees may:
Click phishing links
Share credentials
Use weak passwords
Send information to the wrong person
Bypass controls
Install unauthorized applications
Organizations therefore need:
Training
Awareness
Clear policies
Monitoring
Appropriate consequences
But training cannot fix every badly designed process.
If the organization makes secure behavior unnecessarily difficult, employees will develop workarounds.
The control environment must make the secure choice practical.
Artificial Intelligence Creates a New Cybersecurity Frontier
Insurance organizations are rapidly adopting generative and predictive AI.
Potential applications include:
Underwriting
Claims
Fraud detection
Customer support
Risk analysis
Finance
Internal Audit
AI also creates cybersecurity and information-governance questions:
What information can employees submit?
Can policyholder information be entered?
Where is the information retained?
Who can access AI systems?
Who approves new AI applications?
How are outputs validated?
How is unauthorized “shadow AI” detected?
AI governance therefore needs to become part of the cybersecurity program.
The technology is new.
The internal-control questions are familiar:
Who has access?
What information is involved?
What can go wrong?
What prevents it?
How do we know the control works?
Insurance Cybersecurity Also Requires Regulatory Awareness
Insurance companies operate within state-based regulatory frameworks, and cybersecurity obligations can extend well beyond general corporate IT practices.
That means compliance professionals need to understand the relationship among:
Cybersecurity regulation
Information-security programs
Governance
Risk assessment
Third-party management
Incident response
Regulatory reporting
The objective should not be merely to prepare for the next examination.
The organization should build a cybersecurity system capable of operating effectively every day.
Continuous Improvement Matters
Cybersecurity risks evolve continuously.
New vulnerabilities appear.
Attack methods change.
Technology changes.
Third parties change.
Organizations adopt new applications.
A cybersecurity assessment performed two years ago cannot automatically be assumed to describe today's risk environment.
A mature program therefore requires:
Risk Assessment
↓
Controls
↓
Monitoring
↓
Testing
↓
Findings
↓
Corrective Action
↓
Reassessment
Cybersecurity is a cycle—not a project with an end date.
What Participants Should Take Away
The value of an insurance cybersecurity program is not measured by the number of policies produced or cybersecurity products purchased.
Management should ultimately be able to answer:
What information are we protecting?
What are our most significant cyber risks?
Who owns those risks?
What controls address them?
How do we know those controls work?
What third parties create exposure?
What happens when an incident occurs?
Who tells management and governance?
How do we improve after a failure?
Those are the questions that turn cybersecurity from a technical function into a managed system of internal control.
Who Should Attend?
The CCS program is particularly relevant to professionals working in and around insurance information-security programs, including:
Internal Auditors
IT Auditors
Cybersecurity professionals
Compliance professionals
Risk Managers
Information Technology professionals
Insurance executives
Professionals responsible for cybersecurity governance
The Bottom Line
Insurance cybersecurity ultimately comes down to protecting:
Information.
Systems.
Operations.
Customers.
The organization itself.
Technology is an important part of that defense.
But technology alone is not enough.
Effective cybersecurity requires:
Governance
Risk Assessment
Internal Controls
People
Third-Party Oversight
Monitoring
Incident Response
Continuous Improvement
That is the broader perspective Corporate Compliance Seminars' Insurance Information Cybersecurity Programs event brings to the subject.
Join CCS on Tuesday, October 27, 2026, and strengthen your understanding of how insurance organizations can build, assess, and improve cybersecurity programs capable of standing up to operational risk, regulatory expectations, and the rapidly changing threat environment.

Comments