top of page
Search

Insurance Information Cybersecurity Programs: Building a Defensible Cybersecurity Program Under Insurance Regulatory Expectations

Live CPE Webinar • Tuesday, October 27, 2026

Insurance organizations hold exactly the kind of information cybercriminals want.


They may possess:

  • Personally identifiable information

  • Financial information

  • Claims information

  • Medical and health-related information

  • Driver information

  • Policyholder records

  • Banking and payment information

  • Employee information

  • Producer information


At the same time, insurers increasingly rely on interconnected systems, cloud services, third-party administrators, vendors, agents, artificial intelligence, and other technology providers.


That combination creates significant cybersecurity exposure.


For insurance organizations, cybersecurity is no longer simply an IT issue.


It is a governance, compliance, internal control, operational resilience, third-party risk, and regulatory issue.


Corporate Compliance Seminars' Insurance Information Cybersecurity Programs CPE event is designed to help insurance professionals understand how to develop, operate, assess, and improve an information-security program appropriate for the insurance regulatory environment.


The next program is scheduled for Tuesday, October 27, 2026.



Cybersecurity Is an Enterprise Risk

A common mistake is assigning cybersecurity entirely to Information Technology.


IT certainly plays a major role.


But cybersecurity failures can affect:

  • Operations

  • Compliance

  • Finance

  • Claims

  • Underwriting

  • Customer service

  • Reputation

  • Regulatory relationships


A ransomware attack, for example, may not merely shut down servers.


It could prevent an insurer from:

  • Processing claims

  • Accessing policy information

  • Communicating with policyholders

  • Paying vendors

  • Performing financial reporting

  • Meeting regulatory obligations


The appropriate question for management is therefore not:

“Does IT have cybersecurity covered?”

It is:

“Does the organization have an effective system for identifying, assessing, controlling, monitoring, and responding to information-security risk?”

That is an enterprise-risk-management question.


Start With a Cybersecurity Risk Assessment

A strong cybersecurity program should begin with risk.


Before selecting controls, management needs to understand:

  • What information it possesses

  • Where that information resides

  • Which systems process it

  • Who can access it

  • Which third parties receive it

  • Which threats could affect it

  • What the consequences of compromise would be


The logic should be:


Information Assets

Threats

Vulnerabilities

Risk

Controls

Monitoring

Response


Without a meaningful risk assessment, organizations can spend substantial amounts of money on cybersecurity while failing to address their most important exposures.


Know Where the Sensitive Information Is

An insurance company cannot protect information it does not know it has.


Sensitive information may exist in:

  • Core insurance applications

  • Claims systems

  • Underwriting applications

  • Email

  • Shared drives

  • Cloud applications

  • Laptops

  • Mobile devices

  • Third-party platforms


Organizations need to understand the information lifecycle:


Collection → Use → Storage → Transmission → Retention → Destruction


Each stage creates different risks.


That is why information governance and cybersecurity increasingly need to operate together.


Access Control Is One of the Fundamental Defenses

A basic cybersecurity question is:

Who can access what?

Access should generally reflect business need.


Important control areas include:

  • User provisioning

  • Authentication

  • Multifactor authentication

  • Privileged access

  • Transfers

  • Terminations

  • Periodic access reviews

  • Segregation of duties


The organization should also ask whether access that was appropriate when initially granted remains appropriate today.


An employee who changes responsibilities may accumulate access over time.


That can create unnecessary exposure.


Privileged Access Creates Concentrated Risk

Administrators and other privileged users may possess extensive capabilities.


Depending on the environment, they might be able to:

  • Create users

  • Reset passwords

  • Change configurations

  • Access sensitive information

  • Modify applications

  • Change security settings


Those capabilities require stronger controls.


Management should understand:

  • Who has privileged access

  • Why they need it

  • Who approved it

  • Whether activities are monitored

  • How access is periodically reviewed

  • How unnecessary privileges are removed


Privileged access should never become invisible simply because it belongs to technical personnel.


Third-Party Risk Is Insurance Cybersecurity Risk

Insurance organizations frequently depend on external organizations including:

  • Claims administrators

  • Producers

  • Brokers

  • Cloud service providers

  • Data processors

  • Software vendors

  • Consultants

  • Call centers

  • Payment processors


That means the organization's data-security perimeter extends beyond its own network.


A cybersecurity program should therefore address:

Vendor selection

Due diligence

Contract requirements

Security expectations

Ongoing monitoring

Incident notification

Termination


The question is not merely:

“Does the vendor have a cybersecurity policy?”

The better question is:

“What evidence gives us reasonable confidence that this third party is appropriately protecting our information?”

Cybersecurity Governance Starts at the Top

Technology teams can implement security controls.


They cannot alone establish enterprise governance.


Senior management and appropriate governance bodies should understand:

  • Significant cyber risks

  • Major incidents

  • Material control weaknesses

  • Third-party exposure

  • Remediation progress

  • Resource needs


Effective governance requires useful information.


A dashboard containing 75 technical statistics may impress people without helping them govern.


Leadership needs to understand:

What could hurt the organization, how exposed are we, and what are we doing about it?

Internal Audit Has an Important Role

Internal Audit should not own cybersecurity.


Management owns the risk and controls.


Internal Audit can independently assess:

  • Governance

  • Risk assessment

  • Access controls

  • Change management

  • Vendor risk

  • Incident management

  • Information protection

  • Monitoring

  • Corrective action


The key assurance question is:

Can management and the Board rely upon the organization's cybersecurity program?

That is a natural Internal Audit responsibility.


Test Design Effectiveness Before Operating Effectiveness

Consider this cybersecurity control:

“Management reviews privileged access quarterly.”

The auditor obtains four signed reviews.


Did the control work?


Not necessarily.


First determine whether the control is properly designed.


Ask:

  • Is the access population complete?

  • Does the reviewer understand appropriate access?

  • Is the reviewer sufficiently independent?

  • Are exceptions investigated?

  • Is inappropriate access removed?


Only after establishing design effectiveness should the auditor determine whether the control actually operated.


A perfectly performed bad control remains a bad control.


Cybersecurity Policies Are Not Cybersecurity Controls

Insurance organizations may maintain impressive documentation:

  • Information-security policies

  • Incident-response plans

  • Access-control procedures

  • Vendor-security policies

  • Acceptable-use standards


Those documents establish expectations.


They do not prove execution.


The auditor should ask:

Show me.

Show me:

  • The most recent privileged-access review

  • The last terminated employee

  • The most recent cybersecurity incident

  • The latest third-party assessment

  • The last recovery test


Move from policy to evidence.


Incident Response Must Work Under Pressure

Every organization should assume that cybersecurity incidents are possible.


The question becomes:

What happens next?

A credible incident-response program should address:

  • Detection

  • Escalation

  • Containment

  • Investigation

  • Recovery

  • Communication

  • Regulatory notification

  • Lessons learned


An incident-response plan sitting on a shared drive is not enough.


Organizations should test whether the plan can actually work.


Ransomware Turns Cybersecurity Into Business Continuity

Ransomware illustrates why cybersecurity cannot be isolated from operational resilience.


If critical information is encrypted or systems become unavailable, the organization needs to know:

  • Which systems are critical

  • How quickly they must be restored

  • How much data can be lost

  • Whether backups exist

  • Whether backups are protected

  • Whether restoration has been tested


A backup is only valuable when it can actually be restored.


Cybersecurity Monitoring Should Produce Action

Organizations can generate enormous volumes of cybersecurity information.


Alerts alone create little value.


There must be a process:

Alert

Analysis

Investigation

Escalation

Response

Corrective Action


A sophisticated monitoring platform combined with weak follow-up is still a weak control

environment.


Human Behavior Remains a Cybersecurity Risk

Cybersecurity professionals sometimes focus heavily on technology.


People remain critical.


Employees may:

  • Click phishing links

  • Share credentials

  • Use weak passwords

  • Send information to the wrong person

  • Bypass controls

  • Install unauthorized applications


Organizations therefore need:

  • Training

  • Awareness

  • Clear policies

  • Monitoring

  • Appropriate consequences


But training cannot fix every badly designed process.


If the organization makes secure behavior unnecessarily difficult, employees will develop workarounds.


The control environment must make the secure choice practical.


Artificial Intelligence Creates a New Cybersecurity Frontier

Insurance organizations are rapidly adopting generative and predictive AI.


Potential applications include:

  • Underwriting

  • Claims

  • Fraud detection

  • Customer support

  • Risk analysis

  • Finance

  • Internal Audit


AI also creates cybersecurity and information-governance questions:

What information can employees submit?
Can policyholder information be entered?
Where is the information retained?
Who can access AI systems?
Who approves new AI applications?
How are outputs validated?
How is unauthorized “shadow AI” detected?

AI governance therefore needs to become part of the cybersecurity program.


The technology is new.


The internal-control questions are familiar:

  • Who has access?

  • What information is involved?

  • What can go wrong?

  • What prevents it?

  • How do we know the control works?


Insurance Cybersecurity Also Requires Regulatory Awareness

Insurance companies operate within state-based regulatory frameworks, and cybersecurity obligations can extend well beyond general corporate IT practices.


That means compliance professionals need to understand the relationship among:

  • Cybersecurity regulation

  • Information-security programs

  • Governance

  • Risk assessment

  • Third-party management

  • Incident response

  • Regulatory reporting


The objective should not be merely to prepare for the next examination.


The organization should build a cybersecurity system capable of operating effectively every day.


Continuous Improvement Matters

Cybersecurity risks evolve continuously.


New vulnerabilities appear.


Attack methods change.


Technology changes.


Third parties change.


Organizations adopt new applications.


A cybersecurity assessment performed two years ago cannot automatically be assumed to describe today's risk environment.


A mature program therefore requires:


Risk Assessment

Controls

Monitoring

Testing

Findings

Corrective Action

Reassessment


Cybersecurity is a cycle—not a project with an end date.


What Participants Should Take Away

The value of an insurance cybersecurity program is not measured by the number of policies produced or cybersecurity products purchased.


Management should ultimately be able to answer:

  • What information are we protecting?

  • What are our most significant cyber risks?

  • Who owns those risks?

  • What controls address them?

  • How do we know those controls work?

  • What third parties create exposure?

  • What happens when an incident occurs?

  • Who tells management and governance?

  • How do we improve after a failure?


Those are the questions that turn cybersecurity from a technical function into a managed system of internal control.


Who Should Attend?

The CCS program is particularly relevant to professionals working in and around insurance information-security programs, including:

  • Internal Auditors

  • IT Auditors

  • Cybersecurity professionals

  • Compliance professionals

  • Risk Managers

  • Information Technology professionals

  • Insurance executives

  • Professionals responsible for cybersecurity governance


The Bottom Line

Insurance cybersecurity ultimately comes down to protecting:

  • Information.

  • Systems.

  • Operations.

  • Customers.

  • The organization itself.


Technology is an important part of that defense.


But technology alone is not enough.


Effective cybersecurity requires:


Governance


Risk Assessment


Internal Controls


People


Third-Party Oversight


Monitoring


Incident Response


Continuous Improvement


That is the broader perspective Corporate Compliance Seminars' Insurance Information Cybersecurity Programs event brings to the subject.


Join CCS on Tuesday, October 27, 2026, and strengthen your understanding of how insurance organizations can build, assess, and improve cybersecurity programs capable of standing up to operational risk, regulatory expectations, and the rapidly changing threat environment.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page