Skip to content
All posts

Cyber security in the insurance sector

Person signing an insurance document, representing cyber security risks, sensitive data protection and data breach prevention in the insurance sector.

Explore why cyber security in the insurance sector is critical for protecting sensitive customer data, reducing ransomware risk and preventing human error from becoming a breach.

The most targeted sector. Is your insurance data safe?

Money is not the only thing drawing attackers to insurance. It is data. Insurance companies hold vast amounts of sensitive and personally identifiable information, making the sector a high-value target for cybercriminals. According to the report, the insurance industry was the most targeted sector by cyber attacks in Q1 2023, while over a quarter of attackers in 2022 were motivated by financial gain.

Rapid digital transformation has widened the attack surface across the insurance sector, creating new opportunities for ransomware, data theft, phishing, weak password attacks, misconfigured web servers and unpatched devices. In 2021, CNA Financial reportedly paid a $40 million ransom after an attack exposed sensitive employee and customer data, while attackers in another case spent four months inside an insurer's systems stealing data before deploying ransomware.

With the typical cost of a data breach for a financial services organisation reaching $5.97 million, this report explains the threats facing insurers and why human error, staff awareness and behaviour change remain central to reducing cyber risk.

In this free eBook, you'll discover:

Why the insurance industry is one of the most targeted sector
How rapid digital transformation has widened the attack surface
Why the sensitive data insurers hold is so valuable to criminals
How ransomware and Ransomware-as-a-Service threaten the industry
Real-world attacks, including the $40 million CNA Financial breach
How data theft has become as important to attackers as extortion
The growing role of AI in powering future ransomware attacks
Why human error remains a leading cause of insurance data breaches

Reduce cyber risk across your insurance workforce

TSC helps insurance organisations strengthen security awareness and reduce human error risk through practical training focused on phishing, ransomware, data protection, password security, misconfiguration, unpatched devices and the everyday behaviours attackers exploit.

View the report Book an eLearning demo


Insurance cyber security FAQ

Why is the insurance sector targeted by cybercriminals?

The insurance sector is targeted because it holds large volumes of sensitive customer data, personally identifiable information, financial records, medical details and policy information. This data can be used for fraud, identity theft, extortion, ransomware and resale on criminal marketplaces.

What are the biggest cyber security risks for insurance companies?

Key insurance cyber security risks include ransomware, Ransomware-as-a-Service, data theft, phishing, weak passwords, misconfigured web servers, unpatched devices, digital transformation risk and human error that leads to accidental data exposure.

How can insurance organisations reduce data breach risk?

Insurance organisations can reduce data breach risk by improving staff cyber security awareness, training employees to spot phishing, strengthening password and MFA controls, patching devices, securing web servers, protecting sensitive customer data and building a security culture that reduces human error.


Related pages

Human Risk Platform
Products & Services