Explore why cyber security in the insurance sector is critical for protecting sensitive customer data, reducing ransomware risk and preventing human error from becoming a breach.
Money is not the only thing drawing attackers to insurance. It is data. Insurance companies hold vast amounts of sensitive and personally identifiable information, making the sector a high-value target for cybercriminals. According to the report, the insurance industry was the most targeted sector by cyber attacks in Q1 2023, while over a quarter of attackers in 2022 were motivated by financial gain.
Rapid digital transformation has widened the attack surface across the insurance sector, creating new opportunities for ransomware, data theft, phishing, weak password attacks, misconfigured web servers and unpatched devices. In 2021, CNA Financial reportedly paid a $40 million ransom after an attack exposed sensitive employee and customer data, while attackers in another case spent four months inside an insurer's systems stealing data before deploying ransomware.
With the typical cost of a data breach for a financial services organisation reaching $5.97 million, this report explains the threats facing insurers and why human error, staff awareness and behaviour change remain central to reducing cyber risk.
In this free eBook, you'll discover:
TSC helps insurance organisations strengthen security awareness and reduce human error risk through practical training focused on phishing, ransomware, data protection, password security, misconfiguration, unpatched devices and the everyday behaviours attackers exploit.
View the report Book an eLearning demo
The insurance sector is targeted because it holds large volumes of sensitive customer data, personally identifiable information, financial records, medical details and policy information. This data can be used for fraud, identity theft, extortion, ransomware and resale on criminal marketplaces.
Key insurance cyber security risks include ransomware, Ransomware-as-a-Service, data theft, phishing, weak passwords, misconfigured web servers, unpatched devices, digital transformation risk and human error that leads to accidental data exposure.
Insurance organisations can reduce data breach risk by improving staff cyber security awareness, training employees to spot phishing, strengthening password and MFA controls, patching devices, securing web servers, protecting sensitive customer data and building a security culture that reduces human error.