Insurers Face Cybersecurity Gaps Despite Investments
Property and casualty insurers have made significant investments in cybersecurity, but critical vulnerabilities remain in areas like patching, authentication, and recovery testing, according to a latest report from the Insurance Information Institute (Triple-I) and Fenix24. These gaps could complicate responses to the evolving threat landscape, particularly concerning ransomware attacks.
Report Highlights Key Vulnerabilities
The report, titled “Cybersecurity for Insurers: Squaring Safety with Service,” examined current cybersecurity practices within the insurance industry. Findings indicate that while insurers are adept at assessing cyber risk for policyholders and setting security requirements for coverage, they need to bolster their own defenses. Specifically, the report points to deficiencies in:
- Patching Cadence: Inconsistent and slow application of security patches leaves systems vulnerable to known exploits.
- Authentication Practices: Weak or outdated authentication methods increase the risk of unauthorized access.
- Recovery Testing: Insufficient testing of recovery plans, especially in the context of sophisticated ransomware attacks, hinders effective response and recovery.
Ransomware Resilience Requires More Than Backups
Mark Grazman, CEO of Fenix24, emphasized that traditional disaster recovery plans often fall short when dealing with ransomware. “Most organizations have tested their recovery plans for natural disasters or standard IT outages, but not for ransomware attacks,” he stated.
The report details how ransomware attacks travel beyond simply encrypting data. Attackers actively target and destroy critical infrastructure, including Active Directory, identity systems, virtual machines, hypervisors, and email communications. Effective resiliency planning requires a comprehensive understanding of backup survivability, architecture for data restoration, and data integrity, alongside detailed asset intelligence and prioritization of business-critical applications.
Insurers in a Paradoxical Position
Sean Kevelighan, CEO of Triple-I, highlighted the unique position insurers occupy in the cybersecurity ecosystem. “Insurers occupy a paradoxical position in the cybersecurity landscape,” he explained. “They assess cyber risk for policyholders and establish security requirements as conditions of coverage, yet they likewise need to demonstrate their own cybersecurity practices meet or exceed evolving standards.”
Looking Ahead
The report underscores the need for insurers to prioritize comprehensive cybersecurity strategies that address the specific threats posed by ransomware and other advanced attacks. Investing in robust recovery testing, strengthening authentication practices, and maintaining a rigorous patching cadence are crucial steps toward building a more resilient cybersecurity posture. As the threat landscape continues to evolve, insurers must proactively adapt their defenses to protect their own operations and maintain trust with their policyholders.
Worth a look