It’s time for the insurance sector to ramp up its cyber defenses - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading From the Field: Expert Insights
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
From the Field: Expert Insights
From the Field: Expert Insights RSS Get our newsletter
Order Prints
February 18, 2025 From the Field: Expert Insights
Share
Share
Tweet
Email

It’s time for the insurance sector to ramp up its cyber defenses

By Matt Lindley

Insurance companies know all about assessing and managing risk for their customers, but they also must be capable of identifying the most urgent risks to themselves.

insurance cyber
Matt Lindley

One such risk is the growing threat of cyberattacks, which are increasingly directed at the insurance sector to steal highly sensitive information collected during underwriting and claims processes. When insurance companies suffer cyberattacks, they don’t only confront significant financial and operational consequences — they also face the reputational damage that comes with the failure to manage risk effectively for their own organizations.

 

Insurance companies must apply the principles of their business to their own operations. This means understanding their unique vulnerabilities, as well as the latest cybercriminal tactics for taking advantage of those vulnerabilities. For example, insurance companies are far more digitized — from online policy applications and claim filing to the collection of health data via fitness trackers for incentives like wellness premiums. Although digitization offers more convenience and a greater range of services, it also increases the number of attack vectors for cybercriminals to exploit.

The digital transformation is a competitive necessity for insurance companies, which is why cybersecurity is so vital for the industry. It’s time for insurance companies to adopt more robust policies and processes to guard against cyberattacks, from zero-trust security infrastructure to cybersecurity training for employees. When insurance companies protect themselves, they will be in a stronger position to focus on their core mission of protecting customers.

Cybercriminals are targeting the insurance sector

In February 2024, Change Healthcare was hit by a major cyberattack that compromised the data of as many as 100 million Americans. This was one of the largest breaches ever recorded, and it caused severe disruptions for healthcare providers, cost Change Healthcare at least $2.5 billion, and interrupted patient care. Change Healthcare is a payments platform owned by UnitedHealth Group, a major health insurance provider.

The cyberattack on Change Healthcare is a reminder that the insurance industry spans many domains. According to IBM, the financial sector, which includes insurance companies, had the second-highest average cost of a data breach in 2024: over $6 million. However, the health care sector — which overlaps with the insurance industry — was at the top of the list at nearly $10 million. Insurance companies don’t only operate in a wide array of fields — they also collect and protect many different types of data, from financial and health records to intellectual property.

Insurance companies also face regulatory and compliance risks when they suffer a cyberattack. In November 2024, auto insurance companies Geico and Travelers were fined $11.3 million by New York state for cybersecurity failures that led to stolen customer data. All these attacks are part of a broader trend. Allianz reports that cyber incidents constituted the top global business risk in 2024 “for the first time by a clear margin,” and it’s clear that insurance companies should be focused on addressing this risk.

How cybercriminals are attacking insurance companies

The insurance industry is in the middle of a sweeping digital transformation. Customers want accessible and powerful digital platforms to manage their policies, check updates and receive 24-hour support. They also increasingly expect personalization, such as policies that reflect their individual behavior and meet their unique needs more effectively. While these services are drastically improving customer experiences, they also create a whole new landscape of attack vectors for cybercriminals.

Insurance companies are increasingly reliant upon digital internal processes, from automated workflows to data analysis. They can use artificial intelligence for actuarial analysis, underwriting and claims automation, and they have access to a much larger universe of data about their customers than ever before. For example, auto insurance customers are increasingly willing to share telemetrics data to receive safe driver discounts. But the digital transformation has a dark side. As Deloitte explains, cyberattacks on the industry are “growing exponentially as insurance companies migrate toward digital channels in an effort to create tighter customer relationships, offer new products and expand their share of customers’ financial portfolios.”

It has never been more critical for insurance companies to protect their networks and safeguard the data they collect. Doing so won’t just ensure the integrity of their operations and shield sensitive customer information from cybercriminals — it will also build the trust necessary to continue offering digital services that improve customer satisfaction and retention.

Building up cyber defenses in the insurance industry

As cybercriminals continue to target insurance companies and the digitization of the sector accelerates, cybersecurity must become a core priority. This means implementing security technology such as data encryption, threat monitoring systems and zero-trust architecture. It also means addressing third-party risks, which are especially relevant because insurance interacts with many other sectors. Finally, insurance companies must focus their cybersecurity efforts on the workforce — from the development of an incident response plan and reporting procedures to employee awareness training at every level.

IBM found that the two most frequently exploited initial attack vectors are phishing and compromised credentials. These methods stem from social engineering, which is why employee training is the top factor that reduces the average cost of a data breach. One key aspect of cybersecurity awareness training is personalization — the most effective training programs account for different learning styles, psychological traits and behaviors, vulnerabilities, and levels of knowledge. These programs must also consider different roles within the organization, from analysts who evaluate actuarial data to agents who work directly with customers.

The cybercriminals who infiltrated Travelers deployed stolen credentials to access an online quoting tool used by agents — a tool that wasn’t protected by multifactor authentication. The Change Healthcare hackers were able to execute one of the largest data breaches in U.S. history by stealing the username and password of a “low-level customer support employee” who also wasn’t using multifactor authentication. It’s difficult to think of clearer examples that insurance companies should make cybersecurity awareness a higher priority.

The digital transformation in the insurance industry will only gain momentum in the coming years. The companies that make this transition while making cybersecurity a core strategic priority will keep their networks and systems safe — a prerequisite for maintaining the hard-earned trust of their customers.

© Entire contents copyright 2025 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.

 

 

Matt Lindley

Matt Lindley is chief innovation and information security officer at NINJIO. Contact him at [email protected].

Older

Medicaid on the chopping block as Republicans release budget draft

Newer

4 things every federal worker should do to safeguard their benefits

Advisor News

  • Bill that could expand access to annuities headed to the House
  • Private equity, crypto and the risks retirees can’t ignore
  • Will Trump accounts lead to a financial boon? Experts differ on impact
  • Helping clients up the impact of their charitable giving with a DAF
  • 3 tax planning strategies under One Big Beautiful Bill
More Advisor News

Annuity News

  • An Application for the Trademark “EMPOWER INVESTMENTS” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Bill that could expand access to annuities headed to the House
  • LTC annuities and minimizing opportunity cost
  • Venerable Announces Head of Flow Reinsurance
  • 3 tax planning strategies under One Big Beautiful Bill
More Annuity News

Health/Employee Benefits News

  • Rep. Fulcher introduces bill extending private, short-term health care coverage
  • Health insurance in retirement
  • Craig Schillig: Health insurance in retirement
  • TRUMP'S REAPER' IS COMING FOR YOUR DISABILITY BENEFITS
  • Cancer patient denied treatment until it was too late Cancer patient denied potential life-saving treatment until it was too late (copy)
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • On the Move: Dec. 4, 2025
  • Judge approves PHL Variable plan; could reduce benefits by up to $4.1B
  • Seritage Growth Properties Makes $20 Million Loan Prepayment
  • AM Best Revises Outlooks to Negative for Kansas City Life Insurance Company; Downgrades Credit Ratings of Grange Life Insurance Company; Revises Issuer Credit Rating Outlook to Negative for Old American Insurance Company
  • AM Best Affirms Credit Ratings of Bao Minh Insurance Corporation
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • Altara Wealth Launches as $1B+ Independent Advisory Enterprise
  • A Heartfelt Letter to the Independent Advisor Community
  • 3 Mark Financial Celebrates 40 Years of Partnerships and Purpose
  • Hexure Launches AI Enabled Version of Its Platform to Power Life Insurance Sales
  • National Life Group Board Approves Dividends for 2026
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet