It’s time for the insurance sector to ramp up its cyber defenses - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading From the Field: Expert Insights
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
From the Field: Expert Insights
From the Field: Expert Insights RSS Get our newsletter
Order Prints
February 18, 2025 From the Field: Expert Insights
Share
Share
Post
Email

It’s time for the insurance sector to ramp up its cyber defenses

By Matt Lindley

Insurance companies know all about assessing and managing risk for their customers, but they also must be capable of identifying the most urgent risks to themselves.

insurance cyber
Matt Lindley

One such risk is the growing threat of cyberattacks, which are increasingly directed at the insurance sector to steal highly sensitive information collected during underwriting and claims processes. When insurance companies suffer cyberattacks, they don’t only confront significant financial and operational consequences — they also face the reputational damage that comes with the failure to manage risk effectively for their own organizations.

 

Insurance companies must apply the principles of their business to their own operations. This means understanding their unique vulnerabilities, as well as the latest cybercriminal tactics for taking advantage of those vulnerabilities. For example, insurance companies are far more digitized — from online policy applications and claim filing to the collection of health data via fitness trackers for incentives like wellness premiums. Although digitization offers more convenience and a greater range of services, it also increases the number of attack vectors for cybercriminals to exploit.

The digital transformation is a competitive necessity for insurance companies, which is why cybersecurity is so vital for the industry. It’s time for insurance companies to adopt more robust policies and processes to guard against cyberattacks, from zero-trust security infrastructure to cybersecurity training for employees. When insurance companies protect themselves, they will be in a stronger position to focus on their core mission of protecting customers.

Cybercriminals are targeting the insurance sector

In February 2024, Change Healthcare was hit by a major cyberattack that compromised the data of as many as 100 million Americans. This was one of the largest breaches ever recorded, and it caused severe disruptions for healthcare providers, cost Change Healthcare at least $2.5 billion, and interrupted patient care. Change Healthcare is a payments platform owned by UnitedHealth Group, a major health insurance provider.

The cyberattack on Change Healthcare is a reminder that the insurance industry spans many domains. According to IBM, the financial sector, which includes insurance companies, had the second-highest average cost of a data breach in 2024: over $6 million. However, the health care sector — which overlaps with the insurance industry — was at the top of the list at nearly $10 million. Insurance companies don’t only operate in a wide array of fields — they also collect and protect many different types of data, from financial and health records to intellectual property.

Insurance companies also face regulatory and compliance risks when they suffer a cyberattack. In November 2024, auto insurance companies Geico and Travelers were fined $11.3 million by New York state for cybersecurity failures that led to stolen customer data. All these attacks are part of a broader trend. Allianz reports that cyber incidents constituted the top global business risk in 2024 “for the first time by a clear margin,” and it’s clear that insurance companies should be focused on addressing this risk.

How cybercriminals are attacking insurance companies

The insurance industry is in the middle of a sweeping digital transformation. Customers want accessible and powerful digital platforms to manage their policies, check updates and receive 24-hour support. They also increasingly expect personalization, such as policies that reflect their individual behavior and meet their unique needs more effectively. While these services are drastically improving customer experiences, they also create a whole new landscape of attack vectors for cybercriminals.

Insurance companies are increasingly reliant upon digital internal processes, from automated workflows to data analysis. They can use artificial intelligence for actuarial analysis, underwriting and claims automation, and they have access to a much larger universe of data about their customers than ever before. For example, auto insurance customers are increasingly willing to share telemetrics data to receive safe driver discounts. But the digital transformation has a dark side. As Deloitte explains, cyberattacks on the industry are “growing exponentially as insurance companies migrate toward digital channels in an effort to create tighter customer relationships, offer new products and expand their share of customers’ financial portfolios.”

It has never been more critical for insurance companies to protect their networks and safeguard the data they collect. Doing so won’t just ensure the integrity of their operations and shield sensitive customer information from cybercriminals — it will also build the trust necessary to continue offering digital services that improve customer satisfaction and retention.

Building up cyber defenses in the insurance industry

As cybercriminals continue to target insurance companies and the digitization of the sector accelerates, cybersecurity must become a core priority. This means implementing security technology such as data encryption, threat monitoring systems and zero-trust architecture. It also means addressing third-party risks, which are especially relevant because insurance interacts with many other sectors. Finally, insurance companies must focus their cybersecurity efforts on the workforce — from the development of an incident response plan and reporting procedures to employee awareness training at every level.

IBM found that the two most frequently exploited initial attack vectors are phishing and compromised credentials. These methods stem from social engineering, which is why employee training is the top factor that reduces the average cost of a data breach. One key aspect of cybersecurity awareness training is personalization — the most effective training programs account for different learning styles, psychological traits and behaviors, vulnerabilities, and levels of knowledge. These programs must also consider different roles within the organization, from analysts who evaluate actuarial data to agents who work directly with customers.

The cybercriminals who infiltrated Travelers deployed stolen credentials to access an online quoting tool used by agents — a tool that wasn’t protected by multifactor authentication. The Change Healthcare hackers were able to execute one of the largest data breaches in U.S. history by stealing the username and password of a “low-level customer support employee” who also wasn’t using multifactor authentication. It’s difficult to think of clearer examples that insurance companies should make cybersecurity awareness a higher priority.

The digital transformation in the insurance industry will only gain momentum in the coming years. The companies that make this transition while making cybersecurity a core strategic priority will keep their networks and systems safe — a prerequisite for maintaining the hard-earned trust of their customers.

© Entire contents copyright 2025 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.

 

 

No image

Matt Lindley is chief innovation and information security officer at NINJIO. Contact him at [email protected].

Older

Medicaid on the chopping block as Republicans release budget draft

Newer

4 things every federal worker should do to safeguard their benefits

Advisor News

  • Americans less confident about retirement as worries grow
  • 6 in 10 Americans struggle with financial decisions
  • Trump bets his tax cuts will please Las Vegas voters on his swing West
  • Lifetime income is the missing link to global retirement security
  • Don’t let caregiving derail your clients’ retirement
More Advisor News

Annuity News

  • Allianz Life Adds New Accumulation-Focused Fixed Index Annuities
  • Allianz Life adds new accumulation-focused FIAs
  • Industry objects to ‘tone and tenor’ of draft NAIC Annuity Buyer’s Guide
  • Annuity industry grapples with consolidation, innovation and planning shifts
  • Human connection still key in the new annuity era
More Annuity News

Health/Employee Benefits News

  • 69,000 drop NJ marketplace health plans after enrolling
  • Limits to health insurance program for immigrants approved by Colorado lawmakers
  • NC LEGISLATIVE SESSION BEGINS WITH FOCUS ON CANCER POLICY ACS CAN URGES LAWMAKERS TO PASS HOUSE BILL 567 FOR BIOMARKER TESTING COVERAGE
  • SEN. WEBBER SEEKS TO ENSURE HEALTH CARE IS AFFORDABLE FOR INDIVIDUALS AND SMALL BUSINESS OWNERS
  • How to make a high-deductible health plan work for you
More Health/Employee Benefits News

Life Insurance News

  • Life insurance tips: 5 underwriting concerns for clients living abroad
  • Prudential extends Japan sales ban another 6 months at a total $1B loss
  • AM Best Affirms Credit Ratings of The Wawanesa Mutual Insurance Company and Wawanesa Life Insurance Company
  • Life insurance for gig economy power earners: what advisors need to know
  • Allianz Life Adds New Accumulation-Focused Fixed Index Annuities
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Protectors Vegas Arrives Nov 9th - 11th
1,000+ attendees. 150+ speakers. Join the largest event in life & annuities this November.

A FIA Cap That Stays Locked
CapLock™ from Oceanview locks the cap at issue for 5 or 7 years. No resets. Just clarity.

Aim higher with Ascend annuities
Fixed, fixed-indexed, registered index-linked and advisory annuities to help you go above and beyond

Unlock the Future of Index-Linked Solutions
Join industry leaders shaping next-gen index strategies, distribution, and innovation.

Leveraging Underwriting Innovations
See how Pacific Life’s approach to life insurance underwriting can give you a competitive edge.

Bring a Real FIA Case. Leave Ready to Close.
A practical working session for agents who want a clearer, repeatable sales process.

Press Releases

  • RFP #T01325
  • RFP #T01325
  • RFP #T01825
  • RFP #T01825
  • RFP #T01525
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet