TRIPLE-I/FENIX24 REPORT IDENTIFIES EMERGING CYBERSECURITY PRIORITIES FOR INSURERS
The following information was released by the
The
The report found that while property/casualty insurers have made impactful cybersecurity investments, gaps remain in areas including patching cadence, authentication practices, and recovery testing, which are all weaknesses that could complicate responses to today's threat environment. The report draws on a series of conversations with insurance industry executives, with questions aligned to best practices, regulatory requirements and security controls commonly required in cyber insurance underwriting.
"Insurers occupy a paradoxical position in the cybersecurity landscape," said
"Most organizations have tested their recovery plans for natural disasters or standard IT outages, but not for ransomware attacks," said
A Growing Market Facing Evolving Threats
The cyber insurance market reached
Key Findings
The report identified strengths and areas for improvement across several critical cybersecurity domains:
Immutable Backups and Recovery: Most insurers implement immutable backups across critical system categories, and most report meeting recovery time objectives for their highest-tier systems. However, recovery tests are often conducted under ideal conditions on a single system rather than across full network recovery, creating a potential gap when a real incident strikes.
Credentials and Access Management: All participating insurers use corporate password vaults and enforce strong password complexity, with user passwords averaging more than 13 characters. All require multi-factor authentication (MFA) for administrative accounts. However, some organizations still permit less secure MFA methods such as SMS messages and email confirmation, which are approaches with known limitations that threat actors frequently exploit.
Browsing Controls and Attack Surface Management: Most insurers implement DNS filtering and block peer-to-peer file transfer and web-based email sites, which are effective measures for limiting threat actor access. Some organizations use "split tunneling," which allows employee internet browsing outside of VPN encryption, improving user experience but increasing exposure to phishing, malware and "man-in-the-middle" attacks.
Patching and Risk Management: All participants conduct penetration testing, including social engineering scenarios targeting help desk personnel, which recognizes human defenses are as critical as technical ones. However, only about half deploy security patches monthly. In today's threat environment, adversaries often exploit newly disclosed vulnerabilities within hours or days of public disclosure, making accelerated patch cycles an emerging best practice.
Preparation Over Perfection
The study emphasizes systematic preparation, such as tested recovery capabilities and faster patch cycles, over the pursuit of any single "perfect" security solution. Insurers, like all businesses, must balance cybersecurity with user experience and operational performance, making thoughtful risk management essential.
"The difference between resilience and disaster lies not in perfect prevention but in systematic preparation, validated recovery capabilities and organizational commitment to continuous security improvement," the report concluded.
About the
Since 1960, the
About Fenix24
Fenix24™ is the global leader in breach recovery, providing assured and battle-tested cyber resilience solutions. With a mission to redefine how organizations recover from cyber incidents, Fenix24 combines expert-driven response, cutting-edge technology, and a proven track record of restoring businesses faster and more securely than ever before.
For more information, visit www.Fenix24.com
Fenix24 is the "world's first civilian cybersecurity force," with four time-tested battalions:
Fenix24™ / Ransomware rapid response, remediation and recovery
Athena7™ / IT security assessments, strategy and planning
Grypho5™ / Ongoing, security-based management
Argos99™ / Expert insights into data, assets and infrastructure
About The Institutes
The Institutes are a not-for-profit comprised of diverse affiliates that educate, elevate, and connect people in the essential disciplines of risk management and insurance. Through products and services offered by The Institutes 20 affiliated business units and backed by more than 115 years of experience as a trusted knowledge partner, we empower people and organizations to help those in need with a focus on understanding, predicting, and preventing losses to create a more resilient world.
The Institutes is a registered trademark of The Institutes. All rights reserved.


ASSEMBLY PASSES LEGISLATION TO EXPAND ACCESS TO ACUPUNCTURE SERVICES IN NEW YORK
POWELL ISSUES A WARNING ON U.S. DEBT
Advisor News
- A rising retirement challenge: The license to spend
- Financial stress leaves less room for retirement saving
- Giving while you’re living: 3 frequently asked questions about gifting
- Helping clients prepare for one of their biggest retirement expenses
- Important year-end financial conversations every advisor must have
More Advisor NewsAnnuity News
- A rising retirement challenge: The license to spend
- What lower interest rates mean to annuity payouts
- AM Best downgrades A-Cap insurers amid financial and regulatory troubles
- Lawsuit claims Delaware Life hid billions in insurer-linked investments
- AM Best to Deliver Presentation at 2026 ACLI Annual Conference
More Annuity NewsHealth/Employee Benefits News
Life Insurance News