Insurers hold an unusually rich combination of data - health, financial, behavioural, sometimes telematics and biometric - across systems that frequently predate modern security, distributed through intermediaries they do not control. Each of those three facts creates a distinct problem.
The data
Underwriting and claims files routinely contain special category personal data: medical history, health assessments, sometimes genetic or biometric information. That raises the bar under every privacy regime and makes a breach disproportionately damaging.
It also means retention is a live issue. Long-tail liability lines require holding files for decades, which collides directly with storage limitation - and produces enormous archives of highly sensitive data that must remain both retrievable and protected.
The legacy estate
Policy administration systems are long-lived because replacing them is expensive and risky. The practical consequences are familiar from other regulated industries:
- Platforms that cannot support modern authentication, sitting behind compensating controls.
- Patching constrained by vendor support and testing windows.
- Data extracted into spreadsheets because the system cannot report, creating uncontrolled copies of sensitive data.
- Integration by file transfer, often with weak controls around the transfer mechanism itself.
The spreadsheet problem deserves specific attention. Where the core system cannot answer a question, someone exports the data - and those extracts are where sensitive policyholder information most often leaves the controlled environment.
The distribution network
Brokers, managing general agents and appointed representatives handle policyholder data on your behalf while operating their own infrastructure, often with far smaller security functions. Your exposure runs through organisations you do not manage.
Practical controls: contractual security requirements with proportionate assurance, controlled data exchange rather than email attachments, access to your systems tightly scoped and reviewed, and clear breach notification obligations flowing both ways.
Map sector and international requirements to one control set
GRC Copilot maps a single control library across sector regulation, ISO 27001 and privacy requirements so overlapping obligations are evidenced once.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Regulatory picture
Insurers typically sit under financial sector regulation with operational resilience expectations, alongside privacy law and, depending on geography, specific cyber requirements - the NYDFS rules in New York, DORA in the EU, and central bank frameworks in the Gulf. Expect operational resilience obligations covering important business services, tolerances for disruption and third-party oversight.
Claims fraud and the security overlap
Claims fraud detection and cybersecurity increasingly intersect: account takeover to redirect claim payments, synthetic identities in policy applications, and manipulated documentation - now including AI-generated images and reports. Out-of-band verification for payment detail changes is as important here as anywhere, and the fraud and security functions benefit from sharing signals rather than operating separately.
Where to focus
- Find the data - including extracts, archives and broker-held copies.
- Segment and compensate around legacy systems rather than pretending they are patchable.
- Control the extract problem with better reporting, not just policy.
- Tier and assure the distribution network proportionately.
- Align retention with long-tail obligations deliberately, rather than keeping everything by default.
Frequently asked questions
How long must we keep claims files?
Long-tail lines can require decades. Set the period against the binding obligation and delete what falls outside it rather than retaining everything.
Can we secure a legacy policy system?
Usually by compensating - segmentation, strict access, monitoring - documented as accepted risk with an owner.
How do we handle broker security?
Proportionate contractual requirements with evidence obligations, controlled data exchange, and scoped access that is reviewed.
Does ISO 27001 cover sector requirements?
It provides the management system and most controls, not the sector operational resilience or reporting duties.
Key takeaways
- Special category data plus decades-long retention is a compounding exposure.
- Extracts from legacy systems are where sensitive data escapes.
- Your exposure runs through a distribution network you do not manage.
- Fraud and security signals belong together, especially on payment changes.