Cybersecurity for
Insurers and Brokers

Policy administration, claims and the broker network — assessed as one connected estate, because that is how an attacker reaching policyholder data experiences it.

Insurance analyst working through risk figures and charts

What Security Means
In Insurance

Keeping policyholder data where it belongs.

Insurers hold an unusually rich concentration of personal data: identity documents, financial information, vehicle and property detail, and in medical lines, health records that the Data Protection Act treats as a sensitive category with heightened obligations. The value of that data to an attacker is independent of your premium income, which is why smaller insurers are targeted as readily as large ones.

The estate is also unusually distributed. Policy administration, claims handling, broker and agent portals, aggregator integrations, assessors, garages, medical providers and payment partners all touch the same records, frequently through interfaces built years apart to different standards. Assessing any one component in isolation misses the paths that run between them.

Our insurance work maps those paths first, then concentrates testing where policyholder data and claims authorisation are reachable — including the broker and partner access that sits outside your own control environment.

Where Insurance
Actually Gets Hit

Broker and agent portal credential abuse

Portals issued to intermediaries extend access to policyholder data to organisations whose security you do not run. Shared logins, no multi-factor authentication and no per-account anomaly baseline are the common findings.

Claims fraud enabled by data access

Where the same interface permits both claims lookup and claims adjustment, used by a broad group, the fraud path is internal and looks like ordinary work. Dual authorisation above a threshold and append-only logging change the picture.

Sensitive health data in medical lines

Medical insurance brings health records into scope, which the Act treats as sensitive personal data. Retention, access control and the onward flow to providers and third-party administrators all need to withstand specific scrutiny.

Legacy policy administration platforms

Long-lived core systems often predate the controls now expected around them — weak authentication, unencrypted interfaces, no meaningful audit trail. Compensating controls and segmentation are usually more realistic than replacement.

Premium payment diversion

Business email compromise against finance and client-facing teams redirects premium and claims payments without touching your systems. The control that stops it is procedural: out-of-band verification on a number held on file beforehand.

Aggregator and comparison integrations

Quote and bind integrations hand data to partners at volume. Credentials scoped wider than the use case, no rate limiting and no per-partner traffic baseline are the pattern we find most often.

Built Around
Your Constraints

The sequence below is what a insurance engagement looks like in practice — shaped by what your environment can and cannot tolerate.

Talk to our Insurance team
01

Map where policyholder data actually lives

We produce the data map the Act effectively requires — every system holding personal data, its lawful basis, its retention rule, and the downstream parties it flows to. It is the foundation for everything that follows.

02

Assess the intermediary edge

Broker, agent, assessor and provider access is tested as its own trust boundary, with recommendations you can actually impose through your intermediary agreements rather than through your own infrastructure.

03

Separate read from write in claims tooling

We review operational entitlements against what each role genuinely needs, and design the approval and logging changes that make internal fraud detectable without slowing legitimate claims handling.

04

Build the compliance evidence pack

Findings land mapped to the Data Protection Act, its subsidiary regulations and ISO/IEC 27001:2022, with the records a regulator or a reinsurer’s due diligence would ask to see.

What You Are
Held To

Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.

Data Protection Act, 2019
The central instrument for insurers. Health data in medical lines falls into the sensitive category, attracting stricter conditions for processing and a lower tolerance for over-broad access.
Insurance Regulatory Authority supervision
The IRA supervises licensed insurers and intermediaries in Kenya, including governance and risk management expectations that a security programme has to be able to evidence.
Data Protection (General) Regulations, 2021
Adds operational detail on data subject rights, impact assessments and transfer conditions — the parts of the Act that translate most directly into engineering requirements.
ISO/IEC 27001:2022
Commonly requested by reinsurers and corporate clients during due diligence, and a practical structure for an insurer’s own control documentation.

Reading For
Insurance Teams

All publications

What Insurance Clients
Ask First

More than it appears. Segmentation around the platform, access control and entitlement review on top of it, logging exported to somewhere the platform administrators cannot alter, and contractual security requirements on the vendor are all within your control without touching their code.
Where you determine the purpose and means of the processing, you carry controller duties regardless of who holds the records operationally. Establishing whether each intermediary is a processor, a joint controller or an independent controller is an early and consequential step.
Yes, where your agreements permit it or the intermediary consents. We also help draft the security schedule for those agreements so the right to assess exists in the next contract cycle.