Skip to main content
Advertisement
Home

Main navigation

  • Digital Issue Archive
  • Service Directory
  • Awards
  • Advertise
  • Subscribe now

Secondary

  • Travel Insurance
  • Policies & Partnerships
  • Travel Risk Management
  • Travel Trends
  • Hospitals & Healthcare
  • Industry Moves
  • Reviews
International Hospitals & Healthcare Part of the IH&H family
Part of the
IH&H family
International Hospitals & Healthcare

Insurers' cyber vulnerability

Travel Insurance
2 May 2018 | Editorial Team
Featured in Issue 207 | April 2018
Share
Insurers' cyber vulnerability
Insurers' cyber vulnerability

Chris Camacho, Chief Strategy Officer at Flashpoint, explains why the insurance industry is uniquely vulnerable to cyber threats

The insurance industry plays a unique role in modern society, providing individuals and organisations with a sense of financial security when faced with unforeseen circumstances. Unfortunately, the insurance industry is also unique in how and why it is susceptible to fraud, phishing, ransomware, credential theft and other cyber threats. Indeed, many of these threats have become especially familiar to insurers in recent years – largely due to the following circumstances:

Rapid digitisation

Modernisation and innovation have driven the insurance industry to migrate to digital channels in order to broaden the scope of its service offerings. Although these initiatives enable insurers to remain relevant amid a fast-paced competitive landscape, they also increase a company’s exposure to various threats. Similar to how the healthcare sector’s rushed implementation of electronic medical record systems ultimately fuelled an uptick in healthcare data breaches, the insurance industry’s rapid and continual adoption of cloud-based storage and services expanded its attack surface beyond traditional on-premises risks. While these types of systems do not automatically make security incidents and breaches inevitable for insurers, they can give rise to various risks and challenges that ultimately necessitate a more comprehensive and proactive approach to security.

Cybercriminals’ shifting targeting strategies

Another key issue contributing to the insurance industry’s susceptibility to certain cyber threats stems – inadvertently – from a prominent trend across the financial services sector. Specifically, the ongoing adoption of stronger security measures has made financial services companies – though historically seen as prime targets for cybercrime – more and more difficult for adversaries to penetrate. But rather than halt their activity altogether, many of these stringent security measures have instead prompted cybercriminals to shift their attention toward what they perceive to be ‘softer’ targets, such as insurance companies.

A comparatively lax regulatory landscape

Many of the financial services sector’s aforementioned security measures continue to be implemented rapidly and effectively because of a strict regulatory landscape. Financial services companies have long operated under stringent requirements pertaining to secure data storage and encryption, as well as incident and breach disclosure. In the event that a financial services company fails to meet such requirements, the penalties can be severe.

Insurers, however, have historically faced far fewer regulatory requirements when it comes to information security. As a result, the industry has generally been less cognisant of how to address various cyber threats and subsequent business risks. While organisations across all sectors should strive for comprehensive security and risk strategies beyond what is required by regulations, looking to the effective security measures present in financial services and other sectors can be a valuable and insightful starting point.

Where do we go from here?

The above characteristics have undoubtedly helped shape a complex threat landscape for the insurance industry. The good news, however, is that these characteristics are also driving many insurers to rethink their approach to security, risk and, more specifically, intelligence. In response, more companies are coming to regard intelligence as not just a tool to be siloed within their IT department, but rather a core operational requirement. Insurance companies that integrate business risk intelligence into their security and risk strategies programmes glean actionable insights from the deep and dark web communities where adversaries congregate and develop new schemes. By applying these insights to enhance their defences and inform their security and risk strategies, insurance companies can and do gain a decisive advantage over these threats and adversaries.

ITIJ 207 Cover

April 2018
 Issue

Contents include:
Price hikes in Peru
Is something afoot?
Kiwi claims
SCTI reveals 2017 data
Allianz launches payment app
New partnership with Visa
Upgrade your defences
Insurers ‘uniquely vulnerable’ to cyber risk
2017 – a good year for air travel
New survey from IPK International
The economic impact of outbreaks
It’s all about the money

Read full issue
Travel Insurance
2 May 2018
Share

Editorial Team

The Editorial Team updates the ITIJ website daily, and works on features for the print edition. With expert industry knowledge and years of experience in writing about complex travel insurance issues, the Editorial Team is ready to investigate and report on the topics that matter most to ITIJ's readers.

Keep on reading

No results

There are no results available matching your search term.

Why subscribe to ITIJ?

In-depth analysis

In-depth analysis

Unique insights and expert opinions on the latest industry developments

A wider perspective

A wider perspective

Get the global view on the topics that are trending in your region

Breaking news

Breaking news

ITIJ.com has all the latest news relevant to travel insurance and IPMI professionals

Subscribe now
ITIJ IH&H

Footer menu

  • About Us
  • Subscribe
  • Advertise
  • Contact
  • Privacy Policy
  • Terms
  • Voyageur
International Travel & Health Insurance Conferences

Social

  • LinkedIn link
  • Twitter link

© Voyageur Publishing & Events 2026

Close