SecurityScorecard today released research indicating that 59% of breaches among the top 150 insurance companies involved third-party attack vectors, exposing vulnerabilities in the sector’s supply chain. The report highlights systemic risks posed by cyber threats to the industry, which is critical for safeguarding sensitive financial and personal information.

The interconnected nature of the insurance industry, encompassing carriers, reinsurers, brokers, claims processors, and specialized IT providers, is essential for delivering services. However, it also increases exposure to cyber risks.

Andrew Correll, Senior Director of Cyber Insurability, stated, “Insurance companies’ reliance on technology to manage daily operations has outpaced their ability to secure it. Cyber risks don’t stop at the first layer of defense — they extend deep into the supply chain, where vulnerabilities are harder to detect and even harder to mitigate. Addressing these risks requires a shift in how the industry prioritizes third-party security.”

Key findings from the report include:

  • 28% of companies reported breaches, higher than the S&P 500's 21% and double that of the U.S. energy industry at 14%.
  • 59% of breaches involved third-party attack vectors, more than double the global average of 29%, with half of these initiated by third-party software and IT.
  • Insurance carriers made up 50% of the companies affected by third-party incidents, despite composing only 27% of the total sample.
  • 56% of companies had at least one compromised credential in the last two years.
  • 17% of companies were affected by malware infections and device compromises last year.
  • The lowest-scoring cyber risk factors for the sector are application security, DNS health, and network security.

In light of these findings, SecurityScorecard recommends that the insurance sector enhance its third-party risk management practices. This includes focusing on high-risk partners and ensuring that vendors implement effective third-party risk management programs to mitigate potential breaches. Additionally, the report advises against paying ransomware demands to deter future attacks.

The study evaluates security ratings and breach histories of leading companies in the insurance sector and provides clear insights into its cybersecurity landscape, organized into five segments: insurance carriers, reinsurance companies, agencies and brokers, claims processors, and insurance-specific IT products.