Cyber Threat Intelligence for Insurance: The Supply Chain Risk Insurers Can't Ignore
A strong internal security score means little if the brokers, claims processors, and software vendors an insurer depends on are the weak link. This blog breaks down where insurance supply chain risk sits and what to do about it.

Key takeaways
- Insurers can pass every internal security check and still be breached through a broker, claims processor, or software vendor they rely on.
- Approximately 59% of breaches among the top 150 insurance companies involve third-party attack vectors, which is more than double the cross-industry average.
- The weakest links sit furthest from the carrier itself: agencies, brokers, and insurance-specific software providers consistently score lowest for security.
- More than half of insurers have had at least one compromised credential exposed in the past two years. This exposure is often tied to a third-party system.
- Fourth-party risk, the vendors of an insurer's vendors, is where most supply chain due diligence still falls short.
In CYJAX’s previous look at cyber threat intelligence for the insurance sector, we covered why insurers are targeted, how attackers get in, and why a growing digital footprint keeps expanding the attack surface. That article touched on supply chain exposure as one piece of a wider picture. This one goes further into the insurance ecosystem itself, because for most insurers, the supply chain is not a peripheral risk, it is the primary one.
An internal security score only tells half the story
An insurer can invest heavily in its own defences, patch on schedule, train staff, and still get breached. That is because a modern policy rarely touches only the carrier's own systems. A single claim might pass through a broker's portal, a third-party administrator's platform, an insurtech provider's API, and a cloud host before it ever reaches the insurer's core infrastructure. Each handover is a point where the carrier's own controls no longer apply.
Research from SecurityScorecard puts a number on this. Across the top 150 insurance companies studied, 59% of breaches involved a third-party attack vector. This is more than double the 29% cross-industry average. Third-party software and IT providers alone accounted for 50% of those breaches. Carriers made up roughly 27% of the companies studied yet represented half of all firms hit through a third party, a clear sign that the exposure sits disproportionately with the largest, most data-rich players.
Where the ecosystem breaks down
The same research found a clear tiering effect across the insurance supply chain. Carriers and reinsurers scored highest for security, in the high 80s out of 100. Third-party claims administrators sat in the middle. Agencies, brokers, and insurance-specific software and IT providers scored lowest in the low-to-mid 80s. That gap matters because it is precisely these lower-scoring segments that carriers depend on to sell policies, process claims, and run day-to-day operations.
It is worth breaking down where the exposure sits:
- Brokers and agencies. Often smaller organisations with limited security budgets, yet holding policyholder data across multiple insurers at once. A single compromised broker can expose several carriers simultaneously.
- Claims processors and third-party administrators. Handle high volumes of sensitive claims data and frequently connect directly into insurer systems, making them an efficient route in for attackers.
- Insurtech providers. Fast-moving by design, often prioritising product velocity over mature security practices, and increasingly holding real-time access to underwriting and pricing data.
- Software vendors. Legacy policy administration platforms and specialist insurance software are common fixtures across the sector, and a single vulnerable product can affect every insurer that licenses it.
- Cloud providers. The infrastructure layer underneath most of the above, where a single misconfiguration or outage can ripple across multiple insurers at once.
Credential exposure compounds all of this. More than half of the companies studied (56%) had at least one compromised credential surface in the past two years. Reused or stolen logins remain one of the simplest ways for an attacker to move from a vendor's environment into an insurer's own.
The fourth-party blind spot
Most third-party risk programmes stop at the first layer: due diligence on direct vendors, contractual security requirements, the occasional audit. Far fewer extend that scrutiny to the vendors those vendors rely on. This fourth-party layer, the sub-processors, hosting providers, and software dependencies sitting behind a broker or claims platform is where risk most often goes unmonitored. The MOVEit file transfer compromise showed exactly this dynamic in practice: a single vulnerability in one widely used product led to breaches at organisations that had never directly assessed the tool. This is because it was buried several layers down in a vendor's own stack.
For UK insurers specifically, the stakes attached to getting this wrong are rising. The UK cyber (re)insurance sector wrote around £13.2 billion in gross premium in 2025, and UK insurers paid out £197 million in cyber claims in 2024. This is a 230% year-on-year increase. Supply chain and third-party incidents are a growing share of what sits behind those figures, and they are exactly the kind of exposure that traditional perimeter security cannot see.
CYJAX’s previous article noted that 90% of UK insurance professionals had experienced at least one supply chain cyber incident in the past year, with 94% ranking it among their top three concerns. The concern is clearly there. The visibility to act on it, consistently, is what is missing.
Where CTI fits into supply chain risk
An insurer cannot audit every broker, TPA, and software vendor in its network on a continuous basis. However, it can gain visibility into which of those relationships are the highest risk right now. Cyber threat intelligence gives security teams insight into which vendors are showing signs of compromise, which vulnerabilities in widely used insurance software are being actively exploited, and where credential leaks tied to the supply chain are surfacing on criminal marketplaces, often before a breach notification ever arrives.
CYJAX works with insurers to extend that visibility beyond the carrier's own perimeter and into the ecosystem it depends on. If your organisation wants a clearer picture of where its real exposure sits across brokers, TPAs, and vendors, book a demo to see how tailored threat intelligence supports supply chain risk management.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.




