Blog
Cyber Threat Intelligence

Cyber Threat Intelligence for Insurance: The Supply Chain Risk Insurers Can't Ignore

A strong internal security score means little if the brokers, claims processors, and software vendors an insurer depends on are the weak link. This blog breaks down where insurance supply chain risk sits and what to do about it.

September 7, 2026
14
min read
Shail Yadav
Marketing Executive
Table of contents
Share

Key takeaways

  • Insurers can pass every internal security check and still be breached through a broker, claims processor, or software vendor they rely on.
  • Approximately 59% of breaches among the top 150 insurance companies involve third-party attack vectors, which is more than double the cross-industry average.
  • The weakest links sit furthest from the carrier itself: agencies, brokers, and insurance-specific software providers consistently score lowest for security.
  • More than half of insurers have had at least one compromised credential exposed in the past two years. This exposure is often tied to a third-party system.
  • Fourth-party risk, the vendors of an insurer's vendors, is where most supply chain due diligence still falls short.

In CYJAX’s previous look at cyber threat intelligence for the insurance sector, we covered why insurers are targeted, how attackers get in, and why a growing digital footprint keeps expanding the attack surface. That article touched on supply chain exposure as one piece of a wider picture. This one goes further into the insurance ecosystem itself, because for most insurers, the supply chain is not a peripheral risk, it is the primary one.

An internal security score only tells half the story

An insurer can invest heavily in its own defences, patch on schedule, train staff, and still get breached. That is because a modern policy rarely touches only the carrier's own systems. A single claim might pass through a broker's portal, a third-party administrator's platform, an insurtech provider's API, and a cloud host before it ever reaches the insurer's core infrastructure. Each handover is a point where the carrier's own controls no longer apply.

Research from SecurityScorecard puts a number on this. Across the top 150 insurance companies studied, 59% of breaches involved a third-party attack vector. This is more than double the 29% cross-industry average. Third-party software and IT providers alone accounted for 50% of those breaches. Carriers made up roughly 27% of the companies studied yet represented half of all firms hit through a third party, a clear sign that the exposure sits disproportionately with the largest, most data-rich players.

Where the ecosystem breaks down

The same research found a clear tiering effect across the insurance supply chain. Carriers and reinsurers scored highest for security, in the high 80s out of 100. Third-party claims administrators sat in the middle. Agencies, brokers, and insurance-specific software and IT providers scored lowest in the low-to-mid 80s. That gap matters because it is precisely these lower-scoring segments that carriers depend on to sell policies, process claims, and run day-to-day operations.

It is worth breaking down where the exposure sits:

  • Brokers and agencies. Often smaller organisations with limited security budgets, yet holding policyholder data across multiple insurers at once. A single compromised broker can expose several carriers simultaneously.
  • Claims processors and third-party administrators. Handle high volumes of sensitive claims data and frequently connect directly into insurer systems, making them an efficient route in for attackers.
  • Insurtech providers. Fast-moving by design, often prioritising product velocity over mature security practices, and increasingly holding real-time access to underwriting and pricing data.
  • Software vendors. Legacy policy administration platforms and specialist insurance software are common fixtures across the sector, and a single vulnerable product can affect every insurer that licenses it.
  • Cloud providers. The infrastructure layer underneath most of the above, where a single misconfiguration or outage can ripple across multiple insurers at once.

Credential exposure compounds all of this. More than half of the companies studied (56%) had at least one compromised credential surface in the past two years. Reused or stolen logins remain one of the simplest ways for an attacker to move from a vendor's environment into an insurer's own.

The fourth-party blind spot

Most third-party risk programmes stop at the first layer: due diligence on direct vendors, contractual security requirements, the occasional audit. Far fewer extend that scrutiny to the vendors those vendors rely on. This fourth-party layer, the sub-processors, hosting providers, and software dependencies sitting behind a broker or claims platform is where risk most often goes unmonitored. The MOVEit file transfer compromise showed exactly this dynamic in practice: a single vulnerability in one widely used product led to breaches at organisations that had never directly assessed the tool. This is because it was buried several layers down in a vendor's own stack.

For UK insurers specifically, the stakes attached to getting this wrong are rising. The UK cyber (re)insurance sector wrote around £13.2 billion in gross premium in 2025, and UK insurers paid out £197 million in cyber claims in 2024. This is a 230% year-on-year increase. Supply chain and third-party incidents are a growing share of what sits behind those figures, and they are exactly the kind of exposure that traditional perimeter security cannot see.

CYJAX’s previous article noted that 90% of UK insurance professionals had experienced at least one supply chain cyber incident in the past year, with 94% ranking it among their top three concerns. The concern is clearly there. The visibility to act on it, consistently, is what is missing.

Where CTI fits into supply chain risk

An insurer cannot audit every broker, TPA, and software vendor in its network on a continuous basis. However, it can gain visibility into which of those relationships are the highest risk right now. Cyber threat intelligence gives security teams insight into which vendors are showing signs of compromise, which vulnerabilities in widely used insurance software are being actively exploited, and where credential leaks tied to the supply chain are surfacing on criminal marketplaces, often before a breach notification ever arrives.

CYJAX works with insurers to extend that visibility beyond the carrier's own perimeter and into the ecosystem it depends on. If your organisation wants a clearer picture of where its real exposure sits across brokers, TPAs, and vendors, book a demo to see how tailored threat intelligence supports supply chain risk management.

FAQs

Frequently asked questions

Because most of an insurer's operations depend on external parties, brokers, claims processors, Insurtech providers, software vendors, and cloud hosts, each of which sits outside the carrier's direct control. A weakness at any one of them can expose the insurer regardless of how strong its own defences are.

Agencies, brokers, and insurance-specific software and IT providers consistently score lowest for security across the sector. Third-party software and IT vendors account for around half of all third-party breaches.

Fourth-party risk refers to the vendors and sub-processors that an insurer's own suppliers rely on. It is rarely assessed directly, which makes it a common blind spot, as shown by incidents like the MOVEit compromise that affected organisations with no direct relationship to the vulnerable software.

CTI gives security teams early visibility into compromised vendors, actively exploited vulnerabilities in third-party software, and leaked credentials tied to the supply chain, allowing them to act before a partner's incident becomes their own.

As covered in our first article on the insurance sector, insurers face commercial pressure to integrate with more third parties at the same time as adversarial pressure targeting those same connections. Supply chain risk sits directly at the intersection of both.

Subscribe for weekly updates

Receive our latest cyber intelligence insights delivered directly to your inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share
Get started

Get Started with CYJAX CTI

Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.

Link Copied