Cyber Threat Intelligence for the Insurance Sector: A Sector Under Two Kinds of Pressure
The insurance sector faces mounting pressure from both commercial growth and a persistent, evolving cyber threat landscape. This blog examines why insurers remain key targets, where their security gaps lie, and how cyber threat intelligence helps close the gap between ambition and resilience.

Key takeaways
- The insurance sector is being pressed from two directions at once: commercial pressure to modernise and grow and cyber pressure from attackers drawn to the data insurers hold.
- Phishing, stolen credentials, and unpatched systems remain the most common routes attackers use to reach policyholder data.
- Insurance firms score well on paper for overall security, yet a disproportionate share still suffer breaches compared with sectors like US energy.
- Application security, DNS health, and network security are the weakest points across the sector, particularly among brokers, agencies, and specialist software providers.
- The financial cost of a breach continues to climb, while the industry itself is still forecast to grow.
Cyber Threat Intelligence for the Insurance Sector: A Sector Under Two Kinds of Pressure
Insurance has always been a data business. Every policy, claim, and renewal depends on the industry holding, analysing, and trusting vast quantities of personal and financial information. That dependency is now the sector's greatest vulnerability as much as its greatest asset.
Insurers today sit under two distinct forms of pressure. The first is commercial: a market that continues to grow steadily, pushing firms to adopt new technology, integrate with more third parties, and deliver faster, more personalised services to policyholders. The second is adversarial: a threat landscape that treats every one of those same systems as an entry point. Understanding how these two pressures interact is central to building an effective CTI strategy for the sector.
Why insurers are such an attractive target
Three structural factors make insurance firms a persistent target for cybercriminals.
- The first is the sensitivity of the data itself. Much like the wider financial services sector, insurers process large volumes of sensitive data tied directly to individual policyholders. This information underpins how insurers price, personalise, and underwrite policies. As such, it is commercially valuable and by extension, valuable to criminals seeking to monetise or exploit it.
- The second is a growing attack surface. As insurers use technology to deliver real-time quotes, personalised products, and digital-first customer journeys, they inevitably expand the number of systems, integrations, and third parties that need defending. Each new digital touchpoint introduces the potential for a new vulnerability, and each new process introduces the potential for human error.
- The third is simple scale. The insurance industry is used by a significant share of the population. In the UK, 14% of adults, which is around 7.6 million people, held private medical insurance in 2024. This was up from 6.7 million in 2020, as rising NHS wait times pushed more people and employers toward private cover. That kind of reach means a single breach can expose data belonging to millions of policyholders at once, which is precisely the leverage that makes insurers appealing targets for extortion and data theft.
How attackers are actually getting in
Despite the sector's growing sophistication, the methods attackers rely on remain largely unchanged.
Phishing and social engineering continue to be the most common entry point. Attackers craft emails which are designed to look as though they are from a trusted vendor, partner, or colleague. These emails are used to persuade an employee to click a malicious link or disclose sensitive credentials. Because insurance firms work with large networks of brokers, agents, and third-party administrators, there are more plausible-looking senders for attackers to impersonate.
Credential compromise follows closely behind. Reused or stolen passwords give attackers a key entry point, where they can often go undetected for extended periods once inside.
Unpatched vulnerabilities can also have a significant impact. Legacy policy administration systems and internet-facing applications, some running for years without significant modernisation, frequently carry known weaknesses that attackers can exploit with minimal effort once identified.
A security posture that looks solid until you look closer
On the surface, the insurance sector's security performance appears reasonably strong. The industry's average security score is close to the broader cross-sector benchmark at 86 against 88.
However, research found that 90% of UK insurance professionals had experienced at least one supply chain cyber incident in the past year. Approximately 94% ranked the issue among their top three concerns. As such, a strong average score has seemingly not translated into fewer incidents.
Digging into where the weaknesses sit tells the more useful story. UK insurers depend on an extensive network of brokers, agencies, claims processors, and specialist IT vendors to operate day-to-day. It is this exact layer of the supply chain that consistently carries the greatest cyber risk. A single incident at one shared vendor can have a significant impact, disrupting several insurers at once and turning what looks like an isolated weak link into sector-wide exposure.
The cost of getting it wrong keeps rising
Security failures in insurance rarely stay contained to a single system. Given the volume and sensitivity of the data involved, a breach in this sector tends to be expensive by any measure.
Globally, the average cost of a data breach reached $4.88 million USD in 2024, the highest figure recorded to date. For an industry built on assessing and pricing risk, that number is difficult to ignore. It represents not just remediation and regulatory exposure, but reputational damage in a market where trust is the product being sold.
Growth and risk are rising together
The commercial pressure on insurers is not slowing down to accommodate better security. The UK general insurance industry's revenue is forecast to grow at a compound annual rate of 1% over the five years through 2026-27, reaching £90.8 billion. Additionally, there is an estimated 2.9% growth in 2026-27 alone.
That growth is a positive signal for the industry, but it also means more policies, more data, more digital infrastructure, and more third-party relationships to secure. Growth without a corresponding investment in threat visibility simply widens the gap between commercial ambition and cyber resilience.
Where cyber threat intelligence fits in
The pattern across the insurance sector is consistent. Attackers are not relying on novel techniques, rather they are exploiting the same phishing lures, reused credentials, and unpatched systems. The sector's challenge is not a lack of security spend, it is a lack of visibility into where the next attack is most likely to come from, and which part of an increasingly complex supply chain is most exposed.
This is where cyber threat intelligence becomes essential rather than optional. Understanding which threat actors are actively targeting insurers, which flaws are being weaponised in the wild, and where a firm's suppliers and brokers may be introducing risk allows security teams to move from reacting toanticipating incidents.
CYJAX works with organisations across regulated and high-value sectors, including insurance, to provide the intelligence needed to see threats before they materialise into breaches. If your organisation wants to understand its real exposure across its supply chain, brokers, and internal systems, book a demo with CYJAX to see how tailored threat intelligence can support your security strategy.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.




