PS ProTech(305) 699-5652
← All posts

Insurance agencies

Protecting policyholder data at an insurance agency

· PS ProTech · 2 min read

To quote and place a policy, an agency collects almost everything a criminal would want: names, dates of birth, Social Security numbers, driver's license numbers, bank details, and for life and health cover, medical history. Most agencies hold this for thousands of people, going back years.

It also arrives and leaves by email all day. That combination is why agencies are worth an attacker's time.

Where the information is exposed

The agency management system. One login reaches every policyholder. If that login is a reused password with no second step, a single stolen credential opens the whole book.

Email. Applications, ID scans and bank details sit in mailboxes for years. A compromised mailbox is a compromised file room.

Carrier portals. Staff sign in to many of them. Attackers send convincing notices asking them to "re-verify" their portal login, as we describe in how AI changed phishing.

Payment changes. A caller with a policyholder's details, or a cloned voice, asks to change where a claim payment or refund is sent.

Your own mailbox, turned against clients. An attacker inside a staff mailbox can send premium invoices with different bank details to your policyholders, from a real address they trust.

What to put in place

  1. Multi-factor authentication on email, the management system and every carrier portal that offers it. See why it comes first.
  2. Individual logins. No shared accounts, so access can be removed for one person and you can see who opened what.
  3. Email security that catches impersonation of carriers and clients.
  4. A call-back rule for any change to payment details. See the call-back rule.
  5. Regular staff training with records. Producers and service staff handle sensitive data constantly. See training that works.
  6. Prompt offboarding. Producers who leave often take up with a competitor. Access should end that day. See the offboarding checklist.
  7. A retention rule. The data you no longer hold can't be stolen. Decide how long you need old applications and delete the rest.

The rules agencies answer to

Many states have adopted insurance data security laws that require licensees to keep a written information security program and to report incidents to the insurance regulator. Federal privacy rules also require firms handling consumers' financial information to safeguard it. Carriers may add their own requirements to your appointment.

The specifics depend on your state and your lines, so check them with your regulator or counsel. This is general information, not legal advice.

An awkward advantage

You sell cyber insurance, or you know people who do. You've seen what the application asks. Your own agency should be able to answer those questions with a clean yes, and that's a fair test. We go through them in what cyber insurers ask.

Our page for insurance agencies covers the threats and what a breach can cost. To see where your agency stands, book a free IT and cybersecurity review.

See what it costs for your firm.

Build a plan in two minutes. No call required.