{"id":24935,"date":"2026-04-17T16:46:52","date_gmt":"2026-04-17T16:46:52","guid":{"rendered":"https:\/\/insurance-canada.ca\/?p=85453"},"modified":"2026-04-17T16:46:52","modified_gmt":"2026-04-17T16:46:52","slug":"triple-i-fenix24-report-identifies-emerging-cybersecurity-priorities-for-insurers","status":"publish","type":"post","link":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/2026\/04\/17\/triple-i-fenix24-report-identifies-emerging-cybersecurity-priorities-for-insurers\/","title":{"rendered":"Triple-I\/Fenix24 Report Identifies Emerging Cybersecurity Priorities for Insurers"},"content":{"rendered":"<p>Malvern, PA (Apr. 2, 2026) \u2013 The Insurance Information Institute (Triple-I), in partnership with Fenix24, is pleased to announce the publication of a new report examining how insurance companies are managing their own cybersecurity risks and where critical vulnerabilities remain: <a href=\"https:\/\/www.iii.org\/white-paper\/cybersecurity-for-insurers-squaring-safety-with-service-040126\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><i><strong>Cybersecurity for Insurers: Squaring Safety with Service<\/strong><\/i><\/a>.<\/p>\n<p>The report found that while property\/casualty insurers have made impactful cybersecurity investments, gaps remain in areas including patching cadence, authentication practices, and recovery testing, which are all weaknesses that could complicate responses to today\u2019s threat environment. The report draws on a series of conversations with insurance industry executives, with questions aligned to best practices, regulatory requirements and security controls commonly required in cyber insurance underwriting.<\/p>\n<p>\u201cInsurers occupy a paradoxical position in the cybersecurity landscape,\u201d said Sean Kevelighan, CEO, Triple-I. \u201cThey assess cyber risk for policyholders and establish security requirements as conditions of coverage, yet they also need to demonstrate their own cybersecurity practices meet or exceed evolving standards.\u201d<\/p>\n<p>\u201cMost organizations have tested their recovery plans for natural disasters or standard IT outages, but not for ransomware attacks,\u201d said Mark Grazman, CEO of Fenix24. \u201cUnderstanding what actually happens in a ransomware scenario is critical to architecting true resiliency. It\u2019s not just backups at risk, attackers systematically target and destroy infrastructure including Active Directory, identity systems, virtual machines, hypervisors, and even core communications like email. Resiliency planning requires understanding backup survivability, architecture for rehydration, and integrity, along with comprehensive asset intelligence, prioritization of business-critical applications and their associated dependencies. Resiliency is achievable if you know what to architect and that is the power of Fenix24\u2019s insights.\u201d<\/p>\n<h4><b>A Growing Market Facing Evolving Threats<\/b><\/h4>\n<p>The cyber insurance market reached $15.3 billion in net premiums written in 2024 and is projected to grow to $16.3 billion in 2025, according to Munich Re. While ransomware remains a major driver of insured cyber losses, it accounted for only 19% of cyber claims in 2023. Business email compromise and funds transfer fraud represented a far larger share, generating 56% of reported claims. Business interruption accounts for roughly half of the $1 million average cost associated with ransomware incidents, according to NetDiligence.<\/p>\n<h4><b>Key Findings<\/b><\/h4>\n<p>The report identified strengths and areas for improvement across several critical cybersecurity domains:<\/p>\n<ul class=\"bwlistdisc\">\n<li><b>Immutable Backups and Recovery:<\/b> Most insurers implement immutable backups across critical system categories, and most report meeting recovery time objectives for their highest-tier systems. However, recovery tests are often conducted under ideal conditions on a single system rather than across full network recovery, creating a potential gap when a real incident strikes.<\/li>\n<\/ul>\n<ul class=\"bwlistdisc\">\n<li><b>Credentials and Access Management:<\/b> All participating insurers use corporate password vaults and enforce strong password complexity, with user passwords averaging more than 13 characters. All require multi-factor authentication (MFA) for administrative accounts. However, some organizations still permit less secure MFA methods such as SMS messages and email confirmation, which are approaches with known limitations that threat actors frequently exploit.<\/li>\n<\/ul>\n<ul class=\"bwlistdisc\">\n<li><b>Browsing Controls and Attack Surface Management:<\/b> Most insurers implement DNS filtering and block peer-to-peer file transfer and web-based email sites, which are effective measures for limiting threat actor access. Some organizations use \u201csplit tunneling,\u201d which allows employee internet browsing outside of VPN encryption, improving user experience but increasing exposure to phishing, malware and \u201cman-in-the-middle\u201d attacks.<\/li>\n<\/ul>\n<ul class=\"bwlistdisc\">\n<li><b>Patching and Risk Management:<\/b> All participants conduct penetration testing, including social engineering scenarios targeting help desk personnel, which recognizes human defenses are as critical as technical ones. However, only about half deploy security patches monthly. In today\u2019s threat environment, adversaries often exploit newly disclosed vulnerabilities within hours or days of public disclosure, making accelerated patch cycles an emerging best practice.<\/li>\n<\/ul>\n<h4><b>Preparation Over Perfection<\/b><\/h4>\n<p>The study emphasizes systematic preparation, such as tested recovery capabilities and faster patch cycles, over the pursuit of any single \u201cperfect\u201d security solution. Insurers, like all businesses, must balance cybersecurity with user experience and operational performance, making thoughtful risk management essential.<\/p>\n<p>\u201cThe difference between resilience and disaster lies not in perfect prevention but in systematic preparation, validated recovery capabilities and organizational commitment to continuous security improvement,\u201d the report concluded.<\/p>\n<h4 class=\"smallhead\"><b>About the Insurance Information Institute (Triple-I)<\/b><\/h4>\n<p>Since 1960, the Insurance Information Institute (Triple-I) has been the trusted voice of risk and insurance, delivering unique, data-driven insights to educate, elevate, and connect consumers, industry professionals, policymakers, and the media. An affiliate of <a href=\"https:\/\/insurance-canada.ca\/2026\/04\/17\/iii-fenix24-emerging-cybersecurity-priorities\/#TheInstitutes\">The Institutes<\/a>, Triple-I represents a diverse membership accounting for nearly 50% of all U.S. property\/casualty premiums written. Our members include mutual and stock companies, personal and commercial lines, primary insurers, and reinsurers \u2013 serving regional, national, and global markets. For more information, visit <a href=\"https:\/\/www.iii.org\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">www.iii..org<\/a>.<\/p>\n<h4 class=\"smallhead\"><b>About Fenix24<\/b><\/h4>\n<p>Fenix24\u2122 is the global leader in breach recovery, providing assured and battle-tested cyber resilience solutions. With a mission to redefine how organizations recover from cyber incidents, Fenix24 combines expert-driven response, cutting-edge technology, and a proven track record of restoring businesses faster and more securely than ever before.&nbsp;For more information, visit <a href=\"https:\/\/fenix24.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">fenix24.com<\/a>.<\/p>\n<h4 class=\"smallhead\"><b>About The Institutes<\/b><\/h4>\n<p>The Institutes\u00ae are a global not-for-profit comprising diverse affiliates that educate, elevate and connect people in the essential disciplines of risk management and insurance. Through products and services offered by The Institutes\u2019 nearly 20 affiliated business units, people and organizations are empowered to help those in need with a focus on understanding, predicting and preventing losses to create a more resilient world. For more information, visit <a href=\"https:\/\/global.theinstitutes.org\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">global.theinstitutes.org<\/a>.<\/p>\n<p><i>The Institutes is a registered trademark of The Institutes. All rights reserved.<\/i><\/p>\n<p class=\"referencetext\"><i>Source: Insurance Information Institute<\/i><\/p>\n<p> Tags: <a href=\"https:\/\/insurance-canada.ca\/tag\/cyber-risk\/\" rel=\"tag\">cyber risk<\/a>, <a href=\"https:\/\/insurance-canada.ca\/tag\/cyber-security\/\" rel=\"tag\">cyber security<\/a>, <a href=\"https:\/\/insurance-canada.ca\/tag\/insurance-information-institute\/\" rel=\"tag\">Insurance Information Institute (III)<\/a>, <a href=\"https:\/\/insurance-canada.ca\/tag\/priorities\/\" rel=\"tag\">priorities<\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malvern, PA (Apr. 2, 2026) \u2013 The Insurance Information Institute (Triple-I), in partnership with Fenix24, is pleased to announce the publication of a new report examining how insurance companies are managing their own cybersecurity&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[1],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/24935"}],"collection":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/comments?post=24935"}],"version-history":[{"count":0,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/24935\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/media?parent=24935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/categories?post=24935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/tags?post=24935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}