Skip to content

Cyber Insurance News

The Leading Source for Cybersecurity Insurance News, Insights and Data

Third-Party Cyber Risks Endanger Insurance Industry: 59% of Breaches Linked to Vendors

Posted on February 6, 2025February 6, 2025 By Martin Hinton

A new report from SecurityScorecard reveals some interesting details about third-party cyber risks in insurance. Among them, 59% of insurance industry breaches stem from third-party attack vectors. These findings underscore vulnerabilities in the supply chain that expose critical policyholder data to cyber threats. The study analyzed 150 top insurance firms, revealing an industry struggling with cybersecurity challenges despite maintaining an average security rating comparable to other sectors.

SecurityScorecard logo featuring a geometric purple icon next to the company name in bold, black text.
Carriers Most at Risk Due to Supply Chain Weaknesses

Insurance carriers comprised 27% of the study sample while accounting for 50% of third-party breaches. Carriers generally maintain stronger security postures, but their reliance on low-scoring brokers, claims processors, and IT vendors increases their exposure. Attackers exploit these weaker links to infiltrate more secure organizations.

Andrew Correll, Senior Director of Cyber Insurability at SecurityScorecard, warned that cyber risks extend far beyond a company’s immediate defenses, emphasizing the need for stronger third-party risk management (TPRM) strategies. “Insurance companies’ reliance on technology to manage daily operations has outpaced their ability to secure it. Cyber risks don’t stop at the first layer of defense,” he said.

Key Findings: Industry Faces Elevated Breach Rates and Cyber Risks
  • 28% of insurance firms suffered breaches, higher than the S&P 500 (21%) and twice the rate of the U.S. energy sector (14%).
  • Over half (56%) of companies had at least one compromised credential in the past two years.
  • Malware infections and device compromises affected 17% of insurance firms in 2023.
  • The leading security risks include weak application security (40%), DNS health issues (29%), and network security flaws (20%).
Ransomware Attacks Dominate Industry Threats

Ransomware remains the insurance industry’s most prevalent cyber threat; Every known attack attributed to a threat actor involved ransomware, with groups like LockBit and BlackCat exploiting weak vendor defenses. The 2023 MOVEit software breach, which compromised multiple companies, demonstrated how ransomware groups scale attacks by targeting supply chains.

Geographic Disparities: U.S. Companies More Likely to Be Breached

Despite having higher security ratings, U.S. insurance firms reported the most breaches. 69% of breached companies were based in the U.S., making them prime targets for cybercriminals. Chinese insurance firms scored lowest in security, raising risks for international partners.

Industry Recommendations: Strengthening Cyber Resilience
  1. Stronger Vendor Oversight – Insurance carriers must assess their third-party and fourth-party vendors, ensuring proper TPRM frameworks.
  2. Geographic Risk Awareness – Firms working with U.S. and Chinese partners should implement stricter cybersecurity controls.
  3. Reject Ransom Payments – Paying ransoms emboldens attackers and doesn’t guarantee data recovery.
Conclusion

Cyber risks in the industry threaten both customer trust and financial stability to address third-party cyber risks. With third-party breaches at record highs, insurers need to take proactive security measures to safeguard sensitive policyholder data.

Other News: SecurityScorecard Report Highlights Escalating Supply Chain Cyber Risks for Global 2000(Opens in a new browser tab)

Martin Hinton

Martin Hinton is the Executive Editor and Publisher of Cyber Insurance News and Information. With over three decades of journalism experience across six continents, his work encompasses investigative reporting, documentaries, and coverage of cultural, political, and business news. To learn more about his career, click on his name to visit his LinkedIn page.

Cyber Insurance Best Practices, Cyber Insurance Carriers & Brokers, Cybersecurity Report Tags:Cyber liability Insruance, Cyber Risk Management, Cyber threats, Cybersecurity, Data Breach, insurance industry, Ransomware, SecurityScorecard, supply chain security, Third-Party Risk, TPRM

Post navigation

Previous Post: Converge Cyber Insurance Expands – New Underwriting Capacity from Obsidian
Next Post: MFA Security Gap: Why It Puts Cyber Insurance Coverage and Business Security at Risk

Related Posts

  • IBM 2025 Cybersecurity Report: Credential Theft Skyrockets AI & Cybersecurity
  • Reinsurers Face Challenges in Cyber Insurance Market  Cyber Insurance
  • Tips for Today’s Cyber Insurance Market: Practical Report for CISO’s/Execs from Microsoft Cyber Insurance Best Practices
  • Personal Cyber Insurance Claims Jumped Even More from 2021-2 than Commercial: Regional Insurer Acuity  Cyber Insurance Best Practices
  • It’s Tough to Make Predictions Concerning the Cyber Insurance Market — Especially About the Future  Cyber Insurance Best Practices
  • Should Ransomware Payments Be Banned? Cyber Insurance Best Practices

Get the Cyber Insurance Newsletter

Receive weekly updates on the top news on cyber insurance.

Cyber Insurance News

Cyber Insurance News
In this clip from our latest podcast episode, Dan Candee, CEO of Cork Protection, dives into a critical topic that hits close to home: Cybersecurity for Main Street businesses.

🛡️ With a background in enterprise-level cybersecurity on Wall Street and a personal connection to small business through his family, Dan shares why Cork focuses on protecting small and mid-sized businesses from rising cyber threats.

🚨 "The threat actors are getting better, and they're coming after Main Street more and more."

👉 Discover why Main Street is being underserved in today's digital threat landscape and how Cork is filling that gap with a unique value proposition.

🔗 Learn more about Cork: corkinc.com
🎧 Full Podcast Episode: www.youtube.com/@CyberInsuranceNews/podcasts

📣 Don't forget to LIKE, SUBSCRIBE, and hit the 🔔 notification bell so you never miss a powerful conversation.

#Cybersecurity #SmallBusiness #MainStreet #DanCandee #CorkProtection #TechForGood #SMBs #PodcastClip #CyberThreats #BusinessSecurity
Cybersecurity for Main Street: Dan Candee on Protecting Small Businesses | CEO of Cork Protection
SMB Cyber Threats - In this episode of the Cyber Insurance News Podcast, host Martin Hinton talks with Dan Candee, CEO of Cork Protection, about the rising tide of cyber threats targeting small and mid-sized businesses (SMBs). Dan shares his journey from Main Street entrepreneur to cybersecurity leader, offering real-world insight into the threat landscape, financial vulnerabilities, and how AI and managed service providers (MSPs) can help fortify business resilience.

We explore:
• Why Main Street is more vulnerable than Wall Street
• Common SMB cybersecurity blind spots (like ACH fraud)
• The evolving role of managed service providers
• How Cork Protection blends cybersecurity and cyber insurance
• Real-world attack case studies and practical advice for SMBs

Whether you’re a small business owner, MSP, or cyber pro, this episode unpacks how to prepare, prevent, and protect your organization in today’s digital world.

📌 Topics: cybersecurity, cyber insurance, social engineering, SMB protection, ransomware, AI in security, MSPs

🎙 Guest: Dan Candee, CEO of Cork Protection
📢 Host: Martin Hinton, Executive Editor, Cyber Insurance News

👉 Don’t forget to like, comment, and subscribe for more insights on cyber insurance and digital defense!

#CyberSecurity #CyberInsurance #SMB #AI #CyberPodcast #BusinessResilience #smallbusiness #sme
00:00 Introduction - Dan Candee and Cork Protection
02:27 The Importance of Cybersecurity for Small Businesses
05:29 Understanding Cyber Threats and Their Impact
08:26 The Role of Managed Service Providers in Cybersecurity
11:24 24Financial Protection and Cyber Insurance Solutions
14:01 Leveraging AI in Cybersecurity
16:53 Navigating Cyber Insurance Policies
19:56 Empowering Small Businesses with Knowledge
21:52 The Future of Cybersecurity and Community Resilience
26:05 MSP/ MSSP The Lingo decoded
29:05 Finals Thoughts and a bit of Hope!
SMBs Are Cyber Targets | Dan Candee on Cyber Resilience & AI | Cyber Insurance News Podcast EP#6
Cyberattack on Small Business is on the rise—and AI is making it worse. In this episode of the Cyber Insurance News Podcast, host Martin Hinton sits down with William Altman of CyberCube to unpack how AI is enabling threat actors to more efficiently target and exploit small businesses.

🔐 From credential stuffing to brute force attacks, William explains how cybercriminals use AI to bypass login portals and MFA solutions—putting millions of small business owners at risk.

🎙️ Timestamps:
0:00 - Introduction
6:26 - William Altman on AI and threat actors
6:50 - Credential stuffing, brute force & reused credentials
10:00 - What small businesses can do right now
14:20 - The future of AI in cybercrime

🎧 Don’t miss this crucial update on the cybersecurity landscape for small businesses. Subscribe and stay informed.

#cyberattack #smallbusiness #AI #cybersecurity #CyberCube
Cyberattack on Small Business: How AI Supercharges Cyber Threats | William Altman @CyberCube"
Load More... Subscribe

Categories

  • 8-K
  • AI & Cyber Insurance
  • AI & Cybersecurity
  • Critical Infrastructure cyber insurance and security
  • Cyber Cat Bonds/Cyber Catastrophe Bonds
  • Cyber Insurance
  • Cyber Insurance APAC
  • Cyber Insurance Best Practices
  • Cyber Insurance Captive
  • Cyber Insurance Carriers & Brokers
  • Cyber Insurance Claims
  • Cyber Insurance EU
  • Cyber Insurance Financial Institutions
  • Cyber Insurance for Government
  • Cyber Insurance for Healthcare
  • Cyber Insurance for Schools
  • Cyber Insurance for SMEs/SMBs
  • Cyber Insurance For Startups
  • Cyber Insurance for Utilities
  • Cyber Insurance Geographic Markets
  • Cyber Insurance Industry Groups
  • Cyber Insurance Investments and M&A
  • Cyber Insurance Jobs
  • Cyber Insurance Laws & Regulations
  • Cyber Insurance Litigation
  • Cyber Insurance Market Size
  • Cyber Insurance MENA
  • Cyber Insurance News & Information Podcst
  • Cyber Insurance People
  • Cyber Insurance Policies & Strategies
  • Cyber Insurance Premiums
  • Cyber Insurance Reports
  • Cyber Insurance Settlements
  • Cyber Insurance Sunday – Upload
  • Cyber Insurance Systemic Risks
  • Cyber Insurance Tech
  • Cyber Insurance Threats
  • Cyber Insurance UK
  • Cyber Insurance Underwriting
  • Cyber Insurance Wholesaler
  • Cyber Regulations
  • Cyber War Exclusions
  • Cybersecurity
  • Cybersecurity and Credit Ratings
  • Cybersecurity for SMBs
  • Cybersecurity in Education
  • Cybersecurity Investment
  • cybersecurity jobs
  • cybersecurity M&A
  • Cybersecurity people
  • Cybersecurity Report
  • Cybersecurity Training
  • Department of Homeland Security
  • EU Cybersecurity
  • Insurance Linked Securities/ILS
  • Insurance Loss Warranty contract/ILW
  • Managed Service Providers
  • National Association of Insurance Commissioners' (NAIC) model cybersecurity law
  • Non-criminal Claims/Non-Malicious Claims
  • Opinion/Commentary
  • Personal Cyber Insurance
  • Personal CyberSecurity
  • Ransomware Insurance
  • Reinsurance
  • Risk Modeling
  • SEC Cyber Disclosure Rule
  • Small Business
  • Supply Chain Cybersecurity And Insurance

Send Ideas, Requests & Comments




    Tags

    AI AI in Cybersecurity Artificial Intelligence At-Bay Beazley CFC Chubb Cloud Security Coalition Corvus Cowbell Cowbell Cyber crowdstrike cyber attack Cybercrime CyberCube cyber insurace cyber insurance cyberinsurance cyber insurance for small businesses Cyber Insurance Market Cyber liability Insruance cyber liability insurance cyberliabilityinsurance Cyber Resilience Cyber Risk Cyber Risk Management cyber security Cybersecurity cybersecurity insurance Cyber threats Data Breach Data Breaches Howden Lloyds Marsh Microsoft personal cyber insurance phishing Ransomware Ransomware Insurance Resilience Risk Management SecurityScorecard small business
    • Cyber Insurance Books
    • Cyber Insurance Reports & Documents
    • Cyber Insurance Acronyms/Terms
    • Cyber Insurance Companies: Carriers, Brokers & Vendors
    • Industry Response: Potential Federal Insurance Response to Catastrophic Cyber Incidents
    • Ransomware Insurance
    • How Much Is Cyber Insurance?
    • Considerations for Buying Cyber Insurance
    • Cyber Liability Insurance Near Me
    • Cyber Insurance Quote
    • Newsletter
    • Legal Analysis & Full Text of 2023 SEC Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
    • Glossary
    • About Cyber Insurance News
    • Privacy Policy

    • You Just Raised $100m. What To Do? One Step: Hire a New CTO  Cyber Insurance Carriers & Brokers
    • Forget Fender Benders — What Happens if a Carrier Insures a Car that Wrecks the Electrical Grid? Cyber Insurance Best Practices
    • Cyber Insurers Tighten Security Requirements for 2024 Policies Cyber Insurance Reports
    • AI Cybersecurity Threats: A Dominating Force in Arelion’s Latest Report Cyber Insurance
    • Companies Are Buying Cyber Insurance & Making (Repeat) Claims, But Ransomware Is Not Covered By About 30% of the Policies: Delinea Survey Cyber Insurance
    • BOXX Insurance and Zurich Insurance Group Launch Personal Cybersecurity App Cybersecurity
    • Cyber Insurance Helps Hospital Recover from Hack & Identify Location of Stolen Data Cyber Insurance
    • Cyber Insurance Market is poised for substantial growth – Report Cyber Insurance Market Size

    Related Cybersecurity Sites

    http://www.whatiscyberliability.com

    https://www.whatiscyberinsurance.com

    http://www.ddosattacktutorial.com

    http://www.ransomwareremovaltool.com

    Our Privacy Policy: https://cyberinsurancenews.org/privacy-policy/

    Copyright © 2024 Cyber Insurance News.

    Powered by PressBook Premium theme