INSURANCE
IRDAI directs two insurers to conduct IT systems audit
Oct-22-2024

Insurance Regulatory and Development Authority of India (IRDAI) has directed two insurers to carry out audits of their IT systems following concerns over the recent instances of policyholders’ data leaks. The regulator is also in touch with their management to address the vulnerabilities. 

Without naming the insurers, IRDAI said it takes data breaches very seriously and asserted that it will continue to engage with the companies to ensure that the policyholders’ interests are fully protected. Star Health Insurance had recently admitted data breach. The name of the second insurer could not be immediately ascertained. There have been reports of data leaks from two Insurers recently. 

The IRDAI is closely monitoring the situation in case of the concerned insurers and has been in touch with their management. Regular updates are being obtained to ensure that the policyholders’ data and interest are fully protected and the company is taking all steps to arrest the threat posed by this breach. The IRDAI will continue to engage with the insurance companies to ensure that the policyholders’ interests are fully protected. The concerned insurers have been instructed to appoint an independent auditor to undertake comprehensive audit of the company’s IT landscape with the aim that there are no vulnerabilities and the IT system are adequate to meet the scale and complexities of their operations.

As part of the standard operating procedures of the concerned insurers, they reported the cyber incident to the Government and IRDAI. The concerned insurers have ring fenced the impacted IT system by isolating it and at the same time appointed an external IT security company to undertake root cause analysis. The audit firm reported vulnerabilities in the company’s IT system and the methodology used by the threat actor to exploit the same which were acted upon by insurers. The Containment, Eradication and Recoverability plan as suggested by the audit firm are being implemented by the insurers.

Further preventive steps outlined in the report are in the process of implementation to keep the policyholders’ data safe and secure. System upgrades over immediate, short and medium time period, will be acted upon by the insurers. The application programming interface (API) vulnerabilities, Gap assessment and vulnerabilities assessment and penetration testing (VAPT) Issues are at an advanced stage of rectification. The insurers have filed a criminal complaint with the law enforcement agencies against the threat actors. It served legal notice on the social media platform to prevent the threat actor from selling the policyholders data. 

Further, IRDAI has issued an advisory to all insurers to check their IT systems for vulnerabilities and take necessary steps to protect the policyholders’ data. 

  RELATED NEWS >>