Data Leak Concerns: Irdai Orders IT Audits for Insurers

By By Rediff Money Desk, New Delhi
Oct 21, 2024 17:39
Insurance regulator Irdai has directed two insurers to conduct IT system audits after concerns over data leaks. The regulator is taking steps to protect policyholders' data.
Illustration: Dominic Xavier/Rediff.com
New Delhi, Oct 21 (PTI) Insurance regulator Irdai has directed two insurers to carry out audits of their IT systems following concerns over the recent instances of policyholders' data leaks.

The regulator is also in touch with their management to address the vulnerabilities.

Without naming the insurers, the Insurance Regulatory and Development Authority of India (Irdai) said it takes data breaches very seriously and asserted that it will continue to engage with the companies to ensure that the policyholders' interests are fully protected.

Star Health Insurance had recently admitted data breach. The name of the second insurer could not be immediately ascertained.

"There have been reports of data leaks from two Insurers recently," the regulator said.

In a release, the Irdai said it is closely monitoring the situation in the case of the concerned insurers and has been in touch with their management.

Regular updates are being obtained to ensure that the policyholders' data and interests are fully protected and the company is taking all steps to arrest the threat posed by this breach, the regulator said.

Irdai said it will continue to engage with the insurance companies to ensure that the policyholders' interests are fully protected.

"The concerned insurers have been instructed to appoint an independent auditor to undertake a comprehensive audit of the company's IT landscape with the aim that there are no vulnerabilities and the IT system are adequate to meet the scale and complexities of their operations," the release said.

As part of the standard operating procedures of the concerned insurers, they reported the cyber incident to the government and Irdai, it added.

It also said the concerned insurers have ring-fenced the impacted IT system by isolating it and at the same time, appointed an external IT security company to undertake root cause analysis.

"The audit firm reported vulnerabilities in the company's IT system and the methodology used by the threat actor to exploit the same, which were acted upon by insurers. The Containment, Eradication and Recoverability plan as suggested by the audit firm is being implemented by the insurers," Irdai said.

Further preventive steps outlined in the report are in the process of implementation to keep the policyholders' data safe and secure. System upgrades over immediate, short and medium periods, will be acted upon by the insurers, Irdai said.

Also, the application programming interface (API) vulnerabilities, gap assessment, vulnerabilities assessment and penetration testing issues are at an advanced stage of rectification.

"The insurers have filed a criminal complaint with the law enforcement agencies against the threat actors. It served legal notice on the social media platform to prevent the threat actor from selling the policyholders' data," the regulator said.

Further, Irdai has issued an advisory to all insurers to check their IT systems for vulnerabilities and take necessary steps to protect the policyholders' data.

The regulator said it considers data security as very important and takes data breaches, cyber-attacks on IT systems of insurance companies, etc very seriously.

Cyber security guidelines for insurance companies are in place, which require insurers to put in place robust IT and cyber security frameworks for carrying out their operations, it added.
Source: PTI
Read More On:
irdaicybersecurityinsurancedata leakit audit
DISCLAIMER - This article is from a syndicated feed. The original source is responsible for accuracy, views & content ownership. Views expressed may not reflect those of rediff.com India Limited.

You May Like To Read

MORE NEWS

Dasnac Invests Rs 2,000 Cr in Noida Luxury Housing

Dasnac to invest Rs 2,000 crore in a luxury housing project, Dasnac Westminster, in...

Nephrocare IPO Subscribed 12% on Day 1

Nephrocare Health Services IPO received 12% subscription on day 1. IPO details, price...

Wakefit IPO Subscribed Over 2 Times

Wakefit''s Rs 1,289-cr IPO was subscribed over 2 times on the final day. Details on...

IAN Group to Deploy USD 100M Alpha Fund by 2027

IAN Group to deploy its USD 100 million IAN Alpha Fund in early-stage startups by 2027....

Corona Remedies IPO Subscribed 137 Times

Corona Remedies IPO subscribed 137.04 times on final day. QIBs subscribed 278.52 times,...

India Logistics Cost Down to 9%: Gadkari

Nitin Gadkari says India has met its target to reduce logistics cost to 9% of GDP due...

Coal Mining: Panel Urges Faster Green Clearances

Parliamentary panel urges faster environmental & forest clearances for coal mining...

DCM Shriram & Bayer Crop Science Collaboration

DCM Shriram and Bayer Crop Science partner to explore agricultural opportunities in...

Silver Price Soars to Rs 1.92 Lakh/kg on Global...

Silver prices surge Rs 11,500 to Rs 1.92 lakh/kg in Delhi amid strong global cues. Gold...

Urea Fixed Costs to Rise for Manufacturers

Govt plans to raise fixed costs for urea makers by year-end. Decision expected soon,...

Read More »

Sectoral Indices Market Indicators Listed Companies Gainers Losers Mutual Funds Portfolio Watchlist
© 2025 Rediff.com