Skip to content

Insurance carriers, brokers, and insurtech

Penetration Testing for Insurance Companies

Insurers hold complete personal and financial records and run them through policy, claims, and agent systems built over decades. Invadel tests those systems and the networks behind them at a fixed price, with a free retest and evidence written for NYDFS examiners and state regulators.

OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology
DTCCCity National BankBrewDogLuluEmeriaIP Telecom

The stakes

Why insurers get tested differently

An insurer’s data is a full identity: name, address, date of birth, medical history, vehicle, home, and bank details for premium payments and claim payouts. Attackers reach it through agent portals with weak authentication and claims systems that let one claimant’s documents be pulled with another’s identifier. Legacy policy administration platforms sit behind modern web front ends nobody fully understands. Claim payouts also make payment fraud a direct objective.

Insurance is regulated by the states, and many have adopted data security laws modeled on the NAIC model law. Those laws call for a written security program and testing of its controls. Carriers, producers, and adjusters licensed in New York are covered entities under NYDFS 23 NYCRR 500 and owe annual penetration testing. The GLBA Safeguards Rule reaches insurers as financial institutions, and reinsurers and program partners ask for testing evidence in their own diligence.

A generic test treats the customer portal as the whole exposure. Insurance risk lives in the connections: the agent portal feeding the policy system, the claims platform pulling documents from a vendor, the batch integrations with third-party administrators. Testers need to follow a policy from quote to claim across every system it touches. The report has to land in a form the examiner and the state regulator will accept.

What we test

The systems attackers go after first

01

Policy administration and claims systems

The core platforms and the web front ends over them, tested for authorization flaws between policyholders and claimants, workflow abuse in payouts, and access to underwriting data.

02

Agent, broker, and policyholder portals

External portals for quoting, binding, servicing, and claims, tested for account takeover, weak onboarding of agencies, and data exposure across books of business.

03

Underwriting and claims APIs

The interfaces used by comparison sites, third-party administrators, and mobile apps, tested for broken object authorization, excessive data in responses, and unsigned partner callbacks.

04

Internal network and Active Directory

The corporate and claims-processing network, tested from an assumed foothold for lateral movement, privilege escalation, and segmentation around the systems holding nonpublic information.

05

Cloud and data platforms

Cloud environments running analytics, document storage, and modern policy systems, tested for IAM escalation, exposed storage of claim documents, and secrets reachable from one compromised role.

06

Underwriting and fraud models

Pricing, risk scoring, and fraud detection models, tested for manipulation through application inputs, evasion by fraudulent claims, and leakage of the features behind a decision.

How it runs

Typical engagements

Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.

Typical engagement

Regional carrier ahead of its NYDFS certification

A regional property and casualty carrier licensed in New York needs its annual §500.5 testing complete before the certification of compliance. We run the external test against the agent and policyholder portals and remote access. The internal test then runs from a standard adjuster workstation through Active Directory toward the policy administration system. The CISO receives an examiner-ready report with tester qualifications, remediation tracking, and retest evidence for every finding.

Typical engagement

Insurtech MGA answering a carrier partner’s diligence

A managing general agent building its own quoting and binding platform is asked by its carrier partner for an independent penetration test before the program launches. We test the web application across agent and underwriter roles, the rating API used by comparison sites, and the AWS environment behind them. The test finds a path from an agency account to other agencies’ quotes. The fix is retested and the attestation letter goes into the carrier’s program file.

Typical engagement

Health plan preparing for a multi-state examination

A health plan operating in several states prepares for a coordinated examination under state data security laws and its HIPAA obligations. We test the member portal and mobile app, the claims API used by providers, and the internal network around the claims platform. Findings are mapped to both the Security Rule’s technical safeguards and the state programs. The compliance team receives one report structured for both examiners, plus retest results.

FAQ

What insurers ask

01Which regulations require insurers to run penetration testing?

In New York, 23 NYCRR 500 requires covered carriers, producers, and adjusters to run penetration testing from inside and outside their information systems every year. Many other states have adopted data security laws modeled on the NAIC model law. Those laws call for testing of key controls as part of the information security program. Health insurers also carry HIPAA Security Rule obligations.

02We are an agency or broker, not a carrier. Does this apply to us?

Often, yes. NYDFS covered entities include licensed producers and adjusters as well as carriers, with limited exemptions for the smallest firms that still require a filed notice. Carrier partners also pass testing requirements down through agency agreements. Scope for a broker is usually the agency management system, email tenant, and office network.

03Can you test a legacy policy administration system safely?

Yes. Legacy platforms are identified during scoping and handled under written rules. No destructive actions, agreed testing windows, non-production environments where they exist, and immediate escalation of anything critical. Most of the exposure sits in the web front ends and integrations around the core system, and those can be tested thoroughly without touching batch processing.

04How much does an insurance penetration test cost?

External network testing starts at $4,200, internal network testing at $6,000, web application testing at $5,200, and API testing at $4,000. Each is fixed in writing before work starts with a free retest included. A NYDFS engagement usually combines the external and internal tests, with the portals added where they process nonpublic information.

05What does the examiner actually want to see?

Dated external and internal reports with scope statements naming the systems that hold nonpublic information, and the tester’s qualifications and independence. Remediation tracking with retest evidence, and an executive summary the CISO can use for the board report. Our reports are structured around those items, and the attestation letter summarizes them for reinsurers and partners.

Get a fixed price for your insurance scope

Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.