Insurance carriers, brokers, and insurtech
Penetration Testing for Insurance Companies
Insurers hold complete personal and financial records and run them through policy, claims, and agent systems built over decades. Invadel tests those systems and the networks behind them at a fixed price, with a free retest and evidence written for NYDFS examiners and state regulators.






The stakes
Why insurers get tested differently
An insurer’s data is a full identity: name, address, date of birth, medical history, vehicle, home, and bank details for premium payments and claim payouts. Attackers reach it through agent portals with weak authentication and claims systems that let one claimant’s documents be pulled with another’s identifier. Legacy policy administration platforms sit behind modern web front ends nobody fully understands. Claim payouts also make payment fraud a direct objective.
Insurance is regulated by the states, and many have adopted data security laws modeled on the NAIC model law. Those laws call for a written security program and testing of its controls. Carriers, producers, and adjusters licensed in New York are covered entities under NYDFS 23 NYCRR 500 and owe annual penetration testing. The GLBA Safeguards Rule reaches insurers as financial institutions, and reinsurers and program partners ask for testing evidence in their own diligence.
A generic test treats the customer portal as the whole exposure. Insurance risk lives in the connections: the agent portal feeding the policy system, the claims platform pulling documents from a vendor, the batch integrations with third-party administrators. Testers need to follow a policy from quote to claim across every system it touches. The report has to land in a form the examiner and the state regulator will accept.
What we test
The systems attackers go after first
Policy administration and claims systems
The core platforms and the web front ends over them, tested for authorization flaws between policyholders and claimants, workflow abuse in payouts, and access to underwriting data.
Agent, broker, and policyholder portals
External portals for quoting, binding, servicing, and claims, tested for account takeover, weak onboarding of agencies, and data exposure across books of business.
Underwriting and claims APIs
The interfaces used by comparison sites, third-party administrators, and mobile apps, tested for broken object authorization, excessive data in responses, and unsigned partner callbacks.
Internal network and Active Directory
The corporate and claims-processing network, tested from an assumed foothold for lateral movement, privilege escalation, and segmentation around the systems holding nonpublic information.
Cloud and data platforms
Cloud environments running analytics, document storage, and modern policy systems, tested for IAM escalation, exposed storage of claim documents, and secrets reachable from one compromised role.
Underwriting and fraud models
Pricing, risk scoring, and fraud detection models, tested for manipulation through application inputs, evasion by fraudulent claims, and leakage of the features behind a decision.
Compliance
The frameworks that usually apply
- NYDFS 23 NYCRR 500
The annual internal and external testing carriers, producers, and adjusters licensed in New York owe under §500.5, reported for examiners.
- HIPAA
Security Rule technical safeguard evidence for health plans and the member, claims, and provider systems that handle ePHI.
- SOC 2
For insurtech platforms and third-party administrators whose carrier partners ask for a SOC 2 report alongside the penetration test.
Services
What insurers usually buy
- From $4,200
External Network Penetration Testing
Testing of your internet-facing perimeter: exposed services, remote access, mail, and cloud edges, from $4,200.
- From $6,000
Internal Network Penetration Testing
Testing from an assumed foothold inside your network: Active Directory, lateral movement, and segmentation, from $6,000.
- From $5,200
Web Application Penetration Testing
Manual testing of your web app across the OWASP Top 10, business logic, and every user role, from $5,200.
- From $4,000
API Penetration Testing Services
REST, GraphQL, and SOAP testing for broken authorization, token flaws, and data exposure, from $4,000.
- From $6,800
Cloud Penetration Testing
Configuration and exploitation testing across AWS, Azure, and GCP, from $6,800.
How it runs
Typical engagements
Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.
Typical engagement
Regional carrier ahead of its NYDFS certification
A regional property and casualty carrier licensed in New York needs its annual §500.5 testing complete before the certification of compliance. We run the external test against the agent and policyholder portals and remote access. The internal test then runs from a standard adjuster workstation through Active Directory toward the policy administration system. The CISO receives an examiner-ready report with tester qualifications, remediation tracking, and retest evidence for every finding.
Typical engagement
Insurtech MGA answering a carrier partner’s diligence
A managing general agent building its own quoting and binding platform is asked by its carrier partner for an independent penetration test before the program launches. We test the web application across agent and underwriter roles, the rating API used by comparison sites, and the AWS environment behind them. The test finds a path from an agency account to other agencies’ quotes. The fix is retested and the attestation letter goes into the carrier’s program file.
Typical engagement
Health plan preparing for a multi-state examination
A health plan operating in several states prepares for a coordinated examination under state data security laws and its HIPAA obligations. We test the member portal and mobile app, the claims API used by providers, and the internal network around the claims platform. Findings are mapped to both the Security Rule’s technical safeguards and the state programs. The compliance team receives one report structured for both examiners, plus retest results.
FAQ
What insurers ask
01Which regulations require insurers to run penetration testing?
In New York, 23 NYCRR 500 requires covered carriers, producers, and adjusters to run penetration testing from inside and outside their information systems every year. Many other states have adopted data security laws modeled on the NAIC model law. Those laws call for testing of key controls as part of the information security program. Health insurers also carry HIPAA Security Rule obligations.
02We are an agency or broker, not a carrier. Does this apply to us?
Often, yes. NYDFS covered entities include licensed producers and adjusters as well as carriers, with limited exemptions for the smallest firms that still require a filed notice. Carrier partners also pass testing requirements down through agency agreements. Scope for a broker is usually the agency management system, email tenant, and office network.
03Can you test a legacy policy administration system safely?
Yes. Legacy platforms are identified during scoping and handled under written rules. No destructive actions, agreed testing windows, non-production environments where they exist, and immediate escalation of anything critical. Most of the exposure sits in the web front ends and integrations around the core system, and those can be tested thoroughly without touching batch processing.
04How much does an insurance penetration test cost?
External network testing starts at $4,200, internal network testing at $6,000, web application testing at $5,200, and API testing at $4,000. Each is fixed in writing before work starts with a free retest included. A NYDFS engagement usually combines the external and internal tests, with the portals added where they process nonpublic information.
05What does the examiner actually want to see?
Dated external and internal reports with scope statements naming the systems that hold nonpublic information, and the tester’s qualifications and independence. Remediation tracking with retest evidence, and an executive summary the CISO can use for the board report. Our reports are structured around those items, and the attestation letter summarizes them for reinsurers and partners.
Get a fixed price for your insurance scope
Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.