DrochaidHorizon3.ai
NodeZero/Industries/Insurance
The state of play — Insurance, 2026

Scattered Spider made Insurance the next sector.

Four insurers compromised in weeks. An APRA capital charge for a cyber failure. CPS 230 in force. The regulatory environment and the threat environment moved in the same direction at the same time.

4
major insurers compromised across June and July 2025 — Erie, Philadelphia Insurance, Aflac, and Allianz Life (via a third-party CRM).
Actuarial Review Magazine — Casualty Actuarial Society
14%
of Australian notifiable data breaches came from finance (which includes insurance and superannuation) in H1 2025 — the second-most-breached sector.
OAIC Notifiable Data Breaches statistics, H1 2025
20+
class action lawsuits filed in response to the Aflac breach alone, with regulatory investigations running in parallel. Erie Insurance has also been sued.
HIPAA Journal / Bloomberg Law
The trend

Why Insurance is in the crosshairs

Five shifts shaping the Insurance threat environment — from attacker tradecraft to the regulatory trajectory that is closing the gap between what controls look like on paper and whether they actually work.

Scattered Spider pivoted to insurance, and the tradecraft is help desk social engineering

Across June and July 2025, activity with the hallmarks of Scattered Spider hit Erie Insurance, Philadelphia Insurance, Aflac, and Allianz Life. The common entry pattern was not software exploitation — it was voice-based social engineering of IT help desks to reset MFA and credentials. Allianz Life was breached via a third-party CRM. Help desk process is rarely in the scope of a traditional pentest.

Insurers concentrate the data attackers want — and intelligence about everyone else's security

Life insurance holds detailed health records. General insurance holds property, asset, and location data. Cyber insurance holds the detailed cybersecurity architecture of the insured parties themselves. Kroll's framing captured the double exposure — concentrated PII plus concentrated intelligence about other targets. Aflac's final figure reached approximately 22.6 million individuals globally — about 13.9 million of them in the United States.

The Medibank capital charge reframed CPS 234 enforcement

APRA's $250 million increase to Medibank's capital adequacy requirement was the first time APRA imposed capital consequences specifically for a cyber attack. The tripartite assessment programme has since covered more than 300 banks, insurers, and superannuation trustees — and has revealed widespread, systemic gaps, particularly in third-party risk, control testing, and demonstrable evidence of effectiveness.

CPS 230 adds cyber-adjacent resilience requirements that CPS 234 did not

Since 1 July 2025, APRA-regulated entities must identify critical operations — for insurers, including claims processing and customer service — and demonstrate that those operations can withstand disruption. Material service provider resilience must be assessed and tested. A completed material service provider register was due to APRA from insurers by 1 October 2025.

FAR extended to insurance and superannuation — the personal exposure is now direct

Since March 2025, the Financial Accountability Regime has applied to insurers and superannuation trustees. Specific accountable persons now hold personal accountability for CPS 234 and CPS 230 obligations — with disqualification and deferred remuneration on the line. "We tested annually" is increasingly inadequate as a defensible posture for an accountable person.

On the record

What regulators and experts are saying

Google Threat Intelligence Group is now aware of multiple intrusions in the US which bear all the hallmarks of Scattered Spider activity. We are now seeing incidents in the insurance industry. Given this actor's history of focusing on a sector at a time, the insurance industry should be on high alert, especially for social engineering schemes which target their help desks and call centers.
John Hultquist
Chief Analyst, Google Threat Intelligence Group
June 2025
The network security of each company — [insurers] are so detailed on the cybersecurity each company has. What a wealth of knowledge to have to know how to attack the next company or industry, or develop tools to go in and attack.
Keith Wojcieszek
Global Head of Threat Intelligence, Kroll
June 2025
This attack, like many insurance companies are currently experiencing, was caused by a sophisticated cybercrime group… This was part of a cybercrime campaign against the insurance industry.
Aflac
Public statement on the June 2025 breach
June 2025
What is now required

CPS 230 is in force and FAR now covers insurers

Since 1 July 2025, APRA CPS 230 requires tested operational resilience including critical operations. Since March 2025, the Financial Accountability Regime has extended to insurance and superannuation — accountable persons for information security carry personal accountability, with disqualification and deferred-remuneration consequences.

APRA CPS 234 (Information Security) applies to all APRA-regulated insurers — general, life, private health — and superannuation trustees, with group-wide extension and Australian branch coverage for foreign entities. Paragraph 27 requires systematic testing of control effectiveness commensurate with the rate of change of the environment, the criticality of assets, and the threat environment. CPS 230 (Operational Risk Management) came into force on 1 July 2025 and requires tested resilience of critical operations, including cyber disruption scenarios and material service provider security. The Financial Accountability Regime extended to insurance and superannuation in March 2025, placing CPS 234 and CPS 230 obligations on named accountable persons with personal accountability and deferred-remuneration consequences. The Cyber Security Act 2024 (mandatory ransomware reporting) and the Privacy Act / NDB scheme apply in parallel. Many insurers also adopt ISO 27001 and the Essential Eight voluntarily as CPS 234-supporting frameworks.

Source: APRA — CPS 230 Operational Risk Management
Frameworks that apply
APRA CPS 234 — Information Security

Principles-based information security standard applying to all APRA-regulated insurers and superannuation trustees. Paragraph 27 (testing effectiveness of controls) is the direct hook for continuous validation.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

APRA CPS 230 — Operational Risk Management

1 Jul 2025

In force since 1 July 2025. Requires identification of critical operations (for insurers, including claims processing and customer service), tested business continuity, and material service provider resilience. A completed material service provider register was due to APRA by 1 October 2025. Pre-existing service provider contracts must comply by the earlier of next renewal or 1 July 2026.

Source: APRA — CPS 230

Financial Accountability Regime (FAR) — insurance and superannuation

Mar 2025

Extended to insurance and superannuation from March 2025. Specific accountable persons now hold personal accountability for CPS 234 information security and CPS 230 operational risk obligations. Disqualification and deferred remuneration are at risk for compliance failures.

Source: APRA — Financial Accountability Regime

Cyber Security Act 2024

30 May 2025

Mandatory ransomware payment reporting within 72 hours for entities over $3M turnover. Captures essentially all APRA-regulated entities, brokers, MGAs, TPAs, and insurtechs. A ransomware event at an APRA-regulated insurer now triggers both the CPS 234 72-hour notification to APRA and the Cyber Security Act 72-hour notification to ASD.

Source: Cyber Security Act 2024

Privacy Act reform — statutory tort and expanded enforcement

2024–2026

Introduction of a statutory tort for serious invasions of privacy, expanded OAIC enforcement powers, and tightened obligations around automated decision-making. Insurers — whose models increasingly incorporate algorithmic underwriting and claims decisioning — face a sharper regulatory environment. Both the OAIC and APRA took action following the Medibank incident.

Source: OAIC — Notifiable Data Breaches Scheme
Beyond the platform

NodeZero produces the continuous evidence. Drochaid helps you bridge to the full CPS 234 and CPS 230 programme.

CPS 234 and CPS 230 obligations extend well beyond control testing — they cover policy, governance, operational risk, and tripartite reporting, and many insurers engage a Big 4 or specialist advisor across that breadth. NodeZero directly validates the control-testing obligation, producing the evidence paragraph 27 demands and the tripartite assessor asks for — continuously, not once a year. Drochaid helps you bridge from NodeZero's testing evidence to the full programme: board reporting, tripartite preparation, and the remediation record.

Tripartite preparation
Three-month engagement producing structured evidence for scheduled tripartite assessment — findings mapped to APRA's assessment taxonomy.
CPS 230 critical operations testing
Embedded programme validating that claims processing, underwriting, and customer service critical operations can withstand cyber disruption — including BCP assumption testing and material service provider exposure.
Post-incident validation
Following a breach or a Cyber Security Act notification, rapid validation of remediation — particularly relevant where reporting is underway and the Cyber Incident Review Board may conduct a no-fault review.
Platform credentials

The only autonomous pentesting platform that is:

CPS 234 / 230
Control-by-control
APRA evidence
Essential Eight
Mapped ML1–3
ASD baseline
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See your CPS 234 and CPS 230 gaps before your tripartite assessor does

Book a baseline assessment mapped to paragraph 27 control effectiveness and CPS 230 critical operations