A cyber attack on an insurer is not merely an IT outage. It halts claims settlement when policyholders need it most, exposes the KYC and medical data of thousands, invites regulatory sanction, and quietly erodes the trust on which every policy is sold. With the IRA’s Guidance Note on Cybersecurity now in force, cyber risk has moved from the server room to the boardroom, and become a supervised compliance obligation with hard deadlines.

Why Cyber Risk Is Now an Insurance Board Issue

Kenya’s insurance industry has digitised rapidly. Insurers regulated by the Insurance Regulatory Authority (IRA) now onboard customers online, price risk with actuarial engines, process claims through digital platforms, and integrate with bancassurance partners, mobile money, credit bureaus and a growing insurtech ecosystem. Each integration widens the attack surface, and each holds some of the most sensitive personal data any institution keeps such as national ID copies, medical histories, financial records and beneficiary details.

In 2025 the IRA issued its Guidance Note on Cybersecurity for the Insurance Industry, signed by the Commissioner of Insurance. The message was unambiguous: cybersecurity is no longer an IT-department concern but a governance responsibility carrying supervised, enforceable obligations. All licensed insurers and reinsurers are required to familiarise themselves with the Guidance Note and implement it fully and on time. Get Our Insurance IT Audit Compliance Bundle.

24hWindow to report a material cyber incident to IRA
15dDeadline for quarterly incident reports after quarter-end
≥1Board member with cybersecurity expertise required
$5.9MAverage financial-services data breach cost, 2024 (IBM)

A successful attack strikes at four things every insurer exists to protect:

1
Policyholder Protection

Compromise of policy administration, claims or underwriting systems can delay or deny legitimate claims, expose sensitive personal and medical data, and leave vulnerable policyholders without the financial protection they paid for.

2
Operational Resilience

Ransomware against a claims platform or core policy system can freeze settlements, renewals and new business for days, a direct hit to solvency, service and reputation.

3
Market Trust

Insurance is a promise to pay when things go wrong. A publicised breach or a data leak of policyholder records corrodes that promise, driving lapses, distribution-partner flight and reputational damage that outlasts the incident.

4
Regulatory Compliance

The IRA Guidance Note, the Data Protection Act, 2019 and the Computer Misuse and Cybercrimes Act now converge on the insurer. A breach frequently exposes gaps in exactly the governance, reporting and control areas these regimes police, inviting directives, penalties and heightened supervision.

The Core Message

Cyber risk in an insurer is not an IT problem. It is a policyholder-protection, regulatory-compliance and institutional-survival problem, and the IRA Guidance Note has made board and senior-management ownership of it a supervised requirement, not a matter of good practice.

Major Cyber Security Risks Facing Insurers

Across IT audit and assurance work with regulated financial institutions in Kenya and East Africa, the same risk themes recur in the insurance sector, sharpened by the industry’s data sensitivity and its dependence on a chain of third parties:

01 · Policyholder Data Breach

Underwriting files, medical records, ID copies and claims documentation leaking from unsecured databases, misconfigured storage or discarded hardware trigger both IRA and ODPC obligations.

02 · Ransomware & Extortion

Encryption of claims and policy administration systems halts settlements, while data-theft extortion threatens release of policyholder records. Insurers with untested or co-located backups face the hardest recovery choices.

03 · Claims & Payment Fraud

Manipulated claims workflows, redirected settlement payments and collusive insider adjustments convert weak application controls and poor segregation of duties directly into financial loss.

04 · Business Email Compromise & Phishing

Spoofed emails targeting finance and claims staff redirect supplier or beneficiary payments and harvest credentials for core systems. Human error remains the thinnest control layer.

05 · Third-party and Vendor Cyber Risk

Core system vendors, TPAs, aggregators, bancassurance partners, bulk-SMS and payment providers hold privileged, often remote, access. A compromise at one supplier can cascade across many insurers at once.

06 · Weak Identity & Access Management

Shared administrator accounts, dormant IDs of exited staff and agents, absent multi-factor authentication and unreviewed access to policy and claims systems are among the most frequent audit findings.

07 · Insider Threat & Privilege Abuse

Staff or vendors with excessive rights can alter policy records, suppress alerts, create fictitious claims or exfiltrate data. Small IT teams magnify the segregation-of-duties gap.

08 · Legacy Systems & Patch Hygiene

Ageing policy administration platforms, unpatched servers and flat networks give attackers easy lateral movement once a single workstation or web front-end is compromised.

Emerging Cyber Risks to Watch

AI-Enabled Fraud & Social Engineering

Deepfake voice and video in support of fraudulent claims, synthetic-identity applications, and highly convincing AI-written phishing in English and Kiswahili are lowering the skill barrier for attackers while insurers’ own adoption of AI in underwriting and claims introduces model-integrity and data-poisoning risks.

API & Open-Integration Exposure

As insurers connect to aggregators, bancassurance channels, mobile money and credit reference bureaus, insecure or undocumented APIs become an attack surface that traditional perimeter controls never see.

Cloud Misconfiguration

Migration of policy systems, data lakes and backups to the cloud introduces exposed storage, weak tenant isolation and unclear shared-responsibility boundaries, a leading cause of large data exposures.

Supply-Chain Software Compromise

Malicious updates or compromised components in widely used insurance software could affect multiple carriers simultaneously, a systemic risk regulators across Africa increasingly flag.

Financial-Crime Convergence

Since Kenya’s February 2024 FATF grey-listing, AML/CFT scrutiny of the sector has intensified. Cyber-enabled fraud, account takeover and identity abuse now sit at the intersection of cybersecurity and money-laundering controls, demanding a joined-up response.

Regulatory Acceleration

Beyond the Guidance Note, the draft Insurance (Corporate Governance) Guidelines, 2025 and proposals to recognise cyber and virtual-asset insurance as new business classes signal that supervisory expectations will keep tightening. Yesterday’s acceptable posture becomes tomorrow’s compliance finding.

What the IRA Guidance Note Requires

The Guidance Note sets minimum standards for managing cybersecurity risk across the sector. The core obligations that every licensed insurer and reinsurer must be able to demonstrate are:

#RequirementWhat Good Looks Like
1Formal cybersecurity strategy, policy and proceduresDocumented, risk-based, framework-aligned (ISO 27001, NIST CSF), and covering the full insurance technology estate
2Board and senior-management approval and ownershipStrategy approved by the board; cyber risk a standing board/risk-committee agenda item with clear accountability
3Cybersecurity expertise on the boardAt least one director with demonstrable cybersecurity experience or expertise
424-hour reporting of material incidentsDefined triage and escalation so a material incident reaches IRA within 24 hours of confirmation or reasonable detection
5Quarterly incident reportingAll cybersecurity events reported to IRA within 15 days after the end of each quarter
6Annual policy review and updateCybersecurity policies reviewed and refreshed at least annually against the evolving threat and regulatory landscape
7People controls — awareness & hygieneStaff-wide security awareness training, regular phishing simulations and cyber-hygiene practices
8Resilience & recoveryRobust, tested backup protocols and incident response capable of restoring critical services within tolerance

Two features distinguish this regime from generic good practice. First, the cybersecurity strategy is not only board-approved but visible to the regulator, posture becomes a supervised artefact. Second, the obligations are time-bound and evidenced: the regulator can now ask precisely when an incident was detected, when it was reported, and when policies were last reviewed. Documentation that cannot answer those questions is itself a finding.

Additional Cybersecurity controls should also be implemented, these include controls listed in our Cybersecurity risks in SACCOs article.

The 24-Hour Breach Reporting Requirement

The headline obligation and the one insurers are least prepared for is mandatory reporting of material cybersecurity incidents to the IRA within 24 hours of the incident being confirmed or reasonably detected. The Guidance Note defines what qualifies as material, and the clock starts on detection, not on convenience.

What Counts as a Material Incident

Disruption to critical systems, services or platforms; unauthorised access to, or loss of, sensitive customer data; and financial losses affecting the insurer, its clients or third parties. In practice, a ransomware attack that shuts a claims platform, or an exposure of policyholder records, triggers the 24-hour clock.

Meeting a 24-hour deadline is a detection-and-decision problem long before it is a reporting problem. An insurer that only reviews logs at end of day, or that has no pre-agreed definition of “material,” will miss the window not because it is negligent but because it is unprepared. A workable reporting capability has four moving parts:

1
Detect

Continuous monitoring and alerting on core, claims and customer-facing systems so a material event is actually noticed in hours, not discovered days later. The 24-hour clock is only as good as the moment of detection.

2
Classify

A pre-agreed materiality standard mapped to the Guidance Note’s criteria, so the on-call team can decide “is this reportable?” against a checklist rather than debating it while the clock runs.

3
Report

A named accountable owner, a drafted notification template and a known IRA submission route, plus parallel awareness of the separate 72-hour ODPC obligation where personal data is involved.

4
Record

A defensible timeline evidencing detection, classification, escalation and submission, the record the regulator will ask for, and the feed into the 15-day quarterly return.

IT Audit Methodology, Approaches, Tools & Best Practices

Assuring an insurer’s posture against the Guidance Note calls for a structured, risk-based IT audit rather than a checklist walk-through. Our methodology draws on ISACA IT Audit Standards, COBIT 2019, the NIST Cybersecurity Framework and ISO/IEC 27001:2022, adapted to the IRA-regulated insurance environment and the sector’s distinctive application landscape. Get Our Insurance IT Audit Compliance Bundle.

1
Define Scope & Objectives

Map the insurer’s critical systems and data flows such as policy administration, claims management, underwriting and actuarial engines, the digital insurance platform, reinsurance and regulatory-reporting systems, and payment and bancassurance integrations, and align scope to the Guidance Note, the risk profile and the board’s appetite.

2
Identify & Prioritise IT Risks

Assess inherent risk across IT governance, identity and access management, change management, operations, cybersecurity, data protection, third-party risk and resilience, and prioritise procedures where risk to policyholders and compliance is greatest.

3
Test Design & Operating Effectiveness

Evaluate IT general controls and insurance-application controls through inquiry, observation, inspection and re-performance, using data analytics (CAATs) over claims and policy data where volumes justify automated testing.

4
Assess Incident Readiness

Test the 24-hour reporting capability end-to-end i.e., detection, materiality classification, escalation and submission — and validate backup and recovery through evidence of actual restore tests, not policy statements.

5
Report & Remediate

Issue a board-level report with risk-rated findings, root causes and actionable, owner-and-date remediation, then track findings to closure, the discipline the regulator increasingly expects to see evidenced.

Tools & Best Practices That Should Be in Place

Governance & Framework

Board-approved cybersecurity strategy and policies mapped to ISO 27001 / NIST CSF, the Data Protection Act and the IRA Guidance Note, with a maintained cyber risk register.

Identity & Access

MFA on all remote and privileged access, unique accounts, least-privilege, and quarterly access reviews across policy, claims and underwriting systems.

Monitoring & Detection

Centralised, tamper-evident logging and SIEM/alerting over critical systems, enabling detection within the hours the 24-hour rule demands.

Resilience & Backup

Offline or immutable backups, network segmentation, and a rehearsed, regularly tested incident response and business-continuity plan.

Third-Party Assurance

Security assessments, contractual security clauses and monitored, time-bound remote access for TPAs, insurtech partners and core-system vendors.

People & Awareness

Annual security awareness training, recurring phishing simulations, and clear reporting channels i.e., the human controls the Guidance Note explicitly requires to be in place.

A Practical Risk Assessment Matrix

Insurers should assess each cyber risk for likelihood and impact (financial, regulatory, operational, customer and reputational), record inherent scores, then re-score after considering control effectiveness to obtain the residual risk, the figure that should be compared against the board-approved risk appetite thresholds as part of the health insurers’ IT compliance obligations.

Likelihood ↓ / Impact →MinorModerateMajorSevere
Almost CertainMediumHighCriticalCritical
LikelyMediumHighHighCritical
PossibleLowMediumHighCritical
UnlikelyLowLowMediumHigh

Illustratively, a policyholder data breach in an insurer with no continuous monitoring typically scores Likely × Severe = Critical inherently; with encryption, access controls, logging and tested response in place, the residual score may fall to Possible × Major = High and onto a defined remediation path. Risk appetite threshold breaches must always be measured against residual scores.

How Management Should Monitor Cyber Risk: KPIs & KRIs for the Board

The Guidance Note puts the board on the hook, so the board needs numbers not a technical narrative. A concise set of Key Risk Indicators (leading signals of rising exposure) and Key Performance Indicators (control-health measures) turns cyber posture into something a board can govern quarter on quarter.

MetricTypeExample ThresholdWhy the Board Cares
Material incidents reported to IRA within 24hKPI100% within windowDirect measure of Guidance Note compliance
Mean time to detect a material incidentKRI< 12 hoursDetermines whether the 24h notification can be met
Confirmed fraud / breach losses per quarterKRIWithin board-set appetitePolicyholder-fund and P&L exposure
Critical vulnerabilities open beyond 30 daysKRI0 toleratedLeading indicator of breach likelihood
Policy & claims system uptimeKPI≥ 99.5%Operational resilience and policyholder service
Privileged accounts reviewed in the quarterKPI100%Insider-threat control health
Backup restore tests passedKPI100% of scheduled testsRansomware survivability
Phishing simulation failure rateKRI< 10%, trending downHuman-layer exposure
Critical third parties with current assessmentsKPI100%Insurtech and vendor supply-chain exposure
High-rated audit findings overdueKRI0 overdueGovernance discipline; IRA readiness

A Simple Board Reporting Dashboard

A one-page dashboard, (RAG-rated), trended quarter-on-quarter and annotated with actions is far more effective than a fifty-page technical report. An illustrative snapshot:

100%
Incidents Reported <24h
Within appetite
2
Critical Vulns >30d
▲ Breach of appetite
99.8%
Claims System Uptime
Within appetite
9%
Phish Fail Rate
▼ from 16%

Each red or amber indicator should arrive with a named owner, a remediation action and a remediation date turning the dashboard from a scoreboard into a management tool. Between quarterly reports, management should operate continuous monitoring and escalate appetite breaches immediately rather than waiting for the next committee cycle.

We have created a complete IRA-aligned IT compliance toolkit purpose-built for Kenya’s insurers, reinsurers and intermediaries with a Risk Register that has 126 controls across 19 domains, 126+ IT audit procedures, and 6 management and board reporting dashboards, Get Our Insurance IT Audit Compliance Bundle – Instant download

Enforcement Posture

The IRA has framed the Guidance Note as a floor, not a suggestion. The Commissioner’s circular requires all licensed insurers and reinsurers to familiarise themselves with it and ensure full and timely implementation, language that establishes a clear supervisory expectation and a baseline against which firms will be assessed.

Three signals define the enforcement direction of travel. First, the obligations are time-bound and measurable: 24-hour incident reports, 15-day quarterly returns and at-least-annual policy reviews give supervisors objective tests of compliance rather than subjective judgements of “adequacy.” Second, accountability is personal: by requiring board approval and a cyber-competent director, the regime makes senior individuals answerable, not just the IT function. Third, cybersecurity sits within a tightening wider framework i.e., the Data Protection Act’s ODPC penalties, the Computer Misuse and Cybercrimes Act, and the draft Insurance (Corporate Governance) Guidelines, 2025, so a single incident can trigger overlapping obligations and multiple regulators.

The Practical Reality

Industry practitioners have warned that many insurers remain under-prepared for the mandatory reporting deadlines. The gap is rarely intent, it is the absence of the detection, classification and escalation machinery needed to meet a 24-hour clock. That gap is precisely what a targeted IT audit surfaces before the regulator, or an attacker.

Persistent Challenges

Even well-intentioned insurers face structural obstacles to meeting the Guidance Note, and naming them honestly is the first step to closing them:

Legacy Core Systems

Ageing policy administration and claims platforms are hard to log, patch and monitor to the standard continuous detection now demands, yet replacing them is a multi-year investment.

Board Cyber-Skills Gap

The requirement for a cyber-competent director is difficult to satisfy in a shallow local talent pool, and a single appointment does not by itself build genuine board oversight.

Detection Maturity

Many insurers still rely on periodic log review rather than continuous monitoring, leaving the 24-hour clock structurally unreachable until detection capability is built.

Third-Party Sprawl

Reliance on TPAs, aggregators, bancassurance partners and insurtechs spreads accountability and data across parties the insurer does not directly control.

Data Sensitivity at Scale

Medical, financial and identity data across underwriting and claims raises the stakes of any breach and the bar for data-protection compliance.

Talent & Budget Constraints

Competition for scarce security skills and pressure on expense ratios leave many carriers running a bank-grade technology estate on a fraction of the resourcing.

Conclusion: Cyber Resilience as a Policyholder-Protection Duty

For Kenya’s insurers, the IRA Guidance Note reframes cybersecurity as inseparable from the core promise of the industry to protect policyholders and pay when it matters. Layered defences, disciplined access management, tested resilience, credible 24-hour reporting and honest board-level measurement are what stand between policyholder data and a well-equipped population of attackers. Insurers that treat cyber risk as a governed, measured and independently assured discipline will satisfy the IRA, protect their policyholders, and preserve the trust on which every policy depends.

In an era where insurers process the most sensitive personal data any institution holds, the cost of weak cyber governance is measured not only in breach losses and regulatory sanction, but in the erosion of the trust that makes insurance possible. Robust cybersecurity is an investment in the promise itself.