We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Industries

Insurance and capital markets — IRDAI and SEBI compliance

Insurers, intermediaries and capital-markets participants run under IRDAI Information and Cyber Security guidelines and SEBI CSCRF, with ISNP obligations and heavy personal and health-data exposure.

Applicable regulations

  • IRDAI Information and Cyber Security Guidelines
  • IRDAI ISNP (Insurance Self-Network Platform) requirements
  • SEBI CSCRF for capital-markets intermediaries
  • DPDP Act 2023, including health data
  • PCI DSS for premium and card payments

Common cybersecurity risks

  • Large volumes of sensitive policyholder and health data
  • Broker, aggregator and TPA third-party exposure
  • Legacy policy-admin systems with weak segmentation
  • Fraud across digital onboarding and claims

Audit findings we typically see

  • Incomplete data inventory for PII and health data
  • ISNP security controls not evidenced
  • Access and log-monitoring gaps in policy and claims systems
  • Weak security oversight of vendors and TPAs

Services required

Our engagement approach

  • Data and scope discovery. Inventory policyholder and health data, ISNP and TPA flows.
  • Assessment. Test against IRDAI guidelines and ISNP requirements.
  • Remediation. Control design, privacy workflows and evidence templates.
  • Assurance. An IRDAI-aligned audit report and management pack.

Expected evidence

  • PII and health-data inventory
  • ISNP control evidence
  • VAPT reports with closure
  • TPA and vendor risk register

Indicative timeline

Readiness usually runs 8 to 14 weeks, depending on systems and ISNP scope.

Deliverables

  • IRDAI-mapped gap assessment
  • ISNP audit evidence
  • VAPT reports
  • DPDP data inventory and DSR workflow
Free tool
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your Insurance security and IRDAI requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →