Home India Insurance Regulatory And Development Authority PRESS RELEASE Information Security...
Date: 2024-10-18 Category: Not Applicable State: Union Government Country: India

PRESS RELEASE Information Security

Issued by Insurance Regulatory And Development Authority · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This press release, dated October 18, 2024, addresses recent data leaks from two insurance companies. The IRDAI (Insurance Regulatory and Development Authority of India) emphasizes the importance of data security and outlines measures taken to protect policyholder data. The IRDAI has issued advisories to all insurers to check their IT systems for vulnerabilities. **Key Points / Main Content** * **Data Security Incident:** * Reports of data leaks from two insurance companies have emerged. * IRDAI views data security and cyber attacks on insurance IT systems with utmost seriousness. * **Existing Guidelines:** * Cyber security guidelines are already in place, requiring insurers to implement robust IT and cyber security frameworks. * **IRDAI's Response:** * IRDAI is closely monitoring the situation with the affected insurers and is in contact with their management. * Regular updates are being obtained to ensure policyholder data and interests are fully protected. * IRDAI will continue to engage with the insurance companies to ensure that the policyholders’ interests are fully protected. * **Actions by Affected Insurers:** * Insurers reported the cyber incident to the Government and IRDAI. * Insurers isolated the impacted IT systems. * External IT security firm was appointed to conduct root cause analysis and recommended a containment, eradication, and recoverability plan. * The suggested plan is being implemented. * **Preventative Measures:** * Additional preventative measures are being implemented to safeguard policyholder data. * System upgrades are planned for the immediate, short, and medium term. * API vulnerabilities, gap assessment, and VAPT issues are being addressed. * **Legal Action:** * A criminal complaint has been filed with law enforcement agencies against the threat actors. * A legal notice has been served on the social media platform to prevent the sale of policyholder data. * **Advisory to All Insurers:** * The IRDAI has advised all insurers to check their IT systems for vulnerabilities and take necessary steps to protect policyholders' data. **Impact Analysis** **Insurance Companies** * **Impact:** * Must enhance their IT and cyber security infrastructure. * Subject to scrutiny and potential corrective actions by IRDAI. * Incur costs associated with audits, system upgrades, and legal actions. * **Action Required:** * Review and strengthen IT systems. * Address identified vulnerabilities. * Comply with IRDAI directives. **Policyholders** * **Impact:** * Potential risk of data exposure and misuse. * Reliance on insurers and IRDAI to protect their information. * **Action Required:** * Remain vigilant for potential fraud or identity theft. * Monitor communications from their insurers.

Key Entities Referenced

IRDAI: Insurance Regulatory and Development Authority of India; the regulator monitoring the data breach incidents and issuing advisories to insurers. Cyber security guidelines for insurance companies: Existing guidelines requiring insurers to implement robust IT and cyber security frameworks. Policyholders' data: The primary asset at risk due to data breaches, requiring protection and security measures.
Official Source Record View Original Source →
See Full Document Text
(cid:366)ेस िव(cid:466)(cid:304)(cid:593) PRESS RELEASE िदनांक / Date: 18.10.2024 हाल ही म(cid:336) दो बीमाकता(cid:330)ओ ं से डेटा (cid:366)कटनो ं (ली(cid:411)) की सूचनाएँ िमली ह(cid:339)। (cid:366)ारंभ म(cid:336) ही यह (cid:729)(cid:700) िकया जाता है िक आईआरडीएआई डेटा सुर(cid:407)ा को ब(cid:352)त मह(cid:533)पूण(cid:330) मानता है तथा डेटा उ(cid:671)ंघन, बीमा कं पिनयो ंआिद की आईटी (cid:366)णािलयो ंपर साइबर आ(cid:354)मणो ंको अ(cid:529)ंत गंभीरतापूव(cid:330)क लेता है। बीमा कं पिनयो ंके िलए साइबर सुर(cid:407)ा संबंधी िदशािनद(cid:337)श िव(cid:552)मान ह(cid:339) जो बीमाकता(cid:330)ओ ंसे उनके प(cid:303)रचालन संचािलत करने के िलए सु(cid:778)ढ़ आईटी और साइबर सुर(cid:407)ा ढाँचा लागू करने की अपे(cid:407)ा करते ह(cid:339)। आईआरडीएआई संबंिधत बीमाकता(cid:330)ओ ं के िवषय म(cid:336) (cid:304)(cid:830)थित की (cid:559)ानपूव(cid:330)क िनगरानी कर रहा है तथा उनके (cid:366)बंधन के साथ संपक(cid:330) म(cid:336) है। िनयिमत अ(cid:552)तन (cid:304)(cid:830)थित की जानकारी यह सुिनि(cid:686)त करने के िलए (cid:366)ा(cid:593) की जा रही है िक पािलसीधारको ंके डेटा और िहत का पूण(cid:330)तः संर(cid:407)ण िकया जाए और कं पनी इस उ(cid:671)ंघन के (cid:554)ारा उ(cid:523)(cid:580) िकये गये खतरे को रोकने के िलए सभी आव(cid:692)क कदम उठाये। आईआरडीएआई यह सुिनि(cid:686)त करने के िलए बीमा कं पिनयो ं के साथ लगातार संपक(cid:330) म(cid:336) रहेगा िक पािलसीधारको ंके िहतो ंका पूण(cid:330)तः संर(cid:407)ण िकया जाए। संबंिधत बीमाकता(cid:330)ओ ंको अनुदेश िदये गये ह(cid:339) िक वे इस उ(cid:542)े(cid:692) के साथ कं पनी के आईटी प(cid:303)र(cid:778)(cid:692) का (cid:681)ापक संपरी(cid:407)ण करने के िलए एक (cid:738)तं(cid:361) संपरी(cid:407)क (आिडटर) की िनयु(cid:304)(cid:389) कर(cid:336) िक कोई असुरि(cid:407)त (cid:304)(cid:830)थित न रहे और आईटी (cid:366)णाली उनके प(cid:303)रचालनो ंके मान और जिटलताओ ं को पूरा करने के िलए पया(cid:330)(cid:593) हो। संबंिधत बीमाकता(cid:330)ओ ं की मानक प(cid:303)रचालन (cid:366)ि(cid:354)याओ ं के भाग के (cid:349)प म(cid:336), उ(cid:590)ोनं े साइबर घटना की सूचना सरकार और आईआरडीएआई को दी। संबंिधत बीमाकता(cid:330)ओ ं ने (cid:366)भािवत आईटी (cid:366)णाली को अलग करने के (cid:554)ारा उसे वलयरोिधत िकया है और साथ ही, मूल कारण का िव(cid:694)ेषण करने के िलए एक बा(cid:744) आईटी सुर(cid:407)ा कं पनी को िनयु(cid:389) िकया है। उ(cid:389) संपरी(cid:407)ण फम(cid:330) ने कं पनी की आईटी (cid:366)णाली, िजसके अनुसार बीमाकता(cid:330)ओ ं (cid:554)ारा काय(cid:330) िकया जा रहा था, म(cid:336) असुरि(cid:407)त (cid:304)(cid:830)थितयाँ होने की तथा खतरा उ(cid:523)(cid:580) करनेवाले (cid:304)खलाड़ी (cid:554)ारा (cid:366)यु(cid:389) काय(cid:330)प(cid:544)ित की (cid:303)रपोट(cid:330) दी िजससे उ(cid:389) (cid:304)(cid:830)थित का अनुिचत लाभ उठाया गया। उ(cid:389) संपरी(cid:407)ण फम(cid:330) (cid:554)ारा सुझाये गये (cid:349)प म(cid:336) िनयं(cid:361)ण, उ(cid:585)ूलन और पुनः (cid:366)ापणीयता योजना बीमाकता(cid:330)ओ ं के (cid:554)ारा लागू की जा रही है। उ(cid:389) (cid:303)रपोट(cid:330) म(cid:336) बताये गये अित(cid:303)र(cid:389) िनवारक उपाय पािलसीधारको ं के डेटा को िनरापद और सुरि(cid:407)त रखने के िलए काया(cid:330)(cid:587)यन की (cid:366)ि(cid:354)या म(cid:336) ह(cid:339)। त(cid:509)ाल, अ(cid:665)ाविध और म(cid:559)म समयाविध म(cid:336) (cid:366)णाली का (cid:356)ेड बढ़ाने के िलए बीमाकता(cid:330)ओ ंके (cid:554)ारा कार(cid:330)वाई की जाएगी। एपीआई असुरि(cid:407)तताएँ, अंतराल िनधा(cid:330)रण और वीएपीटी सम(cid:735)ाएँ सुधार के एक उ(cid:580)त (cid:721)र पर ह(cid:339)। उ(cid:389) बीमाकता(cid:330)ओ ं ने खतरा उ(cid:523)(cid:580) करनेवाले (cid:304)खलािड़यो ं के िव(cid:348)(cid:544) िविध (cid:366)वत(cid:330)क एज(cid:336)िसयो ं के पास एक आपरािधक िशकायत फाइल की है। इसने पािलसीधारको ंका डेटा बेचने से खतरा उ(cid:523)ादक (cid:304)खलाड़ी को रोकने के िलए सोशल मीिडया (cid:600)ेटफाम(cid:330) पर एक कानूनी नोिटस (cid:366)(cid:721)ुत िकया है।इसके अलावा, आईआरडीएआई ने सभी बीमाकता(cid:330)ओ ं को परामश(cid:330) जारी िकया है िक वे असुरि(cid:407)तताओ ं की पहचान करने के िलए अपनी आईटी (cid:366)णािलयो ंकी जाँच कर(cid:336) तथा पािलसीधारको ंके डेटा का संर(cid:407)ण करने के िलए आव(cid:692)क कदम उठाएँ। There have been reports of data leaks from two Insurers recently. At the outset, it is stated that the IRDAI considers data security as very important and takes data breach, cyber-attacks on IT systems of insurance companies, etc very seriously. Cyber security guidelines for insurance companies are in place which require insurers to put in place robust IT and cyber security framework for carrying out their operations. The IRDAI is closely monitoring the situation in case of the concerned insurers and has been in touch with their management. Regular updates are being obtained to ensure that the policyholders’ data and interest are fully protected and the company is taking all steps to arrest the threat posed by this breach. The IRDAI will continue to engage with the insurance companies to ensure that the policyholders’ interests are fully protected. The concerned insurers have been instructed to appoint an independent auditor to undertake comprehensive audit of the company’s IT landscape with the aim that there are no vulnerabilities and the IT system are adequate to meet the scale and complexities of their operations. As part of the standard operating procedures of the concerned insurers, they reported the cyber incident to the Government and IRDAI. The concerned insurers have ring fenced the impacted IT system by isolating it and at the same time appointed an external IT security company to undertake root cause analysis. The audit firm reported vulnerabilities in the company’s IT system and the methodology used by the threat actor to exploit the same which were acted upon by insurers. The Containment, Eradication and Recoverability plan as suggested by the audit firm are being implemented by the insurers. Further preventive steps outlined in the report are in the process of implementation to keep the policyholders’ data safe and secure. System upgrades over immediate, short and medium time period, will be acted upon by the insurers. The API vulnerabilities, Gap assessment and VAPT Issues are at an advanced stage of rectification. The insurers have filed a criminal complaint with the law enforcement agencies against the threat actors. It served legal notice on the social media platform to prevent the threat actor from selling the policyholders data. Further, the IRDAI has issued advisory to all insurers to check their IT systems for vulnerabilities and take necessary steps to protect the policyholders’ data.

Continue your research