Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
Compliance

IRDAI Cyber Security Guidelines: What Annual IS Audits and VAPT Mean for Insurers

May 12, 2026·CyVigilant Security Team
ComplianceCyVigilant

Insurance companies in India operate in an increasingly hostile digital environment. The IRDAI's Guidelines on Information and Cyber Security for Insurers (2023 consolidated circular) formalise obligations that have existed in various circulars since 2017, but the 2023 document creates clearer accountability structures, explicit audit frequencies, and direct references to CERT-In empanelment. For IT and compliance heads at life insurers, general insurers, and health insurers, as well as insurance brokers and third-party administrators (TPAs), understanding the operational implications of these guidelines is now a board-level responsibility.

Scope of the IRDAI guidelines

The guidelines apply to all IRDAI-regulated entities: life insurance companies, general insurance companies, standalone health insurers, reinsurers, insurance brokers, TPAs, and surveyors. The obligations scale with entity size and the sensitivity of the data handled. At the core of the framework is the requirement for a Board-approved Information and Cyber Security Policy, a designated Chief Information Security Officer (CISO) for larger entities, and a periodic cycle of IS audits and VAPT.

The framework is notably prescriptive about the independence of the auditor. Internal teams conducting self-assessments do not satisfy the IS audit requirement. The guidelines require that IS audits be conducted by an external, competent, independent auditing firm — and in practice, regulators and large reinsurers treat CERT-In empanelment as the quality marker for that independence. Third-party tie-ups with non-empanelled firms create reputational and regulatory risk at renewal time.

Annual IS audit: what it must cover

The IS audit is a comprehensive review of the insurer's information security posture. It is broader than a VAPT — it includes policy review (are policies documented and enforced?), access control assessment (user provisioning, privilege management, segregation of duties), incident response process evaluation, business continuity and disaster recovery testing, and vendor/outsourcing risk management. The VAPT sits within the IS audit as the technical assurance component.

For insurers, the systems in scope for VAPT typically include the core insurance platform (policy management, claims management), customer portals and mobile apps, APIs used by insurance aggregators and bancassurance partners, data analytics platforms, and the cloud infrastructure on which these run. With the DPDP Act 2023 now operative, the stakes around customer data exposure have risen — a breach that exposes policyholder health or financial data carries regulatory liability under both IRDAI and the Data Protection Board.

VAPT obligations: frequency and methodology

IRDAI's guidelines require at minimum annual VAPT for all regulated entities. Entities handling sensitive health data or classified as Systemically Important Insurers (SIIs) face enhanced expectations — quarterly vulnerability assessments and semi-annual penetration testing are increasingly the de facto standard for SIIs, influenced by the RBI's practice for SIBs. The VAPT must be scope-defined (scoping document agreed pre-engagement), methodology-aligned to recognised standards (OWASP ASVS for web applications, OWASP MASVS for mobile, PTES/OSSTMM for network testing), and produce a findings register with CVSS severity ratings and remediation recommendations.

Retest after remediation is expected — regulators look for evidence that critical and high findings were fixed and validated. A pentest report without a closure confirmation for critical issues will not satisfy an IRDAI examination team. See our VAPT services page for the full engagement model we follow.

Insurer-specific risks that a VAPT should prioritise

Insurance platforms have an attack surface shaped by their business model. API exposure through insurance aggregators (Policybazaar, Coverfox) means that authentication and authorisation flaws in policy issuance APIs can be exploited to enumerate customer data or manipulate premium calculations. Bancassurance partner integrations create privilege escalation paths where a compromised bank channel partner account could access the full insurer backend. Health data stored by TPAs is particularly high-value for adversaries given its use in identity fraud. These are not theoretical — they represent the class of findings consistently identified in insurer assessments.

The DPDP Act dimension

The Digital Personal Data Protection Act 2023 introduces data fiduciary obligations that insurers must integrate with their IS audit scope. Under DPDP, any breach of personal data must be reported to the Data Protection Board within prescribed timelines. The IS audit must now evaluate whether the insurer has adequate technical safeguards — encryption at rest and in transit, access logging, consent management — to satisfy the fiduciary standard. A VAPT finding that reveals unencrypted policyholder data in a database or an exposed API endpoint returning PII without authentication is now both a technical vulnerability and a DPDP compliance failure.

CyVigilant conducts IRDAI-aligned IS audits and VAPT for insurers and TPAs, with reports structured to satisfy regulatory examination. To understand what a CERT-In audit engagement covers for your organisation, talk to an expert.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert