Insurance is a business built on risk assessment, but most carriers have a blind spot when it comes to their own technology risk. Policy administration, claims processing, and actuarial engines have been patched and extended for decades, accumulating business logic that nobody fully understands anymore. In 2015, Anthem discovered that attackers had been inside their systems for weeks, exfiltrating 78.8 million records including unencrypted Social Security numbers. The subsequent DOJ investigation attributed the attack to a Chinese state-sponsored group, and Anthem settled for $115 million.1
The breach exploited legacy infrastructure that lacked basic modern security practices.
1 DOJ indictment, May 2019