In the digital age, insurance companies are not only guardians of financial protection but also stewards of sensitive customer data. With the advent of the Digital Operational Resilience Act (DORA), the insurance sector faces heightened scrutiny concerning its cybersecurity posture and operational resilience. Central to DORA’s objectives is the imperative for insurance companies to address and mitigate the risks associated with their Information and Communication Technology (ICT) third-party dependencies through robust contractual arrangements.

Insurance companies, like many other businesses, increasingly rely on third-party ICT service providers for critical functions such as data management, claims processing, complaints handling and customer service. While outsourcing these services can enhance efficiency and innovation, it also introduces a complex web of risks, including data breaches, service disruptions, and regulatory non-compliance.

Under DORA, insurance companies are mandated to adopt a proactive approach to managing third-party risks, with particular emphasis on contractual arrangements. These arrangements serve as the foundation for delineating responsibilities, setting expectations, and mitigating potential risks associated with ICT service providers.

Key components of contractual arrangements for insurance companies under DORA include:

  1. Risk Assessment and Due Diligence: Insurance companies must conduct comprehensive risk assessments and due diligence exercises to evaluate the cybersecurity posture and operational resilience of their ICT service providers. This involves scrutinizing vendors’ security protocols, compliance frameworks, and incident response capabilities to ensure alignment with regulatory requirements and industry best practices.
  2. Clear and Defined Responsibilities: Contracts should clearly delineate the responsibilities and obligations of both parties, including data protection measures, incident reporting procedures, and compliance requirements. Insurance companies must articulate their expectations regarding the security and confidentiality of customer data and ensure that ICT service providers adhere to agreed-upon standards.
  3. Service Level Agreements (SLAs): SLAs establish the performance expectations, service levels, and response times for ICT services. Insurance companies should negotiate SLAs that align with their operational needs and regulatory obligations, ensuring that service providers deliver consistent and reliable services while adhering to predefined standards.
  4. Cybersecurity Protocols and Standards: Contracts should incorporate robust cybersecurity protocols and standards to safeguard sensitive information and mitigate cyber threats. Insurance companies must stipulate requirements for encryption, access controls, vulnerability management, and regular security assessments to ensure the integrity and confidentiality of data handled by ICT service providers.
  5. Business Continuity and Disaster Recovery: Given the critical nature of ICT services, contracts should include provisions for business continuity planning and disaster recovery measures. Insurance companies must ascertain that their service providers have robust contingency plans in place to minimize disruptions and ensure the continuity of business operations in the event of a cyber incident or system outage.
  6. Regulatory Compliance: Contracts must address regulatory compliance obligations, including data protection laws, cybersecurity regulations, and reporting requirements. Insurance companies bear the ultimate responsibility for regulatory adherence but must ensure that their ICT service providers comply with relevant legal and regulatory frameworks to mitigate compliance risks.

In conclusion, the Digital Operational Resilience Act underscores the importance of robust contractual arrangements in managing third-party risks and enhancing cyber resilience within the insurance sector. By establishing clear expectations, responsibilities, and safeguards, insurance companies can mitigate the risks associated with ICT dependencies, safeguard customer data, and ensure the continuity of business operations in an increasingly digitized environment.

Author: Beppe Sammut (Senior Associate, Ganado Advocates)

'Insurance & Reinsurance' Related News Articles

01
DORA Trifecta – Three delegated regulations adopted by the Commission
Ganado Advocates

by Ganado Advocates

23rd April 2024

BOV OFFERS MAPFRE MSV Life CAPITAL GUARANTEED AND INCOME PLANS
Bank of Valletta

by Bank of Valletta

5th March 2024

Insurance update: The Nature and Art of Financial Supervision (Volume IX)
Ganado Advocates

by Ganado Advocates

4th March 2024

GRC in Malta: The role of regulatory governance codes in strengthening governance structures of regulated entities
Ganado Advocates

by Ganado Advocates

23rd February 2024

EIOPA’s 2nd Report on the Application of the Insurance Distribution Directive (the “IDD”)
Ganado Advocates

by Ganado Advocates

19th February 2024

Atlas Insurance PCC Expands Reach with UK Branch Authorization and Life Reinsurance License
Atlas Insurance PCC Ltd

by Atlas Insurance PCC Ltd

25th January 2024

MFSA Circular on the Newly Published Accountancy Profession Regulations, 2023 (Legal Notice 299 of 2023)
Ganado Advocates

by Ganado Advocates

22nd January 2024

Insurtech and PCCs: Transforming insurance in Malta
Ganado Advocates

by Ganado Advocates

6th December 2023

MFSA issues Circular making the appointment of Independent Non-Executive Directors mandatory for Insurance Agents, Insurance Brokers and Retirement Scheme Administrators
Ganado Advocates

by Ganado Advocates

6th December 2023

The Guaranteed Capital & Income Plan 2026 II now available from all BOV Branches, Investment Centres and Private Banking
Bank of Valletta

by Bank of Valletta

6th September 2023

BOV announces limited-time offer on the MAPFRE MSV Life Unit Linked Personal Pension Plans
Bank of Valletta

by Bank of Valletta

23rd August 2023

Juridical interest in the context of insurance claims
Ganado Advocates

by Ganado Advocates

27th February 2023

Proposed amendments to the MFSA Insurance Distribution Rules
Ganado Advocates

by Ganado Advocates

24th February 2023

The Development of the Principle of Uberrima Fides over the years
Ganado Advocates

by Ganado Advocates

4th January 2023

Corporate Governance Code: How will your company apply the Code to ensure a sound governance structure?
Ganado Advocates

by Ganado Advocates

4th January 2023

High calibre international speakers for FinanceMalta’s 15th Annual Conference
FinanceMalta

by FinanceMalta

28th October 2022

The sinking of an oil tanker, recognition of judgements, arbitration proceedings and insurance contracts
Ganado Advocates

by Ganado Advocates

27th October 2022

EIOPA issues supervisory statement on the management of non-affirmative cyber risk exposures
Ganado Advocates

by Ganado Advocates

12th October 2022

The Corporate Governance Code provides core principles to be adopted by insurance entities to strengthen its good corporate governance
Ganado Advocates

by Ganado Advocates

12th October 2022

Talent Feature: How education can keep up with finance transformation
FinanceMalta

by FinanceMalta

5th August 2022

Member Spotlight – Jatco Insurance Brokers PPC Ltd: With Lloyd’s Broker Status, Jatco Plots Expansion
FinanceMalta

by FinanceMalta

22nd September 2021

Reinsurers’ Financial Communication: 2019-2020 Benchmark study
Mazars in Malta

by Mazars in Malta

4th June 2020