Insurance companies hold personal, financial, and health data for years, then move it across a chain of brokers, loss adjusters, and contact centers. Under the DORA Regulation, in force since January 17, 2025, proving control over that data and over ICT third-party providers is no longer optional. Protection that stays attached to the file, and keeps working outside the corporate network, moves the place where security is actually decided.
The short version
- Perimeter security defends the network. Insurance data leaves the network every day: to agents, adjusters, contact centers, cloud providers.
- DORA (EU Reg. 2022/2554) requires insurers to demonstrate control over both the data and the ICT supply chain. GDPR (Art. 32) lists encryption among adequate technical measures.
- Verizon's DBIR 2026 reports breaches involving third parties up 60% year over year, reaching 48% of all breaches. That is precisely where the insurance value chain lives.
- Transparent encryption removes the friction that usually kills encryption projects: people work the way they already work, protection stays on the file.
- FileGrant and RemoteGrant, the two CyberGrant products, implement this model: quantum-safe encryption that belongs to the file, plus policies that decide which applications and devices can open it.
- Encrypting data at the source changes the economics of an attack. Exfiltrated data that is already encrypted is worth very little, even under double extortion.
Why insurance data lives outside the perimeter
An insurance company collects and retains some of the most sensitive information a person will ever hand to a business: identity records, bank details and IBANs, and, in life and health policies, actual medical data, which GDPR places in the special categories under Article 9. None of it sits still. It is needed daily to underwrite risk and settle claims, and to do that it travels across a chain of agents, brokers, loss adjusters, contact centers, and vendors processing files in the cloud. The same dynamic turned a cloud vendor breach in the Santander case into the bank's incident, not the vendor's.
What DORA asks insurers to prove about data control
Since January 17, 2025, Regulation (EU) 2022/2554, known as DORA, applies directly to insurance and reinsurance undertakings, intermediaries, and third-party ICT service providers. It changes the register of compliance. Adopting measures is no longer enough: a firm has to show they exist, that they work, and that they extend to its providers. Article 9 (protection and prevention) requires policies and tools that safeguard the confidentiality and integrity of data, encryption included. Chapter V, Articles 28 through 30, requires firms to govern third-party ICT risk. GDPR completes the picture, naming encryption among risk-appropriate measures (Art. 32) and requiring a record of processing activities (Art. 30). Banking has already walked this road, where DORA, GDPR, and file-centric protection converge on the same object.
The trouble is that most of the defenses in place were designed for a world where data sat still on corporate servers. Today data leaves the network daily, and control leaves with it. The Verizon Data Breach Investigations Report 2026 finds the human element present in 62% of breaches, up from 60% the year before. In most cases that means legitimate operations performed badly, not sophisticated attacks. Breaches involving third parties grew 60% in a year and now account for 48% of the total, which is exactly where the insurance value chain sits. Within the Financial and Insurance sector, the DBIR puts the human element at 65% across 1,300 analyzed breaches. Italy's Clusit Report 2026 points the same way: 5,265 serious incidents worldwide in 2025, up 48.7% year over year, the steepest annual increase on record, with Financial and Insurance up 27% in absolute terms and among the two sectors absorbing the largest share of "extreme" impacts.
Why encryption projects stall before they reach production
Encryption is the most direct answer to this problem. Technically, it has been settled for years. In practice, adoption is another matter. Fabio Spagnuolo, who runs security operations at REVO Insurance, knows the reason well: encryption done properly gets perceived as impossible or far too complex, and the outcome is always the same. The people who should adopt it slow down, work around the control, and eventually give up.
"Friction, meaning the operational weight that security pushes onto people, is the real reason many encryption projects never reach production. That gives you a practical rule for any operating environment: if too many people have to do too many things, the measure does not work. Complexity belongs where the expertise to manage it lives, on the side of the people who design security. What the user needs is to get to the result without changing the way they work."
Fabio Spagnuolo, IT Security Operations Manager, REVO Insurance
How transparent encryption stays attached to the file
The choice was to put protection inside the file. Transparent encryption travels with the document even when it leaves the perimeter, and asks nobody to learn a new procedure. A file encrypted on one computer stays encrypted when it lands on another device or on a USB stick, and becomes usable only within a defined set of authorized applications and devices, set at the governance policy level.
The architecture works on two distinct layers. The first is encryption that belongs to the file and stays active wherever the file goes. The second is the policy deciding which applications and which devices are allowed to open it. That second layer is what separates this approach from traditional classification and from tools that inspect content looking for a pattern. As Spagnuolo puts it:
"A private key has no recognizable pattern by design, because it is built to be chaotic. Defending it by looking inside the file does not get you far, whereas it does make sense to establish who and what is allowed to use it.
The practical point, for anyone introducing a technology into an already structured company, is that this model sits alongside the existing infrastructure instead of replacing it. It coexists with endpoint management, with identity, with backups. It adds a layer of protection that follows the document, without dismantling what already works."
Fabio Spagnuolo, IT Security Operations Manager, REVO Insurance
How CyberGrant implements transparent encryption with FileGrant and RemoteGrant
FileGrant is CyberGrant's file-centric platform. It encrypts documents at creation with quantum-safe CRYSTALS-Kyber cryptography (NIST FIPS 203, August 2024), keeps protection in force after a file is shared with a third party, allows access to be revoked after sending, and records every open event in a queryable audit trail. RemoteGrant covers the second layer: more than twenty policies governing which applications, which devices, and which USB ports can open a protected file, with transparent encryption at the endpoint.
Neither product replaces what an insurer already runs. They sit alongside endpoint management, identity, and backup, and cover the gap those defenses leave open by design: the moment the document is already out. It is the same principle behind file-centric DLP 2.0 and behind the zero trust reading of financial sector data.
Why encrypting at the source rewrites the ransomware equation
Behind encryption at origin there is a concrete defensive logic, which Spagnuolo traces back to the economics of an attack. It helps to remember how ransomware started: attackers were already inside the systems, pulling data out unnoticed, and they began encrypting it to make their presence visible and demand a ransom. The model then evolved into double extortion: lock the systems first, then threaten to publish what was taken.
If data leaves the company already encrypted at the source, that equation flips. Exfiltrating unreadable content is expensive for an attacker who has already invested in the attack chain and now has to invest far more to attempt decryption. More importantly, the second lever of the extortion collapses: if the data posted on a leak site is already encrypted, it stays inaccessible, and the threat to publish loses its force. That is exactly what was missing in the Booking, Eataly, and Trenitalia breaches, where the stolen data was readable.
The DBIR 2026 records ransomware present in 48% of breaches, up from 44% the previous year. Reducing the value of the haul is a defense that still works after everything else has failed.
What changes for the CISO and the board
DORA places responsibility for operational resilience with the management body. It is no longer confined to IT. For a board and a security director, moving protection onto the data produces measurable effects. Compliance becomes easier to demonstrate, because encryption is native and access tracking is already in place. Dependence on flawless user behavior drops, because a mistake involving a protected file does not turn into a reportable incident. And supply chain control, which DORA demands, becomes manageable, because the data stays protected even while a third party handles it. On that last point it is worth revisiting how to prevent data loss in external collaboration.
None of this replaces the classic defenses. It sits alongside them, covering the space the perimeter leaves exposed by construction: the moment the data is already outside.
What stays protected when the perimeter does not hold
For years, insurance security was measured by how well it kept outsiders off the network. The text of DORA, and the incidents of recent months, move the question elsewhere: what stays protected when someone walks in with valid credentials, or when the file has already gone out to a broker, an adjuster, a vendor. As long as security remains a property of the network, every new regulatory obligation will find insurers chasing the same moving boundary. When it belongs to the data, the boundary moves with the document, and travels wherever the file travels.
It is the same argument the perimeter has already fallen puts to a room of CISOs, and the one the guide to post-quantum encrypted file sharing turns into technical requirements for regulated organizations.
Frequently asked questions about DORA, encryption, and insurance data
Does DORA require insurance companies to encrypt data?
DORA does not prescribe a specific algorithm. Article 9 of Regulation (EU) 2022/2554 requires policies and tools that safeguard the confidentiality, integrity, and availability of data, and names encryption among the protective measures to adopt in proportion to risk. GDPR follows the same logic in Article 32. The real obligation for an insurer is to show that the chosen measure is adequate to the risk and remains effective even when a third-party provider handles the data.
What is transparent encryption, and how does it differ from traditional DLP?
Transparent encryption protects a file at creation, and that protection stays attached to the document wherever it travels, with no extra steps for the user. Traditional DLP works the other way around: it inspects content in transit looking for patterns, then blocks or permits the transfer. The first model keeps working after a file has left the network. The second does not. The difference is between guarding the exit and protecting the file at birth.
What do FileGrant and RemoteGrant do inside an insurance company?
FileGrant is CyberGrant's file-centric platform. It encrypts documents at creation with quantum-safe cryptography, keeps protection in force after files are shared with brokers, adjusters, and vendors, allows access to be revoked after sending, and logs every open event in an audit trail. RemoteGrant protects endpoints and remote access with more than twenty policies defining which applications and devices can open a protected file. Both products sit alongside existing infrastructure and do not replace endpoint management, identity, or backup.
Does quantum-safe encryption matter to an insurer today?
It matters for data with multi-year value, which in insurance is the norm: a life policy or a health file holds value for decades. The logic is "harvest now, decrypt later." An attacker archives data encrypted with conventional algorithms today and decrypts it once a sufficiently capable quantum computer exists. CRYSTALS-Kyber, standardized by NIST as FIPS 203 (ML-KEM) in August 2024, is the algorithm designed to withstand that scenario.
How do you demonstrate the ICT supply chain control DORA requires?
Chapter V of DORA, Articles 28 through 30, requires insurers to maintain a register of contractual arrangements with third-party ICT service providers and to govern that risk across the full lifecycle. Technically, an audit trail recording who opened a document, when, and from which device, combined with the ability to revoke access after sharing, supplies the evidence that the protective measure still holds at the provider.
Does file-centric encryption work with existing Microsoft 365, SharePoint, and OneDrive?
Yes, and it requires no migration. Connector, the FileGrant extension for SharePoint and OneDrive, brings quantum-safe encryption into the Microsoft environments a company already runs. Documents stay where they are, users keep their Microsoft login and their habits, and protection extends to the non-Office files Microsoft Purview leaves uncovered. No CyberGrant solution replaces Microsoft 365. They sit alongside what the company already has.
Can deployment be on-premise for data sovereignty reasons?
Yes. FileGrant and RemoteGrant are available both in the cloud and on-premise, with zero-knowledge key management. In an on-premise configuration the keys remain inside the insurer's own infrastructure and the data never leaves its servers. For an insurance undertaking subject to DORA and to data sovereignty requirements, this is the configuration that minimizes cryptographic dependence on third parties.