CYB-23 · Cyber security
Most SA short-term insurance brokers depend on 3–6 shared technology platforms: a policy admin system (TIAL, Genius, Flexi), a comparator, insurer extranets, and a CRM. A compromise of any single vendor can expose every broker using that platform simultaneously. A formal third-party cyber risk register must document all vendors with access to client data, their assessed risk, and oversight controls.
Trigger
No third-party cyber risk register; vendors with access to client PII not assessed; no cyber security clauses in vendor contracts; no exit plan for key vendors
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Compile a complete vendor inventory. Assess each vendor against a minimum cyber security questionnaire. Include cyber security obligations in all vendor contracts. Prioritise assessment of policy admin system and cloud providers.
Evidence required
Automated assessment
Verified by the Provantis cyber scanner. Machine checks performed: