For insurance

When third-party risk is the line of business.

Whether you're underwriting cyber risk, managing your own vendor stack, or both — third-party security is the product. The Agency's combined-signal model gives underwriting and operations the same continuous, evidence-backed view across thousands of vendors.

What does third-party risk management involve in insurance?

Insurers do third-party risk twice, for two different purposes, and the distinction is worth keeping clear.

As regulated businesses, they carry the same obligations as other financial institutions: DORA applies to insurance and reinsurance undertakings in the EU, Solvency II treats outsourcing as an operational risk requiring governance and notification of critical functions, UK firms are subject to FCA and PRA operational resilience rules, Australian insurers to APRA CPS 230, and US insurers frequently to NYDFS Part 500 and the NAIC model law.

As underwriters of cyber risk, they assess third-party security as the product itself — pricing policies against an applicant's posture, managing accumulation where many insureds share a dependency, and monitoring exposure through the policy period rather than only at renewal. The 2024 CrowdStrike outage and the Change Healthcare breach both illustrated the same point: correlated loss across a book driven by a single shared supplier.

The two jobs want the same intelligence — continuous, evidence-backed, outside-in posture data across large numbers of organisations — which is why running them off one layer rather than two is usually the better structure.

The numbers your team already knows.

Insurance organisations are doing third-party risk twice — once as a regulated business with a vendor stack, and once as the underwriter pricing other people's third-party risk. The same intelligence layer should serve both.

5M+
Companies REX continuously monitors
The data moat for cyber underwriting
1,000+
Vendors per major UK insurer
Industry estimate
24 hrs
DORA initial-notification window for major ICT incidents
DORA Article 19

REX, VANCE, ARIA — underwriting and ops, one signal.

Three of The Agency's leads serve the dual mandate: continuous outside-in intelligence for the underwriting desk, regulator-formatted reporting for ops and compliance, and the evidence layer that makes both possible.

REX avatar
REX
Outside-In Intelligence

The 5M+ company data moat — for both sides of the business. REX powers continuous monitoring of your own vendors and outside-in intelligence for cyber underwriting. Same data, same signal, same continuous loop.

What you get
  • 5M+ continuously monitored companies
  • Vendor concentration risk surfaced across the portfolio
  • Underwriting-grade outside-in scoring
VANCE avatar
VANCE
Regulatory Reporting

DORA, FCA, APRA — composed, not assembled. VANCE generates regulator-formatted reports from current evidence — Article 28 packs, FCA outsourcing reviews, APRA CPS 230 attestations — across the portfolio.

What you get
  • DORA Article 28 packs from live data
  • FCA outsourcing and APRA CPS 230 attestations
  • Tamper-evident audit trail per output
ARIA avatar
ARIA
Evidence & Document Intelligence

One evidence layer for vendor risk and claims. ARIA structures every piece of vendor evidence against the 157 Universal Controls — useful for vendor risk teams, useful for claims teams handling cyber incidents.

What you get
  • Documents structured against 157 Universal Controls
  • Contract clause extraction — including liability caps
  • SnapShot summaries on demand for risk and claims

Four shifts you'll feel across underwriting and ops.

Insurance is the only industry where The Agency's combined-signal model serves the underwriting desk and the operational risk team from the same data.

Underwriting backed by combined signal

ARIA's evidence reading + REX's external scanning — reconciled into one view. The "single source of truth" cyber underwriters have been promised, finally architected.

DORA / FCA / APRA from one source

One evidence layer, multiple regulator-formatted outputs. The same data feeds the underwriting desk and the operational resilience report.

Vendor concentration risk visible

The DORA-driven question your board will ask — answered in real time, not assembled at quarter end.

Continuous monitoring across portfolios

Your insured book and your own vendor book monitored the same way, on the same cadence, against the same data.

We replaced two analysts' worth of questionnaire chasing with The Agency in eight weeks. The risk team is finally doing risk work.

JM
CISO
FTSE 250 Insurance

What insurers ask us first.

Underwriting, accumulation, and the regulatory load on the business itself.

Can outside-in security ratings be used in underwriting?
They are widely used as a triage and monitoring signal rather than as a rating factor on their own. Outside-in data is objective, available without the applicant's cooperation and refreshable through the policy period, which makes it good for prioritising submissions, flagging deterioration mid-term and validating what an application form claims. What it cannot see is internal control — backups, segmentation, privileged access, recovery testing — which is where most cyber loss severity is actually determined. Used as one input alongside the application and evidence, it improves the picture; used alone it mostly measures external hygiene.
What is accumulation risk in cyber insurance?
The risk that a single event triggers claims across many insureds at once, because they share a dependency — a cloud region, a managed service provider, a widely deployed security agent, a payment processor. It is the reason cyber capacity is constrained relative to demand: the losses are correlated in a way fire or motor losses are not. Managing it requires knowing the technology dependencies across the book, not just each insured's own posture, which is a fourth-party mapping problem applied to a portfolio.
Does DORA apply to insurers?
Yes. Insurance and reinsurance undertakings are explicitly within scope, as are insurance intermediaries above the size thresholds, with proportionality applied to smaller entities. The Article 28 register of ICT contractual arrangements, the contractual minimums, concentration risk assessment and exit strategies all apply. For a group already reporting under Solvency II outsourcing rules the substance overlaps considerably, but the register format and the completeness expected are more demanding. See our DORA page.
How does this help both underwriting and operations?
Both need the same underlying thing — continuous, evidence-backed posture data across a large population of organisations. Underwriting consumes it as applicant and portfolio intelligence; operational risk consumes it as vendor intelligence for the insurer's own supply chain and its DORA or CPS 230 obligations. Running one layer means the accumulation view and the vendor register are built from the same data, which matters when a shared provider appears on both sides of the balance sheet.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.