Insurers do third-party risk twice, for two different purposes, and the distinction is worth keeping clear.
As regulated businesses, they carry the same obligations as other financial institutions: DORA applies to insurance and reinsurance undertakings in the EU, Solvency II treats outsourcing as an operational risk requiring governance and notification of critical functions, UK firms are subject to FCA and PRA operational resilience rules, Australian insurers to APRA CPS 230, and US insurers frequently to NYDFS Part 500 and the NAIC model law.
As underwriters of cyber risk, they assess third-party security as the product itself — pricing policies against an applicant's posture, managing accumulation where many insureds share a dependency, and monitoring exposure through the policy period rather than only at renewal. The 2024 CrowdStrike outage and the Change Healthcare breach both illustrated the same point: correlated loss across a book driven by a single shared supplier.
The two jobs want the same intelligence — continuous, evidence-backed, outside-in posture data across large numbers of organisations — which is why running them off one layer rather than two is usually the better structure.