Skip to main content
Insurance · External monitoring evidence

Most of an IRDAI cyber-security file is self-reported.

Policies, registers, control narratives, remediation logs — every one of them authored inside the organisation being examined. The external view is the part an insurer cannot write for itself: what its intermediaries are exposing, whose policyholder credentials are already circulating, and which domains are collecting quote data under its name. ShadowMap produces that record, dated, and hands it to whoever is assembling the file.

What this is

A dated, external record of the exposure attributable to your organisation and to the firms distributing on your behalf — produced continuously, and exportable.

What this is not

An audit, an opinion, or a determination that any instrument binds your entity. Security Brigade does that work, under CERT-In empanelment, on its own site.

The supervisory cycle

What changes at each stage, and where self-reported evidence runs out

The same estate, seen at three points in a cycle. The three registers repeat deliberately: the gap between what you can assert and what you can evidence does not move — it only gets more expensive to close.

01 Between examinations

Nobody is asking yet, which is when the record has to be accumulating

What your team is doing
Running the control programme — patching, access reviews, intermediary questionnaires, the independent audits your own policy and your advisers have put in the calendar. Almost all of it inside the perimeter you operate and can instruct.
Where self-reported evidence runs out
A questionnaire returned by a corporate agent describes what that agent believes about its own estate. It is not an observation of that estate, and nothing in it is dated to a day anyone can point at afterwards.
What the external record contributes
Continuous observation of the properties carrying your name from outside, whether or not anybody filled in a form. The value is that it was already running before the question existed — a record started in response to a question proves only that you responded.
02 Assembling the file

The submission gets written, and its external half has to come from somewhere

What your team is doing
Pulling policies, registers, test reports and remediation logs into one file, with a compliance owner reconciling them against the guidelines mapping your advisers produced for your licence class.
Where self-reported evidence runs out
Every artefact in the file was authored by the organisation the file describes. Where an item concerns an intermediary, or an exposure sitting on the customer side, the honest answer is often that nobody looked.
What the external record contributes
An exportable record of what was observed, when, under what scope, and what was deliberately left out — including the intermediary estates that were observed rather than tested, stated as such rather than quietly counted as clean.
03 When someone follows up

The question is how far back you can see, and it is rarely in the file

What your team is doing
Answering on a specific finding, a specific date or a specific distribution partner — usually at a level of detail the submission was never built to anticipate.
Where self-reported evidence runs out
Point-in-time testing answers for the day it ran. A question about the months in between has no artefact behind it, and reconstructing one after the fact is both expensive and unconvincing.
What the external record contributes
The dated history, retrievable per asset and per identity — including its corrections. Because the raw source material is retained, an exposure first extracted this month can be shown to have originated on a machine compromised long before, rather than being presented as something new.

What a finding is allowed to claim

Four states, and what each one lets you write down

This matters more in a regulatory record than in a ticket queue. A finding that overstates what was verified is worse than no finding at all, so the states are published exactly as the platform shows them, and the third column states what the evidence will actually support if somebody leans on it.

Credential states, read as evidence
StateWhat it meansWhat the record supports
Confirmed Working Probed and it authenticated. The account is reachable with this credential now. Supports a statement that a live credential existed on a stated date. Rotate today, and check for session persistence.
Maybe Working Probing was inconclusive — rate limiting, an MFA interstitial, or an ambiguous response. Supports “not ruled out”, and nothing stronger. Treat as live until your own team has checked it.
Not Working Probed and rejected. The credential is stale against this service. Still evidences a compromised endpoint — which is the finding a stale password tends to conceal.
Not Tested Outside authorised scope, or no safe probe exists. An intermediary’s own systems usually land here. The record says exactly that. We never imply validation we did not perform, and a file built on the opposite fails on its first follow-up question.
Key
  • Verified live
  • Not ruled out
  • Stale — endpoint still exposed
  • Unverified by us

Where the exposure sits

What carries your name, and who actually runs it

Insurers carry a large customer-identity estate and a long intermediary chain, which is why credential exposure and third-party observation are the two capabilities that do the most work here. Each row is a different question about whose asset this is, answered in a different part of the platform — and each row carries its own limits, because a boundary declared three sections later is a boundary nobody read.

External exposure an insurer is answerable for, by owner and by evidence source
What carries your nameWho actually runs itWhere the dated record sits
Policyholder and employee credentials in stealer logs and breach corpora Nobody you can instruct. The machines are personal; the identities are your customers and your staff Dark Web Monitoring
Identity exposure is the sharpest form of this for an insurer, because the estate of personal data is large and the remedy is not yours to apply. Every credential carries an explicit state, and the ones that could not be probed safely say so rather than being counted as clean. The corpus is 12B+ breach and credential records against ~41TB of retained source material, which is what lets a finding be dated to the compromise that produced it rather than to the day it was noticed.
Corporate agents, brokers, web aggregators and bancassurance partners The intermediary, on its own infrastructure, under its own change control Third-Party Risk Management
Intermediated distribution is the clearest case in financial services of an estate that carries your brand from outside your change control. Partners are assessed with the same method used on your own estate, and they arrive observed rather than tested: an insurer cannot grant permission over a broker’s own servers, and we do not proceed as though it had. What you get per partner is a continuously refreshed outside view sitting beside the questionnaire they returned.
Look-alike domains, and quote or renewal pages collecting policyholder details Whoever registered them — sometimes a fraud operation, sometimes an over-enthusiastic agent Brand Protection
Separated from the partner and reseller properties that legitimately carry your name, because an agent’s microsite and a credential-harvesting page look identical to a keyword alert. Confirmed impersonation is raised for takedown, and takedowns are unlimited, subject to fair use.
Self-network platforms, partner portals and quote APIs reachable from outside Your platform team, or a vendor’s, or a team that has been reorganised twice since it shipped Attack Surface Management
Discovery runs outside-in with no agent and no credentials, and each asset is attributed back to your organisation with the evidence for the attribution recorded alongside it. That matters for a group whose name is shared across several licensed entities and a set of joint ventures, where a name match on its own would pull in infrastructure that is not yours.
What IRDAI, and the other authorities supervising the same group, have published The authority — and it changes without telling you Regulatory Intelligence
What an authority publishes on information and cyber security, and on outsourced and intermediated distribution, is tracked as it changes rather than as it stood when somebody last read it. We do not restate an instrument, cite it or number it here. What this will not do is tell you whether any of it binds your entity. That is a legal determination, and it stays with your compliance function and your advisers.

External exposure an insurer is answerable for, by owner and by evidence source

Policyholder and employee credentials in stealer logs and breach corpora

Who actually runs it
Nobody you can instruct. The machines are personal; the identities are your customers and your staff
Where the dated record sits
Dark Web Monitoring

Identity exposure is the sharpest form of this for an insurer, because the estate of personal data is large and the remedy is not yours to apply. Every credential carries an explicit state, and the ones that could not be probed safely say so rather than being counted as clean. The corpus is 12B+ breach and credential records against ~41TB of retained source material, which is what lets a finding be dated to the compromise that produced it rather than to the day it was noticed.

Corporate agents, brokers, web aggregators and bancassurance partners

Who actually runs it
The intermediary, on its own infrastructure, under its own change control
Where the dated record sits
Third-Party Risk Management

Intermediated distribution is the clearest case in financial services of an estate that carries your brand from outside your change control. Partners are assessed with the same method used on your own estate, and they arrive observed rather than tested: an insurer cannot grant permission over a broker’s own servers, and we do not proceed as though it had. What you get per partner is a continuously refreshed outside view sitting beside the questionnaire they returned.

Look-alike domains, and quote or renewal pages collecting policyholder details

Who actually runs it
Whoever registered them — sometimes a fraud operation, sometimes an over-enthusiastic agent
Where the dated record sits
Brand Protection

Separated from the partner and reseller properties that legitimately carry your name, because an agent’s microsite and a credential-harvesting page look identical to a keyword alert. Confirmed impersonation is raised for takedown, and takedowns are unlimited, subject to fair use.

Self-network platforms, partner portals and quote APIs reachable from outside

Who actually runs it
Your platform team, or a vendor’s, or a team that has been reorganised twice since it shipped
Where the dated record sits
Attack Surface Management

Discovery runs outside-in with no agent and no credentials, and each asset is attributed back to your organisation with the evidence for the attribution recorded alongside it. That matters for a group whose name is shared across several licensed entities and a set of joint ventures, where a name match on its own would pull in infrastructure that is not yours.

What IRDAI, and the other authorities supervising the same group, have published

Who actually runs it
The authority — and it changes without telling you
Where the dated record sits
Regulatory Intelligence

What an authority publishes on information and cyber security, and on outsourced and intermediated distribution, is tracked as it changes rather than as it stood when somebody last read it. We do not restate an instrument, cite it or number it here. What this will not do is tell you whether any of it binds your entity. That is a legal determination, and it stays with your compliance function and your advisers.

The sequence

How the record gets made

Order is the content here, not the decoration. Each step bounds what the next one is permitted to look at, which is why an exposure snapshot starts at the perimeter rather than at the finding.

The boundary

The output is an input to a regulatory decision, not the decision

Nothing on this page tells you what IRDAI requires of your entity. That determination is legal, it turns on your licence class and how you distribute, and it belongs to your compliance function and your advisers — the assessment practice at Security Brigade is where that work is done.

What monitoring can do is answer the questions sitting underneath such a determination — the ones that are unanswerable from inside the perimeter. What was reachable from outside on a given date. Whose it turned out to be once it was attributed. Whether an exposed credential still opened anything, or only looked as though it might. And what was already known before the incident that prompted somebody to ask.

Those answers arrive as records carrying timestamps, scope profiles and audit identifiers, so they reconcile against your own logs instead of arriving as assertions that have to be taken on trust. An insurer’s supervisory surface is wider than any single authority, and the same record is put to work across the rest of it — see how it reads for financial services as a whole.

Sourcing and boundaries

How the record is built, and what it deliberately leaves out

How the external record is produced As of August 2026
  • Collection is outside-in. Nothing is installed, no agent runs, no credentials are taken, and nothing is touched that is not already reachable from the public internet.
  • Attribution is evidenced per asset. The record states why an asset was tied to your organisation, so a shared group name does not silently pull in somebody else’s infrastructure.
  • Credential and breach material is matched against our own corpus rather than a licensed feed, and the raw source archives are retained — so a finding improves when our extraction improves, not only when something new is stolen.
  • Validation runs where it is safe and authorised. Every probe carries its evidence, timestamp, scope profile and audit identifier, and the exclusions and rate limits that bounded a run are part of the same record.
  • Regulatory tracking covers what an authority publishes, read from its circulars, guidelines, regulations and enforcement material separately, because cyber-resilience content does not reliably appear in any one of them.

Deliberately excluded

  • Whether any instrument binds your entity. That is a legal determination, it turns on your licence class and your distribution model, and it belongs to your compliance function and your advisers.
  • Assessment, gap analysis, control testing and audit readiness. That is Security Brigade’s practice, CERT-In empanelled since 2008, and it runs on its own site.
  • Source names, channel topology and collection methods. Publishing them is how collection gets blocked.
  • Testing of intermediary systems. Partner estates are observed, never probed: an insurer cannot authorise testing of a broker’s own servers.

Questions insurers actually ask

Before you evaluate this

Does ShadowMap make us compliant with the IRDAI cyber-security guidelines?

No — and a vendor who says otherwise is selling you a problem. Compliance is a determination about your entity, made against instruments your advisers map to your licence class and your distribution model. What we produce is one input to that determination: a dated external record of what was exposed, whose it turned out to be, and what was actually verified. Security Brigade runs the assessment and audit side of this work under CERT-In empanelment, and the two are kept deliberately separate.

Our intermediaries already return security questionnaires. What does this add?

A questionnaire is a description of an estate written by the party that owns it. This is an observation of the same estate from outside, refreshed continuously, and it does not depend on anybody returning a form. The two are complementary rather than competing — and the interesting cases are the ones where the returned questionnaire and the observed estate disagree. That gap is usually the conversation worth having with the partner.

How is policyholder exposure different from employee credential exposure?

Scale, and remedy. Employee exposure is small enough to rotate and serious enough to act on immediately, and you control the accounts. Policyholder exposure is far larger, sits on machines you do not manage, and you cannot force a reset. What you can do is know it exists, correlate it to the products and channels it reaches, and read a cluster of it as a signal about a distribution partner rather than about your customers’ password hygiene.

Can we get a record covering the period before we started monitoring?

Partly, and it is worth being precise about which half. Credential and breach exposure is historical by its nature: a first scan reaches into material collected long before you were a customer, and each finding is dated to the compromise that produced it rather than to the day we saw it. Continuous observation of your external estate, by contrast, begins when monitoring begins. There is no back-dated record of what a domain looked like before anyone was watching it, and we will not pretend there is.

See what is visible from outside before someone asks you for it

One apex domain, two business days, a written snapshot of what is already reachable from outside — assets, exposed credentials, leaked code and domains wearing your brand. No call required.