Insurance brokers hold sensitive client data, access insurer portals, and manage complex supplier relationships — making them a high-value target for cybercriminals. The FCA knows this. Your clients are starting to ask about it. Here's what you need to know, and the free tools to help you act on it.
The tools and resources on this page didn't come from a product team — they came from a frustration. After 30 years working across IT infrastructure, risk management and FCA-regulated financial services, I became increasingly aware of the gap between the cyber risks faced by SMEs and the practical help available to them. Most solutions were designed for large enterprises, or focused on selling products rather than helping organisations understand their actual exposure.
So I built what I wished had existed. And before launching anything, I wanted to understand the problem properly.
Using a passive OSINT approach — nothing intrusive, no systems touched — I developed the Cyber-Vitals scanning framework and ran it across 2,011 UK-biased domains (findings published March 2026) spanning five sectors: Finance, Insurance Brokerage, Charities, Education, Manufacturing and General SMEs. The findings were consistent, troubling, and largely avoidable. They directly shaped every tool and recommendation on this page.
Phishing and email compromise aren't theoretical risks for financial services firms. GET-IT's own audit of 2,011 UK domains, published in March 2026, found the technical foundations that could reduce them largely unimplemented.
Business Email Compromise (BEC) and Funds Transfer Fraud are a major source of cyber insurance claims — and they typically start with a phishing email or a compromised inbox.
of domains analysed in our 2,011-domain UK audit lacked DMARC 'reject' enforcement — meaning their email domain could be impersonated by any attacker, today, without their knowledge.
Source: GET-IT's own research — UK Cyber Risk Landscape 2026 (passive OSINT audit of 2,011 UK domains, published March 2026)A compromised mailbox is a common route into Funds Transfer Fraud. For brokers handling premium payments and client instructions, this is a direct exposure.
reduction in observable risk profile was achieved when standard hardening techniques were applied to a typical UK domain in our audit. A properly configured DMARC, SPF, and DKIM setup can close the impersonation gap quickly, without disrupting any existing infrastructure.
Source: GET-IT's own research — UK Cyber Risk Landscape 2026, Remediation Gap findings (published March 2026)Checking that is part of the Cyber Vitals scan GET-IT runs within the Cyber Resilience Review — gathering evidence across email authentication (SPF, DKIM, DMARC), web security headers, SSL and breach exposure, then interpreting it for your firm and turning it into prioritised recommendations. Fixed price: £495.
Cybercriminals don't target brokers opportunistically — they target them because of what brokers hold. High volumes of personal data, direct access to insurer systems, and complex third-party relationships make brokers one of the most valuable targets in the UK financial services sector. Yet most broker firms operate as SMEs, without a dedicated security team or formal risk management function.
That combination — high-value data, complex access, limited defences — is exactly what attackers look for.
Names, addresses, financial details, claims history. Highly valuable on dark web markets and subject to ICO reporting obligations if compromised.
Credentials to insurer extranet systems are a gateway to policy manipulation, fraudulent submissions, and lateral movement across the supply chain.
High volumes of financial instruction by email — premium payments, bank detail changes — create significant business email compromise exposure at every renewal cycle.
Binding authority arrangements mean a compromise at broker level can expose MGA and insurer partners upstream — raising the stakes for everyone in the chain.
Policy management systems, premium finance providers, comparison platforms — each third-party connection is a potential entry point if not properly managed.
Most brokers run lean. Without dedicated IT resource, security is often reactive. Patching delays, shared credentials, and legacy systems are common findings in our domain audits.
These aren't theoretical risks. Each of the following attack types has been used against UK financial services firms.
Targeted emails impersonating insurers, HMRC, or senior staff. Often the first step in a larger attack.
Most common entry pointAn attacker gains access to a mailbox and becomes a silent insider — intercepting payment instructions, harvesting credentials, redirecting client communications. An attacker may dwell undetected for weeks. Premium payments and bank detail changes are high-risk moments for brokers.
High financial impactSystems encrypted, operations halted. Attackers increasingly steal data as well as encrypting it. For brokers mid-renewal season, even 48 hours of downtime has serious commercial consequences.
Operational disruptionStolen usernames and passwords used to access insurer portals, policy systems, or email. Often acquired via phishing or purchased from previous breaches. Our audit found 87.8% of the 2,011 UK domains analysed lacked DMARC 'reject' enforcement — which makes impersonating them in credential-harvesting emails far easier.
Portal access riskAn attack on a software provider, aggregator, or support firm cascades to your systems. You don't need to be breached directly — a trusted supplier is enough.
Supply chain riskDeparting staff, disgruntled employees, or compromised accounts with excessive access. Access controls and offboarding processes are frequently weak in smaller firms — and rarely tested.
Often overlookedThe FCA does not prescribe a specific cyber framework — but it is increasingly explicit that cyber resilience is a core operational risk obligation, not a technical afterthought. The following areas are directly relevant to brokers.
The Consumer Duty (PS22/9) requires firms to act to deliver good outcomes for retail customers across the product lifecycle. Cyber incidents that expose client data, disrupt service, or result in financial loss are Consumer Duty failures. Firms are expected to have adequate controls in place — and to evidence them.
FCA Consumer Duty guidanceThe FCA's operational resilience rules apply to banks, building societies, insurers, PRA-designated investment firms and enhanced scope SM&CR firms — so they bind larger intermediaries rather than every small broker. Since March 2025, in-scope firms must be able to remain within the impact tolerances they have set for their important business services during disruption, including cyber incidents. Most small brokers are core SM&CR firms and fall outside these specific rules, but every authorised firm is still expected to manage operational and cyber risk in a way that is proportionate to its business.
FCA Operational Resilience policy statementUnder the Senior Managers and Certification Regime, senior managers carry personal accountability for the adequacy of their firm's risk management — including cyber risk. That accountability does not disappear because the firm is small or because cyber security was delegated to a third party.
FCA SMCR overviewUnder UK GDPR, personal data breaches likely to result in risk to individuals must be reported to the ICO within 72 hours of discovery. Brokers hold significant volumes of personal data — claims history, financial details, health information in some cases. Failure to report attracts regulatory sanction.
ICO breach reporting guidanceThe NCSC's Cyber Essentials framework defines five technical controls that, properly implemented, protect against the majority of common cyberattacks. For brokers, these are a credible starting point — not a ceiling. Our ORA tool assesses your position against these controls and others in under ten minutes.
The BIBA member guidance hub is a useful reference for brokers assessing their regulatory position alongside these technical controls.
Tools built by GET-IT Cyber Division to give UK brokers a practical, accessible way to understand and act on cyber risk. The Operational Risk Assessment and MITRE-Lite are free, with no login and no sales call required. Cyber Vitals is the evidence-gathering scan used within the Cyber Resilience Review.
A passive domain security scan that checks how your organisation looks to an outside observer — and to an attacker. GET-IT uses it to gather structured evidence within the Cyber Resilience Review, then interprets the findings for your firm.
A structured 30-question risk assessment aligned to Cyber Essentials v3.3. Produces a scored report across five security pillars with plain-English observations and a branded PDF — in under ten minutes.
Use it to start an informed cyber risk conversation within your own firm or to understand your exposure before a renewal. It is a self-reported assessment — a signal of where to look, not formal evidence of your position.
A weekly-updated threat intelligence layer built on the MITRE ATT&CK framework — translated into plain English. Covers active attack techniques, real-world incidents, and NCSC advisories relevant to UK businesses.
Stay current on the threat landscape without needing a security operations team. Use it to understand what's active right now in the sectors you operate in.
The free tools above flag where to look. The Cyber Resilience Review (£495) is where those signals are interpreted and prioritised for your firm. If the resulting roadmap points to something that needs hands-on technical work, GET-IT can arrange it. The following services are delivered through specialist technical partners, managed through us — one point of contact, no need to navigate multiple suppliers.
These are outsourced technical services — GET-IT acts as the point of coordination. All services are delivered by specialist practitioners. Contact us to discuss scope, timelines and pricing.
Preparation support and independent technical audit for Cyber Essentials and Cyber Essentials Plus certification. Increasingly required by insurers, MGAs, and larger counterparties as a condition of doing business. A natural next step if your ORA surfaces gaps in the five core controls.
Discuss This Service →Authorised simulated attacks against your systems to identify exploitable vulnerabilities before attackers do. Relevant for larger brokers, those with delegated authority arrangements, and any firm whose insurer or MGA is asking for evidence of testing as a renewal condition.
Discuss This Service →A comprehensive review of your Active Directory environment — user access, privilege levels, stale accounts, group policy, and configuration weaknesses. Particularly relevant for broker firms with staff on VPN or remote access, where credential exposure is a primary attack vector.
Discuss This Service →Practical support for organisations preparing for IASME Cyber Assurance Level 1 or Level 2 — scope review, evidence preparation, control uplift, and guidance through the certification journey. A more comprehensive alternative to Cyber Essentials for firms that want stronger client-facing credibility.
Discuss This Service →These are the authoritative resources we'd point any broker to — no affiliation, no commercial arrangement, just useful guidance.
Practical, UK-government-backed guidance scaled for smaller firms. Covers email, devices, passwords, and phishing.
→ Visit NCSC ↗ FCAThe FCA's expectations on cyber resilience, including their multi-firm review findings and good practice examples.
→ Visit FCA ↗ BIBAMember guidance, regulatory updates, and sector-specific resources for UK insurance brokers.
→ Visit BIBA ↗ ICOData protection obligations, breach reporting requirements, and accountability documentation guidance.
→ Visit ICO ↗ GET-ITPlain-English guide to the government-backed certification scheme — what it covers, what it costs, and whether your firm needs it.
→ Read the guide GET-ITNCSC-aligned guidance on exactly what to do next — calmly, methodically, and in the right order. For UK businesses.
→ Read the guideCFC Cyber Masterclass — Free, CII-accredited CPD learning for brokers. Over 25 videos covering cyber economics, coverage, threat landscape and security controls. 5 hours of accredited learning at your own pace. Visit CFC Masterclass ↗
We work with brokers and their clients on practical cyber risk — assessments, Cyber Essentials readiness, and incident response planning. No jargon, no pressure. If it's useful, we'll tell you. If it isn't, we'll tell you that too.
[ Remote. Confidential. No obligation. ]
The brokers who will navigate the next five years well are not those who treat cyber risk as an IT problem. They are those who treat it as a business risk — one with regulatory, commercial, and reputational dimensions that sit firmly on the senior manager's desk. After thirty years in regulated financial services, I built these tools because I believe the guidance and insight needed to have that conversation should be accessible to every broker, regardless of size. Use them as often as you need.
— Franco Pietrantonio, GET-IT Cyber Division