Insurance Self-Networking Platforms (ISNPs) operate under IRDAI's cybersecurity guidelines and the IRDAI ISNP regulations. Digital Defense delivers full-scope ISNP audit support — covering customer-facing apps, agent portals, policy-issuance flows, payment integration, claims, KYC/CKYC and data-localisation evidence. Reports are signed by a CERT-In Empanelled auditor.
Direct ISNP operators (web aggregators, online insurance brokers)
Insurance companies running their own ISNP
POSP-based insurance platforms
Insurtech startups partnering with insurers under tied-agent or broker model
Reinsurance brokers operating an electronic platform
IRDAI inspection findings on weak access controls between policy issuance and underwriting
Customer data exposure via under-protected admin or agent portals
Inadequate logging on policy modifications, claim approvals and rejection
Lack of evidence on data-localisation for policyholder PII and payment data
Missing or weak BCP / DR testing artifacts
Inventory of policy issuance, claims, KYC, payment, agent, customer and admin flows.
Mapping current controls against IRDAI ISNP guidelines + IRDAI cybersecurity circulars.
Customer app, agent portal, policy admin, claims, KYC service, payment gateway integration.
Evidence pack for policyholder PII, payment data, KYC, claims documents staying in India.
CERT-In Empanelled auditor signed report mapped to IRDAI guidelines + remediation tracker.
IRDAI ISNP gap-assessment report
Full VAPT report (customer + agent + admin)
Data-localisation evidence pack
BCP / DR drill report
CERT-In Empanelled auditor signed audit report
Yes. Web aggregators have a tighter scope (no policy issuance) — we run targeted audits on the aggregation flow, KYC, customer data and integration with insurers.
Yes — as a CERT-In Empanelled auditor, our reports are accepted by IRDAI inspections and the insurer onboarding the platform.
IRDAI requires annual cybersecurity audits for ISNPs, with quarterly VA and event-driven audits after major releases or incidents.
Mid-sized ISNP: 4-6 weeks (assessment + VAPT + reporting + 30-day re-test). Larger multi-product platforms: 8-10 weeks.
Yes — POSP, bancassurance, broker platforms and aggregator platforms all fall under our ISNP audit practice.
Talk to Digital Defense — India's CERT-In Empanelled cybersecurity team.
Book a consultationOnline | Typically replies instantly
Hi there! 👋 Welcome to Digital Defense. I'm here to help you with your cybersecurity needs. How can I assist you today?