IRDAI cyber security · ISO/IEC 27001:2022
Compliance work for insurers, foreign reinsurance branches, brokers, corporate agents, TPAs and other IRDAI-regulated intermediaries divides into two halves that should not sit with the same firm. One half is assurance: an independent audit against the IRDAI Information and Cyber Security Guidelines, 2023. The other is implementation — designing the controls, running them, and producing evidence that they actually operated. We do the second.
Gap assessment · control implementation · security operations · evidence
The division
Where we fit
The separation is the point, not a limitation.
| The work | Who should do it | What we provide |
|---|---|---|
| Independent audit or assurance | An independent auditor | Nothing — engaging your implementer as your auditor defeats the purpose of both |
| Gap assessment | Either | A control-by-control read of where you stand |
| Control implementation | Us with your team | Network, identity, endpoint, logging and recovery controls |
| Security operations | Us or in-house | SOC and NOC capability, and the records they generate |
| Evidence | Us with your team | Repeatable proof that a control operated, not just that it exists |
Scroll the table sideways on a narrow screen.
If a provider offers to both implement your controls and audit them, that is the first thing to question.
Control domains
The controls we actually implement
Regulatory frameworks differ in wording and overlap almost entirely in substance. The control domains below are what the work reduces to in practice.
Identity and access
Joiner-mover-leaver process, privileged access separation, multi-factor authentication on administrative paths, and access reviews that produce a dated record with a named approver rather than an assertion.
Network segmentation
Separating what must not reach what, and being able to demonstrate the separation from the running configuration rather than from a diagram. See firewall audit.
Logging and retention
Logs that leave the device, are retained where they can be queried, and cover the systems the policy claims they cover. See SIEM services.
Monitoring and response
Somebody watching, with a defined escalation path and a record of what was seen and what was done about it.
Backup and recovery
Tested recovery with a documented result. An untested backup is a claim, and auditors have become good at asking when it was last proven. See backup and DR.
Third-party risk
Knowing which suppliers reach your data and what they are contractually obliged to do about it — increasingly the domain where findings are raised.
The real difficulty
Why evidence is the hard part
Regulated entities rarely fail on the absence of controls. They struggle to demonstrate that a control operated consistently over the period under review — that access was reviewed and by whom, that changes went through approval, that monitoring actually covered the systems it claimed to, that recovery was tested rather than assumed.
That is an operations problem rather than a documentation problem, which is why organisations running a real SOC and NOC find audits substantially less painful: the evidence is a by-product of the operation rather than something assembled retrospectively each year.
On regulatory specifics — deadlines, thresholds, submission windows — we do not restate them on this page. They are amended, and a confidently wrong figure on a vendor’s website is worse than no figure. We will check the current text with you against your own category.
Related
Related work
These sit alongside this engagement more often than not:
Managed security services
Day-to-day security operations run on your behalf, which is what leadership and compliance work both depend on.
Questions
IRDAI Cyber Security Compliance for Insurers, Brokers and TPAs, answered
Who do the IRDAI guidelines apply to?
The 2023 guidelines apply broadly across the sector — insurers and foreign reinsurance branches, and intermediaries including brokers, corporate agents, web aggregators, TPAs and ISNP operators. Confirm your specific applicability against the current IRDAI text.
We are a broker, not an insurer. Does this affect us?
Intermediaries are within scope, and this is the most common surprise we encounter. Smaller intermediaries frequently assume the obligations sit with the insurer alone.
Can you sign our audit?
No. Assurance must be independent of implementation. We build and operate the controls and produce the evidence; the audit is performed by someone else, and that separation is the point.
Are you CERT-In empanelled?
No, and we will not imply otherwise. Where an engagement requires an empanelled auditor, that work goes to an empanelled firm and we support the implementation and remediation around it.
Do you hold a security certification yourselves?
P J Networks holds ISO/IEC 27001:2022. We have been operating since 2002 and run our own NOC and SOC from New Delhi.
Can you help if we have already failed an audit?
Yes, and it is a common starting point. A findings list is in practice a well-specified scope of work — we take the observations, agree remediation with owners and dates, implement, and produce the evidence for the follow-up review.
Next step
Talk to someone who has done this before
Tell us where you are and we will tell you what the work actually involves. If you do not need us, we will say so.



