“In a world of hybrid working, remote access, cloud infrastructure, and cross-border data flows, traditional boundaries no longer hold”
The shift away from perimeter-based security models is accelerating as cloud adoption, hybrid working, and cross-border data flows reshape the sector.
Mark Kirkby, Professional Services Director at Intersys, said the shift had become unavoidable: “In a world of hybrid working, remote access, cloud infrastructure, and cross-border data flows, traditional boundaries no longer hold,” he said.
Kirkby said this development was being driven by the need to secure increasingly mobile and sensitive information across distributed environments.
“Our approach is firmly identity- and data-centric. Zero trust is foundational: every user, device and workload must continuously prove it can be trusted, regardless of location,” he explained. “Alongside this, data classification and segmentation have become critical, particularly in healthcare and insurance, where highly sensitive personal and clinical data is constantly in motion.”
Bruce McIndoe, Founder of Travel Risk Academy, argued that the implications extend beyond infrastructure alone: “Secure data storage is no longer just an IT architecture issue,” he said. “In healthcare and insurance, it is central to operational resilience.”
Thierry Montrieux, Mentor at Travel Risk Academy, highlighted that this complexity was compounded by regulatory fragmentation and user behaviour in cross-border environments: “Cross-border compliance is another key challenge. Organisations must navigate varying data protection, residency, and healthcare regulations, often aligning with international standards while adapting to local legal requirements.”
He added that the human layer remained central to reducing exposure: “There is also an increasing emphasis on traveller awareness, encouraging users to avoid unsecured networks, maintain updated devices, and use trusted platforms when accessing healthcare services abroad.”
The growing burden of legacy systems
Although many organisations are investing in modern security frameworks, legacy infrastructure remains one of the sector’s most persistent vulnerabilities. Outdated hardware, software, and physical facilities that no longer meet current technological or operational standards continue to expose organisations to risk.
“The biggest cybersecurity challenge posed by legacy systems is that they are no longer patched or maintained, and there can be significant vulnerabilities within them,” Steptoe warned. “And unfortunately, artificial intelligence (AI) and cybercrime organisations can use these vulnerabilities as entry points to cause breaches and systems damage.”
These risks are becoming more visible as organisations are pushed to modernise: “AI-based projects, notably [Anthropic-led cybersecurity initiative] Project Glasswing, are bringing these vulnerabilities to the forefront and showcasing that organisations need to prioritise modernising their infrastructure,” Steptoe explained.
However, modernisation is rarely simple in healthcare and insurance environments that run continuously and depend on complex international systems. Therefore, insurers are increasingly favouring gradual approaches.
“Legacy systems remain one of the most persistent sources of cyber risk, especially in insurance, where core platforms often underpin critical operations but lack compatibility with modern security frameworks,” said Kirkby.
He warned that full replacement could itself create disruption: “A more effective approach is phased modernisation,” he explained. “In the short term, organisations can reduce exposure through compensating controls such as network segmentation, privileged access management, and enhanced monitoring.
“This allows insurers to strengthen their security posture incrementally while maintaining business continuity, an essential balance in a 24/7, customer-facing industry,” Kirkby added.
McIndoe noted that legacy risk was often underestimated because of how embedded older systems were: “Legacy systems create risk because they often support critical workflows, are costly to replace and retrain the workforce, but were not designed for today’s threat environment,” he said.
He stressed the urgency in healthcare, where system failures can directly affect patient care: “I would think that addressing legacy systems is particularly important in healthcare, where ransomware, data breaches, and availability attacks remain persistent concerns.
“The cyber risk is not only the connection; it is the ecosystem behind the connection”
“The immediate answer to addressing this is replacement. However, doing this is costly and difficult,” McIndoe explained. “Many healthcare and insurance organisations must modernise while continuing to operate.”
Glukhman highlighted added complexity in international ecosystems due to uneven digital maturity across partners. “In international medical assistance, this challenge is amplified because we interact not only with our own systems, but also with medical providers, insurers, and payment providers operating at very different levels of digital maturity,” she said.
As a result, many organisations opt for gradual migration strategies. “Rather than attempting large-scale ‘rip and replace’ projects, we focus on isolating legacy components, strengthening access controls around
them, introducing secure middleware layers, and progressively migrating critical functions toward more modern architectures,” Glukhman explained.
She also emphasised the importance of human factors alongside technical change: “At the same time, at AP Companies we place significant emphasis on staff awareness and operational discipline because human behaviour remains one of the largest cybersecurity risk factors regardless of technology stack,” she added.
Telemedicine expands the attack surface
The rapid growth of telemedicine is adding new complexity for healthcare and travel insurers, enabling travellers to access medical advice from airports, hotels, cruise ships, and other temporary locations. However, these conveniences also introduce new cyber risks tied to public Wi-Fi, unmanaged devices, and cross-border data transfers.
Steptoe warned that organisations should assume unfamiliar networks are unsafe: “When accessing sensitive data while travelling, especially across borders, best practice is to assume any unfamiliar network is insecure and act accordingly,” he said.
That requires strong protective measures: “Use a trusted, encrypted connection always – preferably a corporate VPN or secure cellular data instead of public Wi-Fi – and ensure all access is protected with strong, phishing-resistant multi-factor authentication,” Steptoe advised.
Kirkby said telemedicine was reshaping how secure access is designed, with a focus on default distrust of networks. He told ITIJ that layered protections were now standard. “We enforce secure access through conditional access policies, strong authentication, device posture checks, and end-to-end encryption,” he explained.
“This ensures that even when a traveller connects from a hotel, airport or remote location, sensitive medical data remains protected.”
McIndoe highlighted that telemedicine expands risk beyond connectivity into governance and third-party exposure. “The traveller may be in an airport, hotel, cruise ship, conflict-adjacent location, or foreign jurisdiction using an unmanaged device over an untrusted network,” he said. “This creates a complex risk profile.”
McIndoe added that data governance was now central: “There is also a cross-border governance issue. Healthcare and insurance organisations need to understand where data is stored, where it is accessed, which laws apply, and which third parties are involved in the care or claims process. The cyber risk is not only the connection; it is the ecosystem behind the connection.”
AI adoption raises new governance questions
AI is now embedded across healthcare, insurance, and assistance operations, supporting claims handling, fraud detection, triage, and customer support.
Steptoe told ITIJ that structured oversight was essential: “At BOXX, we take a structured approach to embedding AI safely into operations,” he said. “We equip employees with clear policies, approved tools, and targeted training on AI-specific risks so they can confidently integrate AI into their workflows without introducing unnecessary exposure.”
He added that reducing ‘shadow AI’ – the use of unauthorised AI tools, software, or large language models (LLMs) by employees within an organisation – was a priority: “By making it easier to ask than to bypass controls, we reduce shadow AI and ensure new capabilities are deployed with appropriate oversight.”
Kirkby highlighted visibility and governance as key issues: “The biggest challenge is visibility: understanding what data is being used, how models are accessed, and where vulnerabilities may emerge,” he explained. He added that controls should be built in early: “Retrofitting controls after deployment is where organisations expose themselves to the greatest risk.”
“The biggest challenge is visibility: understanding what data is being used, how models are accessed, and where vulnerabilities may emerge”
McIndoe argued AI should be treated as core infrastructure: “That means it needs governance, access controls, testing, monitoring, and clear rules about what data can be used, retained, shared, or acted upon.”
He warned of risks around misuse and automation: “In healthcare and insurance, these risks can affect privacy, claims handling, clinical support, regulatory compliance, and customer trust,” he explained.
Montrieux framed the issue more broadly, pointing to the underlying technical risk categories emerging across the sector: “Key concerns being addressed across the market include data leakage, model manipulation, bias, and unintended system behaviour.”
He added a governance imperative: “The prevailing view is that AI should enhance resilience and operational effectiveness, but only within a structured and well-governed security framework.”
Glukhman stressed the importance of human oversight and caution with third-party tools: “At AP Companies, we view AI as a tool that should augment professional judgement rather than replace it,” she said. “We are especially careful regarding third-party AI tools, data-sharing practices, and the potential for sensitive information leakage into external models,” she added.
Overall, she said the key challenge was responsible adoption at scale: “Ultimately, the challenge for the industry is not whether to adopt AI – because that is already happening – but how to adopt it in a way that strengthens operational resilience rather than weakening it,” she added.
Cyber insurance drives higher standards
Steptoe pointed out that cyber insurance was helping raise baseline security expectations: “The rise of cyber insurance is helping set clear minimum-security standards across ecosystems, with more forward-thinking cyber insurers shifting the focus toward prevention rather than just recovery,” he said.
He also noted the improvement of risk management across supply chains: “Cyber insurance also has a role to play in helping to build trust by raising the overall security baseline across partners and supply chains, ensuring risks are better managed and shared.”
Kirkby noted that insurers were already shaping behaviour through underwriting requirements: “Cyber insurance is actively shaping how organisations are managing risk,” he explained. “Insurers are increasingly requiring clear evidence of controls, resilience, and incident readiness, which is driving improved cyber hygiene across the ecosystem.”
He added that cyber maturity was becoming commercially important: “The ability to demonstrate strong cyber maturity is an absolute differentiator… for building trust with partners and customers,” he said.
McIndoe said insurance strengthens resilience when it reinforces good practice. “Cyber insurance helps strengthen the cybersecurity posture… because it forces organisations to quantify exposure, examine controls, and think more seriously about business interruption, ransomware, data loss, third-party dependency, and recovery,” he said. However, he warned it was not a replacement for preparedness: “Insurance provides economic protection, not organisation or people protection.”
Montrieux reinforced this distinction between financial mitigation and operational resilience: “There is a growing understanding that insurance is not a substitute for resilience. The emphasis is shifting toward prevention, early detection, and coordinated response.”
Overall, organisations are converging on layered security and resilience models combining zero trust, segmentation, monitoring, and governance as digital ecosystems expand and threats become more complex.