Combine AI-driven security operations, multi-signal attack surface coverage and 24/7 Elite Threat Hunters to help you take your security program to the next level.
Get unlimited Incident Response with threat suppression guarantee - anytime, anywhere.
CTEM and advisory programs that identify security gaps and build proactive strategies to address them.
Multi-agent Generative AI system embedded across eSentire’s Security Operations platform to scale human expertise.
Extended Detection andOpen XDR with Agentic AI & machine learning that eliminates noise, enables real-time detection and response, and automatically blocks threats.
Customer PortalSee what our SOC sees, review investigations, and see how we are protecting your business.
Platform IntegrationsSeamless integrations and threat investigation across your existing tech stack.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
Threat Response Unit (TRU)Proactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Cyber Resilience TeamExtend your team capabilities and prevent business disruption with expertise from eSentire.
Response and RemediationWe balance automated blocks with rapid human-led investigations to manage threats.
Flexible MDR pricing and packages that fit your unique security requirements.
Entry level foundational MDR coverage
Comprehensive Next Level eSentire MDR
Next Level eSentire MDR with Cyber Risk Advisors to continuously advance your security program
Stop ransomware before it spreads.
Identity ResponseStop identity-based cyberattacks.
Zero Day AttacksDetect and respond to zero-day exploits.
Cybersecurity ComplianceMeet regulatory compliance mandates.
Third-Party RiskDefend third-party and supply chain risk.
Cloud MisconfigurationEnd misconfigurations and policy violations.
Cyber RiskAdopt a risk-based security approach.
Mid-Market SecurityMid-market security essentials to prioritize.
Sensitive Data SecurityProtect your most sensitive data.
Cyber InsuranceMeet insurability requirements with MDR.
Cyber Threat IntelligenceOperationalize cyber threat intelligence.
Security LeadershipBuild a proven security program.
THE THREAT On October 15th, 2025, F5 disclosed that the organization was impacted by a breach involving an unspecified state-sponsored threat actor. The threat actors were…
THE THREATOn October 4th, 2025 Oracle released a security advisory addressing a critical, zero-day vulnerability impacted its E-Business Suite (EBS), identified during their investigation…
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 2000+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
About Us Leadership CareersWe provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Search our site
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
We offer three flexible MDR pricing packages that can be customized to your unique needs.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why 2000+ organizations globally have chosen eSentire for their MDR Solution.
Within the first half of 2021, we have already seen ransomware attacks crippling many industry giants, resulting in massive operational disruption and costing millions in recovery efforts.
While threat actors have made it a habit to target organizations within the utilities, healthcare, and food & agriculture sectors, a new target has emerged within the past year: the insurance sector. Major insurance providers have reported being the targets of ransomware attacks and surprisingly, some have also admitted to paying the ransom.
Adversaries are fueled by the personally identifiable information (PII) that insurance companies hold for their clients. Since much of this data (e.g. medical records, financial statements, government-issued identification, etc.) is used for underwriting and claims preparation, it is highly sensitive, and insurers collect and store a lot of it. In the hands of a threat actor, this data can easily be used to commit medical, insurance, and/or identity fraud on unknowing victims. Therefore, insurers are at a heightened risk of experiencing financial and reputational loss as well as regulatory repercussions.
Additionally, despite the global adoption of digital transformation, the insurance industry is still very much reliant on legacy systems due to the cost associated with modernizing technology and digitizing client records. However, a move towards modernization can be a double edged sword; the digitization of insurance records and client data can expose insurance firms to third-party risk as well as expand the threat surface as organizations adopt hybrid infrastructures.
As a result of this treasure trove of highly-valuable client data, weak security defenses, and a lack of internal resources driven by a skills shortage in cybersecurity, it’s clear that cyber criminals have found themselves a new opportune target in insurance providers and brokerage firms. Additional risk factors that have contributed to the increasing ransomware attacks include human error and an evolving threat landscape.
In the past couple of years, a new organizational structure has emerged for cyber criminals. Gone are the days when organizations were dealing with a lone hacker. Today, we’re seeing the formation of highly-organized ‘cyber cartels’, wherein cyber criminals have come together to collaborate on leveraging specialized attack tactics to maximize ransom payouts.
One such attack tactic that has rapidly gained momentum is double extortion, through which threat actors first gain access into the corporate environment, exfiltrate all the data on to their own servers, and then deploy ransomware.
Ultimately, even if the target organization is able to restore their data without paying the ransom, threat actors can still cause financial loss & liability, reputational damage, and impact the business’s bottom line by threatening to make the stolen data public.
As a result, it’s increasingly difficult for the insurance industry to keep up with the sophistication of today’s ransomware attacks. In fact, nearly every major insurance firm that suffered a ransomware attack within the past year was also the victim of double extortion:
It seems that the message to the insurance industry is clear: your data is highly valuable and cyber criminals will use any means necessary to extort you.
As a response to the sharp rise of ransomware threats against the insurance sector, the National Association of Insurance Commissioners (NAIC) established the Cybersecurity Task Force in 2015 to address cybersecurity within insurance companies.
In order to remain compliant, firms must demonstrate they have followed the programmatic and operational requirements outlined by the NAIC. This should serve as a clear sign that insurance providers must evaluate their risk exposure on a continual basis.
The reality is that the threat landscape will continue to evolve. Understandably, insurance firms must begin to take threats more seriously and act with diligence to not only prevent incidents, but to take measures to detect and contain if and when they do occur.
Much of prevention is rooted in how the insurance sector manages cyber risk. Ask yourself:
When cyber criminals target your organization, you must be able to detect their presence and immediately contain them to limit their spread.
While prevention certainly plays a role in cyber resilience, it’s evident that insurance firms must take a comprehensive approach to protect clients’ data. Instead of solely relying on preventative measures, insurance firms should have the ability to respond to any threats before they disrupt business operations.
Cybersecurity investment may be a big undertaking for insurance providers and brokerage firms, but it’s an investment that is now a necessity.
To learn more about how Managed Detection & Response can help your organization detect and contain threats before they become business-disrupting events, book a meeting with an eSentire security specialist.
To learn how your organization can build cyber resilience and prevent business disruption with eSentire’s Next Level MDR, connect with an eSentire Security Specialist now.
GET STARTEDeSentire, Inc., the Authority in Managed Detection and Response (MDR), protects the critical data and applications of 2000+ organizations in 80+ countries, across 35 industries from known and unknown cyber threats by providing Exposure Management, Managed Detection and Response and Incident Response services designed to build an organization’s cyber resilience & prevent business disruption. Founded in 2001, eSentire protects the world’s most targeted organizations with 65% of its global base recognized as critical infrastructure, vital to economic health and stability. By combining open XDR platform technology, 24/7 threat hunting, and proven security operations leadership, eSentire's award-winning MDR services and team of experts help organizations anticipate, withstand and recover from cyberattacks. For more information, visit: www.esentire.com and follow @eSentire.