Annex to the ActAnnex I - high-criticality sector
Competent CSIRTNational CERT
Sectoral authorityHANFA
The measures that carry most of the work in this sector
02Asset management
Policyholder and claims data are critical assets, often scattered across legacy systems.
04Digital identities
External intermediaries have system access, and revoking it when the relationship ends is rarely automated.
08Supply chain
Intermediaries, loss adjusters and cloud providers enter the same risk assessment.
10Cryptography
Health data in policies and claims requires protection in transit and at rest.
What we most often find
- Active intermediary accounts from relationships that ended years ago
- Legacy claims systems past vendor support, with no board decision on the risk
- Health data in test environments, unmasked
- A risk assessment that does not cover intermediaries
Check for yourself
Tri alata koja rade u pregledniku, bez registracije:
Entity categorisation check
Incident reporting deadline calculator
Readiness check against the 13 measures
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.