Introduction
Insurance companies play a critical role in helping businesses manage cyber risks by underwriting cyber insurance policies and supporting policyholders during security incidents. However, insurers themselves have become attractive targets for cybercriminals because they possess vast amounts of sensitive customer information, financial data, claims records, underwriting files and confidential business information. The ransomware attack on CNA Financial Corporation in March 2021 serves as an important reminder that even organisations with mature risk management frameworks are vulnerable to sophisticated cyber threats. The incident demonstrates that cyber risk is no longer merely an information technology issue but an enterprise-wide risk requiring strong governance, operational resilience and board-level oversight.
About CNA Financial
CNA Financial Corporation is one of the largest commercial property and casualty insurance companies in the United States. It provides commercial insurance, professional liability, surety and risk management solutions to businesses across multiple industries.
Like most modern insurers, CNA relies heavily on digital platforms for underwriting, claims processing, customer servicing, financial reporting and internal operations. Consequently, uninterrupted availability and security of information systems are essential for its business continuity.
The Cyber Incident
On 21 March 2021, CNA detected a sophisticated ransomware attack that disrupted parts of its corporate network and affected several internal systems. Upon discovering the incident, the company immediately activated its incident response procedures, engaged leading third-party cybersecurity experts, informed law enforcement authorities, including the Federal Bureau of Investigation, and initiated forensic investigations.
Subsequent investigations established that the threat actor had gained unauthorised access to certain CNA systems between 5 March and 21 March 2021. During this period, a limited amount of information was copied before the ransomware was deployed. The company later stated that there was no indication that policyholder data had been specifically targeted, although some personal information relating to current and former employees, contractors, dependants and certain other individuals, including some policyholders, had been accessed.
Operational Impact
The ransomware attack disrupted several internal business operations. Corporate email services and portions of the company’s information technology infrastructure became unavailable, affecting normal workflows.
To prevent further spread of the malware, CNA proactively disconnected affected systems from its network. This immediate containment strategy inevitably resulted in temporary operational disruption but reduced the likelihood of wider system compromise.
The company adopted a phased restoration process, rebuilding systems individually after deploying enhanced endpoint detection tools, conducting malware scans, remediating indicators of compromise and validating that each system was secure before reconnecting it to the network. By May 2021, CNA announced that business operations had been fully restored.
Incident Response
One of the most notable aspects of the incident was the company’s structured response.
Immediately after detecting the attack, CNA:
- Activated its cyber incident response plan
- Isolated affected systems
- Engaged independent forensic specialists
- Notified law enforcement authorities
- Informed regulators where required
- Investigated the scope of compromised information
- Restored systems through a phased recovery programme
- Strengthened network monitoring and endpoint security.
The company subsequently implemented additional cybersecurity measures designed to improve the protection of its networks, systems and data.
Cyber Risk Management Lessons
Cyber Risk Must Be Treated as an Enterprise Risk
Traditionally, cybersecurity was viewed primarily as the responsibility of the information technology department. The CNA incident demonstrates that ransomware can simultaneously affect underwriting operations, claims handling, customer service, finance, legal compliance, reputation and business continuity. Cyber risk should therefore be incorporated into the insurer’s Enterprise Risk Management framework, with regular reporting to senior management and the Board of Directors.
Business Continuity Planning Is Critical
No organisation can guarantee complete immunity from cyberattacks. Consequently, resilience becomes more important than prevention alone.
Business Continuity Plans should clearly define responsibilities, communication channels, backup arrangements, recovery priorities and alternative operating procedures. Regular simulation exercises help ensure that critical business functions can continue even during prolonged system outages.
Rapid Detection and Containment Reduce Damage
One of the important strengths demonstrated during the incident was the rapid isolation of affected systems. Early detection limits the spread of ransomware, reduces operational disruption and assists forensic investigators in identifying the source and extent of the attack. Continuous security monitoring, endpoint detection and automated threat intelligence therefore play a vital role in cyber defence.
Third-Party Expertise Enhances Response
CNA immediately engaged specialist forensic investigators and cybersecurity professionals to assist with incident management. External experts often possess specialised technical capabilities that complement internal teams during major cyber incidents. Large insurers should maintain pre-approved incident response partnerships with forensic specialists, legal advisors, cyber consultants and public relations professionals before an incident occurs.
Data Protection Extends Beyond Prevention
Although CNA indicated that policyholder data was not specifically targeted, the investigation identified unauthorised access to certain personal information. This highlights the importance of comprehensive data governance, encryption, access controls and continuous monitoring of sensitive information. Strong identity management, multi-factor authentication, privileged access management and data classification significantly reduce exposure to cyber threats.
Transparent Communication Builds Confidence
The company provided periodic public updates regarding investigation progress, restoration efforts and data review. It also notified affected individuals where legally required and cooperated with regulatory authorities. Timely communication helps preserve stakeholder confidence while reducing uncertainty during major cyber events.
Risk Management Recommendations for Insurers
The CNA incident offers several practical lessons for insurance companies:
- Integrate cyber risk into Enterprise Risk Management rather than treating it solely as an information technology issue.
- Conduct regular cyber risk assessments covering underwriting, claims, finance and operational systems.
- Strengthen identity and access management through multi-factor authentication and least-privilege principles.
- Continuously monitor networks using advanced endpoint detection and security analytics.
- Maintain secure offline backups and periodically test restoration procedures.
- Establish formal cyber incident response plans supported by regular simulation exercises.
- Strengthen third-party risk management for vendors, cloud service providers and technology partners.
- Provide regular cybersecurity awareness training to employees.
- Ensure periodic reporting of cyber risks to the Board and senior management.
- Continuously review cyber insurance arrangements to ensure adequate protection against evolving threats.
Conclusion
The CNA Financial ransomware attack demonstrates that no organisation, including a leading insurance company, is immune from sophisticated cyber threats. While digital transformation has improved operational efficiency and customer service, it has also expanded the attack surface available to cybercriminals. The incident reinforces that effective cyber risk management extends well beyond technology. It requires robust governance, enterprise-wide risk integration, operational resilience, employee awareness, incident preparedness and continuous monitoring. The company’s ability to contain the attack, restore operations systematically and strengthen its security environment illustrates the importance of having a well-structured incident response framework supported by senior management and external expertise.
For insurers, the most valuable lesson is that cyber resilience should not be measured solely by the ability to prevent attacks but by the capability to detect, respond to and recover from them with minimal disruption. As cyber threats continue to evolve, organisations that embed cybersecurity within their enterprise risk management framework will be better positioned to protect policyholders, maintain stakeholder confidence and ensure long-term business continuity.

