SUSEP Unveils Cybersecurity Manual for Insurers Amid $944B Global Gap

SUSEP Unveils Cybersecurity Manual for Insurers Amid $944B Global Gap

SUSEP's cybersecurity manual for Brazil's insurers rests on brand-new mutualist governance rules and a $944 billion global cyber-risk protection gap.

SUSEP’s new cybersecurity manual for Brazilian insurers did not appear out of nowhere: it is the output of a working group created in August 2024, which held ten meetings across two thematic subgroups that same autumn — but it took regulators nearly two years to weave those findings into governance rules meant, until recently, only for mutualist and cooperative insurers. The manual now reaches across the market, from national reinsurers to capitalization companies, and it arrives with a recurring reporting duty attached.

From Working Group to Rulebook: How SUSEP Built the Manual

SUSEP’s manual traces back to a dedicated Insurance & Cybersecurity working group, formally created by Administrative Order (Portaria) No. 8,323 on August 26, 2024, and later extended by a second order, Portaria No. 8,348. The group did not linger: it held ten meetings between September and October 2024, organized across two thematic subgroups, comparing market practice against the direction international regulators were already taking on operational cyber risk.

The rationale SUSEP cites for moving beyond a single circular is largely a numbers argument. GFIA, the global federation of insurance associations, puts the worldwide cyber-risk protection gap at close to $944 billion a year, a figure the regulator’s own working-group report leans on to justify treating cyber exposure as a standing supervisory concern rather than a one-time compliance box to check.

Mutualist Reform Becomes the Cybersecurity Vehicle

The manual’s legal foundation is where the convergence story gets specific. SUSEP states that the document is grounded in CNSP Resolutions 416/2021, 491/2026 and 492/2026, together with SUSEP Circulars 638/2021 and 700/2024. Two of those five instruments did not exist a year ago, and neither was written with cybersecurity as its headline purpose.

CNSP Resolution 491 was adopted at an extraordinary session on May 4, 2026, establishing general rules for mutual patrimonial protection operations — the first dedicated regime for Brazil’s mutualist property-protection structures. Its companion measure goes further on governance: CNSP Resolution 492/2026 requires insurance cooperative boards to ensure the adequacy and effectiveness of their risk-management structure and internal controls, under Article 21, section X. Cybersecurity, in other words, entered the mutualist and cooperative segment through board-level risk governance — the same logic underpinning the EU’s incident-reporting framework for insurers.

The Fraud and Breach Numbers Behind the Rulebook

SUSEP’s own case leans on data rather than doctrine. Brazil’s average cost of a data breach reached $1.36 million in 2024, up from $1.22 million in 2023, according to IBM figures cited in the working group’s report. Fraud trends point the same direction.

Brazil recorded 3.7 million digital-commerce fraud attempts in 2023, totaling roughly $3.5 billion, per Clearsale data referenced in the same report, while claims-specific figures show fraud migrating deeper into the insurance value chain. Confirmed fraudulent insurance-claims notices reached R$1 billion combining the second half of 2023 and the first half of 2024, according to CNSEG, the national insurers’ confederation — the kind of trend line that turns a cybersecurity manual into a claims-fraud conversation as much as a data-protection one.

What Supervised Entities Must Now Do

Scope is broad by design. The manual applies to insurers, open pension entities, capitalization companies, local reinsurers, insurance cooperatives, and mutual-protection administrators, meaning the same baseline expectations now run across segments that previously sat under separate circulars.

The operational core of the new document is reporting. Supervised entities must prepare an annual report on the prevention and treatment of incidents and vulnerabilities, a recurring disclosure rather than a one-off certification.

None of this replaces existing rules. SUSEP Circular No. 638/2021 already set minimum cybersecurity requirements for supervised entities, five years before the new manual, and the manual folds that baseline into the wider architecture of Brazil’s National Cybersecurity Policy (PNCiber), instituted by Decree No. 11,856 in 2023. The manual lands alongside other structural changes reshaping how Brazilian carriers and brokers operate, including sweeping changes carriers and brokers must absorb under the country’s new insurance law, and follows a market separately building new risk-transfer instruments such as a record-setting reinsurance-linked structure priced for the local market this year.

Mini-FAQ

What prompted SUSEP to publish this cybersecurity manual?
SUSEP built the manual on the findings of an Insurance & Cybersecurity working group created in August 2024 under a formal SUSEP administrative order, which met ten times over two months in 2024 and pointed to a global cyber-protection gap GFIA estimates at roughly $944 billion a year.
Which types of insurance entities does the manual cover?
It applies to insurers, open pension entities, capitalization companies, local reinsurers, insurance cooperatives, and mutual-protection administrators supervised by SUSEP.
What new obligation does the manual create for insurers?
Supervised entities must produce an annual report on the prevention and treatment of cybersecurity incidents and vulnerabilities, layered on top of existing minimum requirements such as SUSEP Circular No. 638/2021.

Sources: SUSEP, Insurance & Cybersecurity working group, SUSEP working group final report, CNSP Resolution 491/2026, official text, CNSP Resolution 492/2026, LegisWeb reproduction, Legismap coverage of the manual.

P

Patrice Dumont

InsuraBeat correspondent

Senior reporter at InsuraBeat leading coverage of insurance regulation, executive moves, and the insurtech landscape across EMEA and APAC. Fifteen years straddling regulation and trade journalism: began in the legal team of a French insurance industry body, advising members on Solvency II implementation and product approvals, then moved to specialised insurance media to cover EIOPA, NAIC and IAIS work and prudential reform. Graduate of the Pan-Asian School of Governance and Regulatory Affairs (Singapore), with an LL.M. in Insurance Prudential Law and Cross-Border Compliance from the Nihon-Siam Institute of Legal Studies (Bangkok). Writes from Brussels, on European afternoon markets.

All articles by Patrice Dumont →

Daily Beat newsletter

Never miss a beat in global insurance.

Get the day’s top deals, executive moves and regulatory shifts in your inbox every morning.

Free. No spam. Unsubscribe anytime.