Ontech ICTM by industry

ICT Management for Insurers & Pensions in Zambia

Protect policyholder and member data, control changes to core systems and keep claims and administration platforms recoverable.

How can insurers and pension funds in Zambia manage ICT risk?

Insurers and pension funds manage ICT risk by protecting the policyholder and member data they hold, controlling changes to policy-administration and claims systems, planning how those systems recover and overseeing technology vendors. Pensions and insurance is a critical sector under Zambia's Cyber Security Act, 2025. Ontech ICTM keeps the registers, assessments and evidence for this work in one platform.

Insurers and pension funds hold long-lived personal and financial records and depend on a few core systems for policy administration, claims and contributions. The Cyber Security Act, 2025 lists pensions and insurance as a critical sector, and the Data Protection Act, 2021 governs the personal data behind every policy and member account.

Ontech ICTM gives IT, risk and data-protection teams one system for the controls around those core platforms: data-protection records, change approvals, continuity plans, vendor contracts and the access reviews that show who can reach sensitive data.

ICT challenges in insurance & pensions

Long-lived personal data

Policy and member records are kept for decades and copied into many systems, making them hard to account for.

Uncontrolled system changes

Changes to policy-administration and claims systems are agreed by email, with no risk assessment or rollback plan on record.

Claims continuity

Nobody has agreed how long claims processing can be down or how much data could be lost.

Outsourced administration

Administrators and technology vendors hold data and run systems, but their contracts and service levels are tracked loosely.

Access creep

Staff accumulate access to policyholder data as they change roles.

How insurance & pensions organisations use ICTM

Policyholder and member data registers

Processing activities are recorded with their purpose and lawful basis and exported to CSV, alongside consent records and cross-border transfer records that show what is stored in Zambia and what is not.

Impact assessments for sensitive data

Impact assessment records for high-risk processing, such as medical information collected for life and health cover, are kept next to the systems they concern.

Breach register

Breaches are recorded with their scope and the dates the Data Protection Commissioner and affected people were notified, giving a history you can show.

Change control for core systems

Changes to policy-administration, claims and contribution systems go through multi-stage approvals with a risk assessment and rollback plan.

Claims-system continuity

Business impact analyses record maximum tolerable downtime and recovery targets; versioned plans and exercises show how claims processing would be restored.

Administrator and vendor oversight

Technology vendors and outsourced administrators are recorded with contracts, service levels, dependencies and single-point-of-failure flags.

Access reviews

Directory data synchronised from Active Directory supports reviews of who can reach policyholder systems, and dormant accounts are flagged.

Regulation that applies

Summaries based on the primary legislation and regulator publications. See the linked Zambia pages for detail and sources — this is general information, not legal advice.

Cyber Security Act No. 3 of 2025

Lists pensions and insurance as a critical sector (s.8). The Zambia Cyber Security Agency designates critical information infrastructure by Gazette notice (s.9); a controller of designated infrastructure must file a preliminary cyber incident report within twelve hours (s.17). The Act repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73).

Data Protection Act No. 3 of 2021

Requires registration of data controllers and processors (s.19), an impact assessment before high-risk processing, including large-scale processing of sensitive personal data (s.46), a data protection officer (s.48), notification of the Commissioner within twenty-four hours of a security breach (s.49) and storage in Zambia unless an exception applies (s.70).

What ICTM covers — and what it doesn't

ICTM does not connect to policy-administration, claims or contribution systems, and it does not include a Pensions and Insurance Authority framework; it manages the IT controls, records and plans around them. Check the Authority's current directives for any sector-specific ICT requirements.

Benefits

Accountable personal data

Processing activities, impact assessments and breaches are recorded against the Act's requirements.

Changes with an audit trail

Every change request carries a risk assessment, approvals and a rollback plan.

Agreed recovery targets

Claims and administration systems have documented recovery time and recovery point targets, tested in exercises.

Vendor oversight

Contracts, service levels and dependencies are held in one register.

Least-privilege access

Access reviews show who can reach policyholder data.

Rolling out ICTM

  1. Scope modules and roles

    Run ICTM as a hosted service or on servers you control, then set up role-based access so each team sees only the modules it needs.

  2. Map systems and data

    Record core systems in the asset register, link their dependencies and list the personal data each one processes.

  3. Set up change control

    Configure multi-stage approvals for changes to policy-administration, claims and contribution systems.

  4. Plan for continuity

    Run business impact analyses for claims and administration processes and record recovery plans and exercises.

  5. Review access and vendors

    Connect Active Directory for access reviews and record administrators and technology vendors with their contracts.

Frequently asked questions

Is insurance a critical sector under Zambia's Cyber Security Act, 2025?

Yes. Section 8 of the Cyber Security Act, 2025 lists pensions and insurance among the critical sectors. The Zambia Cyber Security Agency designates specific critical information or critical information infrastructure by Gazette notice (section 9), and designated controllers take on additional duties, including filing a preliminary incident report within twelve hours (section 17).

How does ICTM help with data protection impact assessments?

ICTM keeps records of impact assessments alongside a register of processing activities, consent and cross-border transfer records and a breach register. The Data Protection Act requires an impact assessment before high-risk processing, including large-scale processing of sensitive personal data (section 46). ICTM records the assessment and its outcome; the analysis itself is done by your team.

Can ICTM control changes to policy-administration systems?

Yes. ICTM's change management records each request with its risk assessment and rollback plan and routes it through multi-stage approvals, which can require any, all or a majority of approvers, trigger extra approval on conditions such as budget, and escalate if approvers do not respond. Every step is logged in the audit trail.

How should an insurer plan continuity for claims systems?

Start with a business impact analysis that sets the maximum tolerable downtime and recovery time and recovery point targets for claims processing, then document recovery plans and test them. ICTM records the analysis, versioned plans with approvals and review dates, and exercises that compare target and actual recovery times.

Does ICTM include Pensions and Insurance Authority requirements?

No. ICTM does not include a framework specific to the Pensions and Insurance Authority. Its data-protection records, ISO/IEC 27001 control set, change control and continuity planning cover common ICT controls; check the Authority's current directives for any sector-specific requirements and map them yourself.

See how insurance & pensions teams use Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.