How can insurers and pension funds in Zambia manage ICT risk?
Insurers and pension funds manage ICT risk by protecting the policyholder and member data they hold, controlling changes to policy-administration and claims systems, planning how those systems recover and overseeing technology vendors. Pensions and insurance is a critical sector under Zambia's Cyber Security Act, 2025. Ontech ICTM keeps the registers, assessments and evidence for this work in one platform.
Insurers and pension funds hold long-lived personal and financial records and depend on a few core systems for policy administration, claims and contributions. The Cyber Security Act, 2025 lists pensions and insurance as a critical sector, and the Data Protection Act, 2021 governs the personal data behind every policy and member account.
Ontech ICTM gives IT, risk and data-protection teams one system for the controls around those core platforms: data-protection records, change approvals, continuity plans, vendor contracts and the access reviews that show who can reach sensitive data.
ICT challenges in insurance & pensions
Long-lived personal data
Policy and member records are kept for decades and copied into many systems, making them hard to account for.
Uncontrolled system changes
Changes to policy-administration and claims systems are agreed by email, with no risk assessment or rollback plan on record.
Claims continuity
Nobody has agreed how long claims processing can be down or how much data could be lost.
Outsourced administration
Administrators and technology vendors hold data and run systems, but their contracts and service levels are tracked loosely.
Access creep
Staff accumulate access to policyholder data as they change roles.
How insurance & pensions organisations use ICTM
Policyholder and member data registers
Processing activities are recorded with their purpose and lawful basis and exported to CSV, alongside consent records and cross-border transfer records that show what is stored in Zambia and what is not.
Impact assessments for sensitive data
Impact assessment records for high-risk processing, such as medical information collected for life and health cover, are kept next to the systems they concern.
Breach register
Breaches are recorded with their scope and the dates the Data Protection Commissioner and affected people were notified, giving a history you can show.
Change control for core systems
Changes to policy-administration, claims and contribution systems go through multi-stage approvals with a risk assessment and rollback plan.
Claims-system continuity
Business impact analyses record maximum tolerable downtime and recovery targets; versioned plans and exercises show how claims processing would be restored.
Administrator and vendor oversight
Technology vendors and outsourced administrators are recorded with contracts, service levels, dependencies and single-point-of-failure flags.
Access reviews
Directory data synchronised from Active Directory supports reviews of who can reach policyholder systems, and dormant accounts are flagged.
ICTM capabilities for insurance & pensions
IT Compliance Management
Map your controls to the frameworks you answer to, see where the gaps are, and keep Data Protection Act records in the same system as your IT estate.
IT Governance
Decide who may do what, write it down as policy, route decisions through the right approvers, and keep a record of every change.
Business Continuity Management
Work out which services matter most, how long you can be without them, and who does what when they fail — then keep the plans current.
Disaster Recovery & Backup Management
Run and schedule backups, see at a glance whether they are keeping up, and rehearse recovery against the targets your business has set.
IT Vendor Management
Know who supplies your technology, what you have agreed with them, and which services would stop if one of them failed.
Cybersecurity Management
Test your systems, watch your network and access, and keep every finding tracked to remediation in one platform.
IT Risk Management
Record IT risks once, score them consistently, assign mitigations to named owners, and see how incidents, compliance gaps and supplier dependencies add up.
Regulation that applies
Summaries based on the primary legislation and regulator publications. See the linked Zambia pages for detail and sources — this is general information, not legal advice.
Cyber Security Act No. 3 of 2025
Lists pensions and insurance as a critical sector (s.8). The Zambia Cyber Security Agency designates critical information infrastructure by Gazette notice (s.9); a controller of designated infrastructure must file a preliminary cyber incident report within twelve hours (s.17). The Act repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73).
Data Protection Act No. 3 of 2021
Requires registration of data controllers and processors (s.19), an impact assessment before high-risk processing, including large-scale processing of sensitive personal data (s.46), a data protection officer (s.48), notification of the Commissioner within twenty-four hours of a security breach (s.49) and storage in Zambia unless an exception applies (s.70).
What ICTM covers — and what it doesn't
ICTM does not connect to policy-administration, claims or contribution systems, and it does not include a Pensions and Insurance Authority framework; it manages the IT controls, records and plans around them. Check the Authority's current directives for any sector-specific ICT requirements.
Benefits
Accountable personal data
Processing activities, impact assessments and breaches are recorded against the Act's requirements.
Changes with an audit trail
Every change request carries a risk assessment, approvals and a rollback plan.
Agreed recovery targets
Claims and administration systems have documented recovery time and recovery point targets, tested in exercises.
Vendor oversight
Contracts, service levels and dependencies are held in one register.
Least-privilege access
Access reviews show who can reach policyholder data.
Rolling out ICTM
Scope modules and roles
Run ICTM as a hosted service or on servers you control, then set up role-based access so each team sees only the modules it needs.
Map systems and data
Record core systems in the asset register, link their dependencies and list the personal data each one processes.
Set up change control
Configure multi-stage approvals for changes to policy-administration, claims and contribution systems.
Plan for continuity
Run business impact analyses for claims and administration processes and record recovery plans and exercises.
Review access and vendors
Connect Active Directory for access reviews and record administrators and technology vendors with their contracts.
Frequently asked questions
Is insurance a critical sector under Zambia's Cyber Security Act, 2025?
Yes. Section 8 of the Cyber Security Act, 2025 lists pensions and insurance among the critical sectors. The Zambia Cyber Security Agency designates specific critical information or critical information infrastructure by Gazette notice (section 9), and designated controllers take on additional duties, including filing a preliminary incident report within twelve hours (section 17).
How does ICTM help with data protection impact assessments?
ICTM keeps records of impact assessments alongside a register of processing activities, consent and cross-border transfer records and a breach register. The Data Protection Act requires an impact assessment before high-risk processing, including large-scale processing of sensitive personal data (section 46). ICTM records the assessment and its outcome; the analysis itself is done by your team.
Can ICTM control changes to policy-administration systems?
Yes. ICTM's change management records each request with its risk assessment and rollback plan and routes it through multi-stage approvals, which can require any, all or a majority of approvers, trigger extra approval on conditions such as budget, and escalate if approvers do not respond. Every step is logged in the audit trail.
How should an insurer plan continuity for claims systems?
Start with a business impact analysis that sets the maximum tolerable downtime and recovery time and recovery point targets for claims processing, then document recovery plans and test them. ICTM records the analysis, versioned plans with approvals and review dates, and exercises that compare target and actual recovery times.
Does ICTM include Pensions and Insurance Authority requirements?
No. ICTM does not include a framework specific to the Pensions and Insurance Authority. Its data-protection records, ISO/IEC 27001 control set, change control and continuity planning cover common ICT controls; check the Authority's current directives for any sector-specific requirements and map them yourself.