Applied IAM

The Privileged Access Blind Spot: Insurance

Insurers govern more people who do not work for them than people who do: agents, brokers, MGAs and TPAs, each with access into policy and claims systems. The incidents below show how access into those systems gets used.

Two pagesPublic reporting onlyFreeWritten by certified engineers
The incidents

Three breaches, one pattern

Aflac

Aflac said attackers used social engineering to gain access to its network, as part of a wider cybercrime campaign against the insurance industry. (Source: Aflac statement)

Allianz Life

Data reached through a third-party SaaS platform holding customer records, on access gained through social engineering. (Source: TechCrunch)

Over-permissioned roles across the sector

The common thread in both: social engineering opened the door, and how far that access reached decided how many customer records went with it.

The read-across

What the pattern means for you

The workforce you can offboard is the smaller half of your access. The other half is contractual, distributed and reviewed by nobody in particular. That is where the campaign that moved through the sector found its footing.

Self-check

The 60-second self-check

  • How many active agent and broker identities do you have, and how many of those relationships ended in the last year?
  • Who approves a new MGA user's access, and who removes it?
  • Is MFA enforced on every agent portal login, or only on employee ones?
  • Could your CISO evidence the access controls 23 NYCRR 500 requires, to the board, this quarter?
  • Is privileged access stored in a password manager, or controlled by one?

If any answer is "no" or "I would have to ask", that is the blind spot.

The full brief

Get the full brief

The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.

Next

Where to go next

The sector page: identity security for insurance. The service that closes the gap: IGA implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.

Get the Insurance brief

Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.