Applied IAM

Identity security for insurance

Insurers run on a vast outside network — independent agents, brokers, MGAs, TPAs, and adjusters — all reaching into policy, claims, and underwriting systems full of sensitive data. We govern who gets in from outside your walls, lock down claims and policyholder data, and help you prove it under the NAIC model law.

NAIC model lawNYDFS (23 NYCRR 500)Agents, brokers & MGAsTPAs & adjustersClaims & policyholder data
Distribution networkAppointments change weekly
  • Carrierpolicy, claims and underwriting systems
    • MGAwith its own sub-producers
      • Agency
        • ProducerAppointed
        • ProducerAppointment ended
          Access revoked the same day
          Agent portalPolicy adminCommission system
      • Sub-producerAppointed
    • Independent agentAppointed

The termination of an appointment has to revoke access the same day.

The extended enterprise

Governing people who do not work for you

A bank mostly secures the people on its payroll. An insurer can't.

Your business runs through a distribution network you don't employ — independent agents, brokers, and managing general agents — and your claims run through third-party administrators, independent and catastrophe adjusters, and repair and medical networks. All of them need real access to real data. Few of them are your employees.

Producer appointments, agency hierarchies, MGAs with their own sub-producers, TPAs and independent adjusters. Access has to follow an appointment that can change weekly, and the termination of an appointment has to revoke access the same day.

That data is sensitive: policyholder PII, and in many lines, medical and financial records. The hard part isn't your staff; it's governing everyone else.

  • Independent agents
  • Brokers & agencies
  • MGAs
  • TPAs
  • Independent & CAT adjusters
  • Reinsurers & vendors

Every one of them needs the right access — and a clean way out. We govern the whole network, not just your staff.

The estate

Hybrid estates make this harder

Insurers run legacy policy and claims systems alongside modern cloud tooling.

Unified identity across both is the practical difficulty — a producer exists in the portal, in the policy admin system and in the commission system, and those three rarely agree on whether they are still appointed.

What we secure

From quote to claim

Across the platforms that run the business and the channel that feeds it.

LayerWhat we secureExamples
Core insurance platformsPolicy administration, claims systems, underwriting & ratingGuidewire, Duck Creek, Majesco
Distribution & partnersAgent & broker portals, producer management, TPA & adjuster access—
Identity & infrastructureDirectories, cloud platforms, finance & ERPActive Directory, Microsoft Entra ID, AWS, Azure, GCP

Platform names are trademarks of their respective owners. Use does not imply partnership, sponsorship or endorsement.

Underwriting

Cyber insurers are now the auditor

Identity control has moved from a compliance checkbox to an underwriting condition.

Insurers occupy an unusual position: you are the buyer and the enforcer. Nearly half of cyber-insurance claims now trace back to compromised credentials or misused privileged access, and least-privilege access has become one of the core controls most carriers require before issuing or renewing coverage. The questionnaire your own underwriters send to policyholders is, increasingly, the questionnaire you have to answer about yourself.

In practice that means being asked, before a policy is issued or renewed, whether human and non-human accounts follow least privilege, whether privileged accounts use dedicated tooling rather than a password manager, and whether MFA covers remote and third-party access.

The rules

What NAIC and NYDFS require

  • The NAIC Insurance Data Security Model Law (#668)

    Requires a written information security program based on risk assessment, a designated employee accountable for it, and notification to the state insurance commissioner after a cybersecurity event. It has been adopted in over 20 states.

  • New York, 23 NYCRR 500

    New York is stricter. 23 NYCRR 500 requires a designated CISO, annual penetration testing, incident reporting within 72 hours, and an annual report from the CISO to the board or senior management.

Where a framework deadline is driving it, that runs alongside a compliance readiness assessment.

RequirementNAICModel Law #668Adopted in over 20 statesNew York23 NYCRR 500Stricter
The model law
Written information security programBased on risk assessmentNot named on this page for 23 NYCRR 500
New York is stricter
Accountable for the programA designated employeeA designated CISO
After a cybersecurity eventNotification to the state insurance commissionerIncident reporting within 72 hours
Penetration testingNot named on this page for the NAIC model lawAnnual
Reporting to the boardNot named on this page for the NAIC model lawAn annual report from the CISO to the board or senior management
Both expect
Access reviews
Third-party oversight
Logging

not named for that rule on this page

Who signs

The designated CISO, under both the NAIC model law and NYDFS.

In New York the CISO also reports annually to the board, which means the access control program has a named person with a board-level reporting line behind it.

The plan

How to govern the whole network

01

Govern external access like it's your own

We extend identity governance to your agents, brokers, MGAs, TPAs, and adjusters — sponsored, role-based, time-bound access with attestation and regular reviews — so an external producer gets exactly the access their appointment warrants and loses it the instant that appointment ends. No standing access for people who stopped representing you a year ago.

02

Lock down claims and policyholder data

We vault and monitor the privileged access behind your policy administration, claims, and underwriting systems and the databases that hold policyholder PII and medical records — least privilege and session control over the admin accounts and integrations that touch the most sensitive data you hold.

03

Keep it audit-ready for the NAIC model law

External relationships churn constantly, and that's exactly what regulators probe. We operate your identity program day to day — running the access reviews, third-party oversight, and logging the NAIC model law and NYDFS expect — and keep the evidence current.

The governance side of that is IGA implementation, the privileged side is PAM implementation, and either can be carried for you as managed IAM services.

Proof

Insurance work in practice

Insurance carrier, $600M+ revenue

Our engineers designed automated credential replication between the primary PAM environment and cloud key vaults, so privileged access survives an infrastructure outage without manual break-glass. 95% reduction in credential provisioning time during a disaster scenario, and 300+ privileged accounts onboarded in minutes rather than days.

Global property and casualty insurer, 20,000+ employees

Facing a SOX deadline, our engineers deployed a unified onboarding framework and integrated 470 databases across six complex types in six weeks, against a six-month baseline, with the certification pipeline streamlined and self-service onboarding in place afterwards.

The same engineers do the work each time, with certified CyberArk delivery behind the privileged side and IAM integration behind the database side.

The starting point

What is usually already there, and what is usually missing

Almost always in placeAlmost always missing
MFA at loginDedicated privileged access tooling — many still rely on a password manager, which stores credentials but does not control or record their use
A written information security program, because the law requires oneConsistent oversight of third-party and vendor access
Role-based access for claims handlers and underwritersSame-day revocation when a producer appointment ends
Free brief

The Privileged Access Blind Spot — Insurance

The 2025 campaign that moved straight through the U.S. insurance sector — and how to check your exposure.

The insurance privileged access brief covers what that campaign did and the checks to run against your own estate.

Carriers

Identity and access management for insurance carriers

Identity access management for insurance starts from an uncomfortable fact: most of the people in a carrier's systems don't work for the carrier. Captive and independent agents, brokers, wholesalers, TPAs, and adjusters all need access to quoting, policy admin, and claims platforms — and every one of them is an identity you're accountable for but don't employ.

Producer hierarchies make it harder. An agency onboards, appoints producers under it, producers move between agencies, appointments terminate — and access has to track every step, or terminated producers keep reaching policyholder data long after the relationship ends. After a catastrophe event, adjuster access surges overnight and has to be pulled back just as fast. Insurance identity management is governing that churn continuously, not annually.

Regulators have noticed. NYDFS Part 500 and the NAIC data security model law both come down to the same questions: who can reach nonpublic information, is that access limited and reviewed, is MFA enforced, and can you prove all of it — including for third parties. Insurance identity governance is how those questions get answered from a report instead of a scramble.

We build that governance: sponsored, time-bound access for external producers, role models that mirror your appointment hierarchy, automated termination when an appointment ends, privileged access controls around claims and policy admin systems, and audit evidence that stays current between exams.

FAQ

What carriers ask first

Yes — that's the core of it. We govern external producers and partners with sponsored, time-bound, role-based access, attestation, and instant offboarding when an appointment or contract ends, so outside parties are held to the same standard as your own staff.

Brokers get sponsored accounts tied to an active appointment, scoped to the products and books of business they actually place, with MFA enforced and every session attributable to a named person rather than a shared agency login. When the appointment lapses, access ends the same day — automatically, not when someone remembers. That closes the most common gap: producers who left an agency years ago still holding live portal credentials.

Yes. We model the hierarchy as it really is: an MGA sponsors its agencies, agencies sponsor their producers, and each level can only grant access downward within what it holds itself. Reviews roll up the same way, so when an auditor asks who can bind coverage or touch claims data, the answer traces cleanly from carrier to individual — even across thousands of external users.

We map access controls to what those rules hinge on — least privilege, MFA, access reviews, logging, and third-party oversight — and keep the evidence current, so demonstrating compliance is a report you run rather than a project you start.

No. A password manager stores credentials and controls who can retrieve them. Privileged access management controls what they can be used for, records the session, rotates the credential afterwards and expires the access. An auditor can tell the difference, and increasingly so can an underwriter.

See who can reach your claims and policyholder data.

A free audit is a 30-minute review of your privileged and external-producer access by a certified engineer, with the findings in writing. The Insurance blind spot brief covers the 2025 campaign that moved through the sector, and KeeperPAM is often the right fit for agent and broker populations.