Solutions · Insurance

Which identities touched policyholder data last night?

The data behind your float is the target: policyholder PII, claims, and PHI, held across every carrier you own. Attackers rarely break in. They log in, with valid credentials, from a broker portal, a claims vendor, a service account.

Book a Discovery WorkshopGet the datasheet
The ledger a carrier never balances

You reconcile premiums, reserves, and claims to the cent.
Access is never reconciled.

Entitlement is asserted in your role model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree, across every operating company.

PersonaEntitled, per RBACObserved, per CINQUEVariance
Broker / agent portalQuote and bind, own bookReached other agents' booksBOUNDARY CROSSED
Claims service accountRead claims, batch windowNew scopes, off-windowSCOPE DRIFT
Third-party TPA identityRead assigned claimsRead and bulk-export PIINEW EXPORT PATH
Underwriting AI agentRecommend pricingRecommend and approveFOUR-EYES BREAK
Reinsurance data feedCeded-loss exchange, continuousCeded-loss exchange, continuousRECONCILED
Illustrative. Each variance sits below the triage threshold of the console that owns it. It exists only once all five control points are read together.

Detection tells you what happened. Context tells you whether it was supposed to happen.

Where carriers point it first

Four places carriers point it first.

Brokers, agents, and TPAs

What contracted identities actually touched across the book, on portals and well beyond them.

Claims and the data layer

Where PII, PHI, and claims data move, and which identity moved it, on the systems that hold your float.

Non-human identities

Service accounts, Shadow AI, and the agents entering underwriting and claims workflows, each baselined as a persona of its own.

Mergers and post-close

Standing privilege, orphaned admins, and duplicate identity stores inherited at close, across acquired carriers.

Evidence for the people who ask

NYDFS and NAIC ask for a living inventory and an annual attestation.
Sign it knowing how access is actually used.

The expectation
Who is asking
What CINQUE gives you
Universal MFA and a living asset inventory
NYDFS Part 500 · NAIC #668
Evidenced from observed behavior, not from the diagram.
Your annual certification
Your board · your regulator
Sign the attestation knowing how access is actually used, human, non-human, and AI alike.
The controls you require of policyholders
You underwrite cyber
Shown continuously across every operating company you own.

NYDFS 23 NYCRR Part 500 and the NAIC Insurance Data Security Model Law require a written security program, access controls, MFA, an asset inventory, and third-party oversight, assessed and certified annually.

Datasheet

CINQUE for Insurance security leaders

Which identities touched policyholder data last night? The ledger a carrier never balances: access, across brokers, TPAs, claims vendors, and every operating company you own.

What it covers
  • Brokers, agents, and TPAs: what contracted identities actually touched across the book
  • Claims and the data layer: where PII, PHI, and claims data move, and which identity moved it
  • Underwriting and claims agents baselined as personas of their own
  • Mergers and post-close: standing privilege, orphaned admins, duplicate identity stores

Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.

The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your reconciliation.