Zero Trust, Continuous Monitoring, and AI-Driven Threat Detection: A CTO's Guide to Cybersecurity in P&C Insurance

Zero Trust, Continuous Monitoring, and AI-Driven Threat Detection: A CTO's Guide to Cybersecurity in P&C Insurance

Craig Hangartner

NavaJeevan Rajaiah

Insurance carriers sit on some of the most sensitive data in any industry. Claims files carry medical records, financial details, and personally identifiable information. Underwriting files carry property data, driving histories, and credit signals. Distribution systems carry broker and agent credentials tied directly into policy administration platforms.

For a CTO at a P&C carrier or MGA, the cybersecurity question is no longer whether to invest in stronger controls. It is how to modernize security architecture without slowing down the core systems work already on the roadmap: Guidewire migrations, data lake builds, and AI adoption across claims and underwriting.

This article covers what a modern security posture looks like for P&C insurance in 2026, and where the real gaps tend to show up.

Why Legacy Security Models Fall Short in Insurance

Most P&C carriers built their security stack around a perimeter model: firewalls at the edge, trust inside the network. That model made sense when core systems like AS/400 and mainframe policy admin platforms lived in a single data center with a small number of access points.

That assumption breaks down fast in a modern insurance environment. Claims data moves between Guidewire ClaimCenter, third-party adjusters, SIU teams, and reinsurance partners. Underwriting data flows in from MGAs, wholesalers, and pricing engines. Distribution data touches broker portals, agency management systems, and quoting tools. Every one of those integration points is a potential entry point, and the perimeter model was never built to secure data in motion across that many systems.

What Zero Trust Actually Means for a Carrier

Zero Trust is not a single product. It is an operating principle: never trust, always verify, regardless of whether a request originates inside or outside the network.

For a P&C carrier, that translates into a few concrete requirements:

Identity as the new perimeter. Every user, service account, and system integration authenticates and re-authenticates based on identity and context, not network location. This matters especially where claims adjusters, underwriters, and third-party vendors all need different levels of access to the same policy or claim record.

Least-privilege access by default. A claims adjuster working a auto liability file should not have standing access to underwriting credit data. Access should be scoped to the specific task and expire when the task is done.

Micro-segmentation across core systems. Guidewire PolicyCenter, ClaimCenter, BillingCenter, and any legacy AS/400 or mainframe systems still in production should be segmented so that a compromise in one system cannot move laterally into another.

Encryption in transit and at rest. This is table stakes, but it is worth stating plainly given how much legacy insurance data still lives in flat files or older database formats without modern encryption applied consistently.

Continuous Monitoring: Moving Past Point-in-Time Audits

Annual security audits and periodic penetration tests were designed for a slower threat landscape. Carriers now need visibility that runs continuously:

  • Real-time logging across policy, claims, billing, and underwriting systems

  • Behavioral baselines for normal user and system activity, so deviations get flagged fast

  • Automatic alerting when data access patterns fall outside expected norms, for example a service account suddenly pulling volumes of PII outside its normal claims processing window

Continuous monitoring is also what makes AI-driven threat detection possible. Pattern recognition across claims and policy data is only useful if the underlying monitoring infrastructure is feeding it consistent, high-quality signal in real time.

Where AI Fits Into Threat Detection, and Where It Doesn't

AI models can be genuinely useful for surfacing anomalies across large volumes of access logs and transaction data. This is a pattern-matching problem at scale, and that is exactly what these models are good at.

What matters for a CTO evaluating any AI-driven security tool is where the human sits in the loop. A model flagging unusual data access is valuable. A model automatically revoking access, quarantining systems, or making containment decisions without a human validating the call is a different risk profile entirely, and one that most carriers are not ready to accept given regulatory exposure under NAIC and state DOI frameworks.

The right posture: AI surfaces the signal, a security analyst or engineer makes the call.

Data Privacy: The Piece That Gets Harder With Every Integration

Every new integration point, whether it is a new MGA feed, a broker portal, or a data lake build, is another place PII and PHI can leak, get exposed in logs, or end up in an environment that was never scoped for that level of sensitivity.

For carriers actively working on legacy modernization or building out insurance data lakes, this is where privacy and security work overlaps directly with data engineering work. Anonymizing PII and PHI before it moves into a shared environment, a testing environment, or a downstream analytics tool is not a one-time project. It needs to happen every time data crosses a system boundary.

Where InsOps Helps

InsOps' insurance-trained AI model, LiLa, is built to run inside the carrier's own environment. Sensitive claims, underwriting, and policy data never has to leave controlled infrastructure to be processed, mapped, or anonymized.

A few ways this shows up in practice:

PII and PHI protection built into data movement. When carriers are migrating legacy claims data, for example moving 40+ years of claims history from an AS/400 system into Guidewire ClaimCenter Cloud, LiLa's Data Privacy capability identifies and anonymizes sensitive fields as part of the migration process itself, rather than as a separate downstream step.

Human-in-the-loop validation, always. LiLa assists with field mapping, data transformation, and anomaly flagging. It does not make autonomous decisions about access, containment, or data handling. Every mapping and transformation InsOps produces goes through human validation before it is applied.

Domain-aware data handling. Generic AI models don't understand the difference between a claim reserve field and a policy premium field, or which fields carry regulated PHI under HIPAA versus general PII. LiLa is trained specifically on insurance data structures and regulatory frameworks including NAIC and HIPAA, so sensitive fields get identified correctly rather than missed or over-flagged.

Real-time data flows with the same privacy discipline. For carriers connecting core systems like PolicyCenter, ClaimCenter, BillingCenter, UnderwritingCenter, and PricingCenter through InsOps' Integration Gateway, the same privacy-aware mapping applies to data moving in real time, not just during one-time migrations.

InsOps is building toward expanded compliance capabilities, including a DOI Compliance layer currently in development, to help carriers keep pace with state-level regulatory requirements as they modernize. If your team is evaluating how AI fits into your security and privacy roadmap, get in touch to talk through where it applies to your environment.

FAQ

What is Zero Trust security in the context of insurance?

Zero Trust is a security model where no user, device, or system is trusted by default, even if it is already inside the network. Every access request is verified based on identity and context. For carriers, this means claims adjusters, underwriters, and third-party vendors each get access scoped to exactly what their role requires, nothing more.

Why does continuous monitoring matter more than periodic audits?

Point-in-time audits only catch what was visible at the moment of the audit. Continuous monitoring tracks access patterns and data movement in real time, which is what allows anomalies, like unusual data pulls or access outside normal patterns, to get caught as they happen instead of months later.

Can AI make security decisions on its own?

AI models are effective at surfacing anomalies and patterns across large volumes of data. Making containment or access decisions autonomously is a different matter, and most carriers should keep a human validating those calls given the regulatory exposure involved in getting it wrong.

How does InsOps handle PII and PHI during legacy data migration?

LiLa's Data Privacy capability anonymizes sensitive fields as part of the migration workflow itself, identifying regulated data based on insurance-specific field semantics rather than generic pattern matching. This happens with human review built into the process.

Does InsOps' AI model process data outside our environment?

No. LiLa runs inside the carrier's own environment, so PII and PHI never has to leave controlled infrastructure to be mapped, transformed, or anonymized.

What regulatory frameworks does InsOps account for?

LiLa is trained on insurance-specific regulatory frameworks including NAIC requirements and HIPAA. A DOI Compliance capability is currently in development to address state-level regulatory requirements as they evolve.

Craig Hangartner

NavaJeevan Rajaiah