M ManySignal

Insurance

Detect insider fraud and policyholder data theft before they reach the regulator

Claims adjuster fraud, MGA credential misuse, and bulk policyholder PII exfiltration are the top threats for P&C, life, and health insurers. ManySignal monitors policy administration platforms, flags insider access anomalies, and tracks multi-state breach notification deadlines — all in one platform.

$308B

Annual global insurance fraud losses (Coalition Against Insurance Fraud)

72 hrs

NAIC Model Law cybersecurity event notification window

$4.2M

Average cost of an insurance sector data breach (IBM, 2023)

50 states

Breach notification laws to track for a US national insurer

How ManySignal protects insurance operations

Claims fraud detection and insider monitoring

Insurance fraud by insiders — claims adjusters inflating settlements, underwriters sharing policyholder data with competitors, and brokers accessing expired policies for identity fraud — is the highest-value insider risk in the sector. ManySignal baselines each employee's claims access patterns and flags bulk lookups, out-of-territory access, and activity on accounts the employee has no assigned relationship with.

  • Claims adjuster access baselining per territory and product line
  • Bulk policyholder record access anomaly detection
  • Access to competitor-sensitive pricing models flagged

Claims fraud detection and insider monitoring

Policyholder PII protection and state breach law compliance

Insurers hold sensitive PII: health conditions, driving records, criminal histories, financial statements. US state breach notification laws (California, New York's SHIELD Act, Virginia CDPA) and the NAIC Insurance Data Security Model Law require timely notification and demonstrated monitoring. ManySignal's incident management tracks notification deadlines per affected state.

  • Multi-state breach notification timeline tracking per incident
  • NAIC Insurance Data Security Model Law audit controls
  • EU Solvency II data governance monitoring for EU insurers

Policyholder PII protection and state breach law compliance

Third-party and managing general agent (MGA) monitoring

Insurers distribute through MGAs, brokers, and TPAs who have delegated access to policy systems. ManySignal monitors third-party access to core policy administration platforms — Duck Creek, Guidewire, Majesco — and flags access outside agreed business hours, bulk data pulls, and access to line-of-business products the MGA doesn't manage.

  • MGA and broker access profile baselining per system
  • Off-hours access to policy administration systems flagged
  • Data egress monitoring from Guidewire and Duck Creek APIs

Third-party and managing general agent (MGA) monitoring

Regulatory frameworks supported

NAIC Insurance Data Security Model LawNY DFS Cybersecurity Regulation (23 NYCRR 500)Solvency II (EU)FCA SYSC 8 (UK)APRA CPS 234GLBA Safeguards RuleState Breach Notification LawsLloyd's Market Minimum Standards

Insurance security — common questions

How does ManySignal address the NAIC Insurance Data Security Model Law?

ManySignal maps to the NAIC Model Law's Section 4 requirements: information security program, risk assessment, and third-party service provider oversight. For Section 5 (investigation of cybersecurity events), ManySignal provides automated incident detection, evidence collection, and the notification timeline tracking required for state insurance commissioner reporting within 72 hours of a cybersecurity event.

Can ManySignal monitor our Guidewire or Duck Creek policy administration platform?

Yes. ManySignal ingests Guidewire ClaimCenter and PolicyCenter audit logs via Syslog and the Guidewire Cloud API. For Duck Creek, it ingests the platform's activity audit trail. Both integrations enable policyholder access baselining, bulk data access detection, and cross-policy-type access anomalies that indicate potential fraud or credential compromise.

Does ManySignal support monitoring for cyber insurance underwriting activities?

Yes. Many insurers use ManySignal's evidence export capability to support their own cyber insurance product — producing security posture evidence for renewals, demonstrating continuous monitoring to underwriters, and providing post-incident forensic reports for claims submissions. ManySignal can also integrate with external cyber risk rating platforms (Security Scorecard, BitSight) to correlate external posture with internal detection data.

How does ManySignal handle monitoring for Lloyd's syndicates and the London Market?

ManySignal's EU and UK deployments support Lloyd's syndicates with data residency in the UK and compliance with the Lloyd's Cyber Security Minimum Standards. The platform monitors Lloyd's market platforms (ACORD messaging systems, Crystal, IMR) and provides evidence for Lloyd's Performance Management Directorate requirements.

What is ManySignal's support for Solvency II data governance requirements for EU insurers?

Under Solvency II's Pillar 2 requirements (ORSA and governance), EU insurers must demonstrate control over their data governance and outsourcing arrangements. ManySignal provides monitoring evidence for IT outsourcing risk, third-party data access controls, and incident management — all of which map to EIOPA Guidelines on System of Governance requirements.

Schedule an insurance-specific demo

See claims-adjuster access baselining, MGA third-party monitoring, and NAIC Model Law evidence export — in one focused session for your security and compliance teams.