A claims adjuster is trying to pull files from home. A broker needs access to a quote portal. A third-party administrator is waiting on policy data. The VPN stays up, but the blast radius stays wide, and one stolen credential can still open the door to systems that were never meant to be broadly reachable.
Zero Trust for insurance companies means verifying every user, device, and application continuously while limiting access to only what is needed. For insurers, the real value is reducing ransomware and cyber risk without breaking claims, underwriting, broker, or TPA workflows. The best approach is a phased roadmap with measurable ROI, legacy integration, and user-friction controls.
Decide where zero trust actually beats VPNs
For insurance companies, Zero Trust should replace VPN access only where identity, device posture, and app-level control can be checked before each session. Everywhere else, a hybrid model is safer in the short term, especially when claims, underwriting, or policy admin still depend on legacy paths.
The wrong comparison is Zero Trust versus VPN as if one must win everywhere. The real decision is which users, apps, and vendors can move now, and which ones need staged controls first.
The most common failure is trying to retire VPNs in one move and blocking core systems in the process. The real problem is not the network; it is identity, device, and workflow readiness.
The first cut: users, apps, vendors
Start with remote staff, third-party admins, and cloud apps that already support conditional access and MFA. Those paths usually give the fastest risk reduction because they have clear identity signals and fewer hidden dependencies.
A practical first cut is groups with high exposure and low legacy dependency, often between 20% and 40% of users in the first phase. That range is enough to prove value without forcing a broad cutover before controls are stable.
The legacy app trap
Legacy claims and underwriting platforms often fail when teams assume app proxying alone will solve the problem. What many guides omit is that old workflows usually need segmentation, session controls, and exception handling before they can move cleanly.
A mainframe-linked claims tool can look ready for modern access until service accounts and shared admin paths are mapped. Once those paths are exposed, the insurer has to keep a hybrid access layer in place while isolating privileged sessions.
What matters most at this stage: if you cannot name the user class, device state, and app dependency for each flow, you are not ready to remove VPN access for that flow.
A phased rollout works best when it is tied to the way insurance actually operates. Many carriers start by mapping access by business unit, application criticality, and dependency on legacy infrastructure, then move in waves: remote staff and cloud apps first, broker portals and TPAs second, and claims or underwriting platforms last. That sequence lets teams prove value quickly while keeping underwriting workflows and claims systems stable.
A strong pilot also defines exit criteria, such as fewer help desk tickets, successful conditional access enforcement, and stable login times, before expanding to higher-risk environments. In practice, that turns zero trust architecture into an insurance cybersecurity program the business can absorb.
Build the insurance roadmap in three phases
A workable insurance roadmap moves from pilot to privileged access to broader application coverage. In most U.S. insurers, the first phase can begin in 6 to 10 weeks, but only if identity is centralized and logging is already usable.
NIST SP 800-207 treats Zero Trust Architecture as a set of decision points, not a product purchase. That matters because insurers with GLBA, NYDFS 23 NYCRR 500, HIPAA, or SOX pressure need evidence of control, not just a new access layer.
Phase 1: pilot with high-friction users
Begin with a controlled pilot for 50 to 200 users, such as remote finance staff, regional leaders, or cloud-first teams. That size is large enough to show patterns and small enough to contain mistakes.
Use MFA, device posture checks, and app-specific access before touching core claims systems. This phase should also define what “normal” looks like for access latency, failed logins, and help desk volume.
Phase 2: brokers, TPAs, and admins
Move next to brokers, TPAs, and privileged admins because they create the largest external risk surface. The combination of broker portals, shared vendor access, and elevated rights is where insurers usually get the fastest reduction in blast radius.
A good target is to cover 60% to 80% of privileged sessions with step-up authentication, session recording, or both. That level is often enough to satisfy audit pressure without breaking every admin task.
Phase 3: claims and underwriting paths
Only after the pilot is stable should you expand into claims and underwriting paths with strong exception handling. This is where the business impact becomes visible, because even small delays can affect cycle time and customer service.
The right design uses least privilege access, microsegmentation, and logging tied to the application, not just the network. That is how you protect legacy systems without forcing a redesign that the business cannot absorb in one budget cycle.
Insurance deployments rarely succeed if they treat every external user the same. Brokers, TPAs, and vendors often need access to specific claims systems, policy data, or broker portals through legacy application security patterns that do not support modern per-app controls out of the box. A hybrid access model can bridge that gap by combining conditional access, device posture checks, and privileged access controls for modern apps while isolating older workflows through session recording, segmentation, and named-account access.
This lowers friction for legitimate users and improves auditability because the insurer can see who entered, from where, and what was done inside the session.
Identity and access control first
Identity and access management is the control plane for Zero Trust in insurance. If identity is weak, every other control becomes a layer of hope.
Multi-factor authentication should be mandatory for staff, brokers, TPAs, and especially admins. Least privilege access should be applied by role and by task, not by broad department membership.
MFA for staff and third parties
Use MFA with step-up prompts only when risk changes, such as new devices, unusual locations, or privileged actions. This keeps normal work moving while still raising the bar for attacks.
For vendors and TPAs, bind access to named identities and expiration dates. Shared accounts are still one of the most common reasons insurers lose visibility into who touched what.
Least privilege without admin pain
Privileged access management should separate daily admin work from elevated tasks. That reduces standing access and makes audit trails easier to defend under NYDFS and SOC 2 reviews.
The best practice is to remove standing admin rights from 70% to 90% of high-value systems first, then phase in just-in-time elevation. That approach lowers risk without forcing a full operational rewrite.
A simple proof point resonates with boards: who accessed the system, from what device, and for how long. That turns Zero Trust from an abstract architecture into measurable exposure reduction.
Network segmentation and microsegmentation
Network segmentation limits lateral movement, while microsegmentation narrows traffic between workloads inside the same environment. In insurance, that matters because a breach in a user segment should not reach claims databases, underwriting platforms, or file shares.
CISA and the NIST Cybersecurity Framework both support this direction because containment is part of resilience. The goal is not perfect isolation, but smaller blast radius and faster recovery.
SIEM and response playbook
Your SIEM should flag unusual access patterns, repeated step-up failures, impossible travel, and privileged actions outside approved windows. If those alerts are noisy, tune them before expanding the rollout.
A response playbook for insurers should name owners for broker access, claims systems, and vendor sessions. That is how you cut investigation time from hours to minutes when a suspicious session appears.
“Zero Trust works in insurance only when it reduces blast radius without slowing claims, underwriting, or broker operations. If it adds friction everywhere, you have designed policy, not control.”

Frequently asked questions
What is zero trust in an insurance company?
Zero Trust in an insurance company means every user, device, and app must prove trust before access is granted. For most insurers, the best first use case is remote staff, brokers, TPAs, and admins who can be checked continuously.
Should we replace VPNs completely?
Not at first, because many insurers still depend on legacy systems that do not fit a full cutover. A hybrid model is usually better until identity, device posture, and segmentation are mature.
How long does a first phase take?
A first phase usually takes 6 to 10 weeks if identity is centralized and the pilot group is limited. If directory cleanup or app mapping is missing, the timeline stretches well past one quarter.
What metrics matter to the board?
The most useful metrics are access latency, MFA step-up rate, privileged session coverage, third-party exposure, and incident containment time. Those numbers connect security controls to business continuity.
Why do claims and underwriting need special handling?
Claims and underwriting depend on legacy apps, shared workflows, and time-sensitive access. If you move them too fast, you can slow cycle time and create business pushback.
What is the biggest zero trust mistake?
The biggest mistake is treating Zero Trust as an IAM project alone. It also needs device posture, segmentation, app access control, and central logging.
How does this help with compliance?
It supports GLBA, NYDFS 23 NYCRR 500, HIPAA, SOX, and the NIST Cybersecurity Framework by tightening access and improving evidence. That makes audits easier because control and proof move together.
Your next step
Start with one pilot that includes remote users, one broker group, and one privileged workflow. If you can reduce exposure, keep access time acceptable, and avoid a help desk surge, then expand in phases rather than chasing a full VPN retirement date.
Zero Trust is not the right first move if your insurer still lacks centralized identity, basic device visibility, or real third-party pressure. In that case, fix identity and logging first, then return to the architecture decision.
Executives usually approve Zero Trust faster when the numbers show both risk reduction and operational stability. Useful KPIs include privileged access reduction, percentage of sessions covered by conditional access, MFA completion rate, time to detect and contain suspicious activity, and the number of broker or TPA sessions blocked or stepped up due to risk signals. For underwriting workflows, leaders also care about quote turnaround time, claim cycle time, and the share of users affected by friction.
When those metrics are tracked before and after rollout, the insurer can show that ransomware protection improved without materially hurting service levels or revenue-generating work.