Security awareness for insurers

An insurer can't train the person who settles claims the same way as the one who sells over the phone. Human risk concentrates on whoever touches policyholder data and payments.

How it works

Where to focus the program

A patchwork roster

Agents, brokers and in-house staff in a single program, with separable evidence.

Claims-based social engineering

Lures that mimic claims, adjusters and payouts: the vector insurers already see in real incidents.

A case for cyber insurance

A documented human risk index carries more weight than a 40-minute course certificate.

Regulatory framework

References that guide the program

The exact scope depends on the jurisdiction and the controls that apply to each organization.

ISO/IEC 27001LGPD / Ley 25.326Cyber insurance
Industry case

Evidence from real customers

See how organizations across the region measured and reduced human risk with Whalemate.

Insurance

Agents, claims, and headquarters do not share a schedule or exposure

An insurer cannot train the person who settles a claim the same way as the person who sells over the phone. Human risk concentrates on whoever touches policyholder data and payments.

The typical lure mimics a claim, an adjuster, a payout, or a rushed email from an agent. Whoever settles has an incentive to open attachments. Whoever sells has a phone full of WhatsApp. Headquarters often runs on another timezone and sometimes another IdP. A corporate LMS sent the same Friday does not cover that roster. The program has to live in the directory and accept that agents and in-house staff are not the same evidence universe.

Agents, brokers, the call center, and the back office that authorizes payouts are exposed. So is whoever loads health or asset data onto the policy. Turnover in the commercial network kills the induction course in three months. If the joiner does not enter the program the day they start selling, the control is theater. People and the commercial network have to explain who is covered without a parallel spreadsheet.

The auditor and the cyber-insurance underwriter ask the same thing in different words: does a program exist, is it measured, can it be shown? ISO/IEC 27001 asks for awareness. LGPD and Ley 25.326 ask that policyholder data be handled with a control that is not just a handbook. Cyber insurance weighs a documented human-risk index more than a course certificate. Whalemate does not issue the policy or certify LGPD. It delivers evidence for those conversations.

Sector vectors

Three attacks that already show up in real claims

The campaign has to look like the job — not like a “beware of phishing” notice.

Claims social engineering

Emails and messages that mimic filings, adjusters, shops, or document requests. The adjuster is trained to unblock the case, not to distrust the PDF. The simulation works that urgency. Reinforcement…

Phishing the agent network

The network is not in the office and does not share the same course schedule. The lure disguises itself as a commission statement, a portal, or headquarters. The program has to reach the mailbox they…

Payment fraud and policyholder data

An account change in the middle of a payout, an ID request “to update the policy.” The vector mixes social engineering with personal data. The campaign trains the second verification channel. The…

Questions about insurance

What evidence can I separate between staff and agents?
The roster is segmented by source when the directory or the joiner file allows it. Reports filter by group. That helps when audit or the network contract asks for different evidence. If the network is not in the IdP, you must define how it enters: file, API, or it stays out. We do not fake coverage of agents we never synced.
How does a new agent enter the program?
The day they exist in the data source we agreed. If the joiner takes a week in the network system, the program cannot jump the queue. SCIM or API avoid the spreadsheet. People and commercial define who is in-scope for the control. Security should not chase Excel by branch.
Does this fulfill LGPD or help with cyber insurance?
It produces evidence useful for both conversations. It is not a compliance opinion or a policy endorsement. Your counsel and your broker still interpret. We do not invent a “cyber insurance pack” with a discount percentage.
What does this module not cover?
It does not settle claims, it is not an insurance core, and it does not replace payment anti-fraud. It does not install an agent on the producer’s endpoint. It does not use individual metrics for a disciplinary regime. It also does not turn the broker network into Whalemate employees: you own the roster.

Insurance — Security awareness and human risk

The program calibrates the same way. We'll show you in the demo.