How the insurance industry is rethinking security, access, and agency efficiency.
Every year, the insurance industry adds another layer of cybersecurity. New password requirements. New authentication tools. New compliance obligations. New carrier security protocols. And for good reason. Cyber threats continue to grow, regulators are demanding stronger safeguards, and agencies are handling more sensitive customer information than ever before.
But as the industry has strengthened security, it has also increased complexity. Today, agency employees routinely manage dozens of credentials across carrier portals, technology platforms, comparative raters, and agency systems. Multi-factor authentication (MFA) has become commonplace. Password resets are a regular occurrence. And logging into systems can sometimes feel like a barrier to getting the actual job done.
“The industry has made tremendous progress improving security,” says Alvito Vaz, executive director of ID Federation. “But every new security requirement can create another hurdle for agency employees. The challenge is finding ways to strengthen security without creating unnecessary friction.”
It’s becoming increasingly relevant as regulators and carriers are placing greater emphasis on identity management and access controls. In New York, for example, the Department of Financial Services (DFS) has strengthened its cybersecurity requirements, including provisions related to multi-factor authentication. While those regulations apply directly to covered entities, they reflect a broader trend across the insurance industry. For a growing group of carriers, technology providers, agents, and industry associations, the answers to better security with less complexity may lie in federated identity management.
Beyond Another Password
ID Federation, a nonprofit industry coalition comprised of carriers, technology providers, agents, and agent associations working to improve both cybersecurity and operational efficiency across the insurance ecosystem, is leading that effort. The organization establishes common standards that allow trusted organizations to securely recognize and authenticate users across multiple systems.
Most agents don’t spend much time thinking about identity management. They experience it through passwords, authentication prompts, and login screens. Behind the scenes, however, it’s become one of the most important cybersecurity issues facing organizations of every size. Who has access to which systems? How is that access verified? How is it removed when an employee leaves? How can organizations confirm that a user is who they claim to be?
These questions sit at the center of modern cybersecurity frameworks. Through ID Federation’s SignOn Once framework, participating agencies can use their agency management system credentials—including MFA—to access participating carrier systems without repeatedly entering separate usernames and passwords. The approach leverages established cybersecurity practices while creating a common trust framework across participating organizations.
“In the past, the sheer complexity of managing dozens of carrier-specific credentials for each individual in the agency was a challenge,” explains Brian Bartosh, President at Spire America Holdings Inc and a user of SignOn Once. “Each carrier had its own login requirements, password expiration policies, and increasingly its own MFA setup. This created password fatigue, time loss, inconsistent MFA processes, and security risks. Overall, it was a fragmented experience that made even simple tasks more time consuming than they should have been.”
The concept itself is not new. Similar federated identity models are used throughout banking, healthcare, and other industries. What makes ID Federation unique is its focus on creating a common framework specifically for the independent agency channel.
“This isn’t about a product or software,” says Vaz. “It’s about creating a common trust framework that allows agencies, carriers, and technology providers to work together more securely and efficiently.”
Why Agents Should Care
For many agencies, the value proposition begins with workflow. Every additional password represents another task to manage. Every authentication challenge interrupts a workflow. And employee hires or departures create another list of systems that must be updated.
But the conversation increasingly extends beyond efficiency. As agencies adopt more technology, connect to more partners, and navigate evolving cybersecurity expectations, identity management is becoming a business issue rather than simply an IT issue. The challenge is particularly acute in agencies, where employees may regularly access systems belonging to numerous carrier partners.
“SignOn Once has helped shift our mindset from seeing security as a barrier to viewing it as an integrated part of workflow,” says Bartosh. “Previously, tighter security often meant more steps and more disruption for staff. Now we see that it’s possible to enhance security while simplifying the user experience.”
The Role of Agent Advocacy
Agent involvement is critical. Participating carriers have already demonstrated that the framework works. Agency management system providers such as Applied Systems and Vertafore have also played important roles in expanding participation. The question now is scale.
Vaz describes the industry’s current challenge as a classic chicken-or-egg scenario. Carriers want to see agency demand. Agencies often assume carriers are not interested. Meanwhile, the need for stronger security and streamlined workflows continues to grow.
“We’ve largely solved the technology challenge,” says Vaz. “What we need now is broader participation. Agents have an important role to play because carriers pay attention when their distribution partners ask for something.”
ID Federation is encouraging agencies to raise the issue with carrier representatives, not because single sign-on is a silver bullet, but because it represents one example of how the industry can improve security without simply adding another layer of complexity.
Agents interested in learning more can visit IDFederation.org, where the organization provides additional information about SignOn Once, participating organizations, and an Engage Your Carriers tool that allows agents to contact carrier partners directly and encourage participation.
“The independent agency channel has always been strongest when carriers, agencies, and technology providers work together,” says Vaz. “Identity management is another example of where collaboration benefits everyone.”
What Agents Can Do
Interested in learning more about ID Federation and SignOn Once? Consider taking these steps:
- Visit www.IDFederation.org
- Learn whether your carrier partners currently support SignOn Once.
- Ask carrier representatives about their plans for participation.
- Use the site’s “Engage Your Carriers” tool to encourage broader adoption.
- Include identity management and single sign-on in conversations about cybersecurity, agency efficiency, and carrier connectivity.




Leave a comment