Fortellar
Case Study| Cybersecurity

From Reactive to Resilient: How a Leading Health Insurer Transformed Its Cybersecurity Posture

Executive Summary

A large regional health insurance provider serving over 2 million members and managing sensitive regulated data (PHI/PII), faced declining cybersecurity maturity despite a substantial annual security investment of over $4.5 million. Fragmented visibility, inconsistent policy execution, and a disconnect between business continuity and security objectives elevated the risk of breaches and reputational harm.

We built a unified risk intelligence platform that consolidated data from nearly 30 disparate systems into a single, real-time dashboard. This provided leaders with their first-ever comprehensive view of the organization's security posture, tracking 68 previously untracked Key Risk Indicators (KRIs). The result was a dramatic improvement in governance, faster decision-making, and a defensible, data-driven foundation for audit readiness and future resilience.

Colleagues in discussion in an office

The Challenge: Fragmented Risk Visibility and Declining Security Maturity

A large regional health insurer faced a critical challenge: despite a $4.5M+ annual cybersecurity investment, its security posture was falling below industry benchmarks. This exposed the organization, its 2 million members, and their sensitive data (PHI/PII) to significant risk. The core issues were:

  • Fragmented Visibility: Risk data was scattered across numerous platforms, preventing leadership from identifying key trends or understanding the true state of their defenses.
  • Inconsistent Policy Execution: Written policies existed but lacked enforceable procedures and tool standardization, creating defense gaps.
  • Limited Operational Insight: Security reviews relied on static documentation and interviews, not real-time performance data from the tools themselves.
  • Elevated Risk Exposure: Incomplete oversight left the organization vulnerable to breaches, ransomware, and reputational damage.

The organization urgently needed to replace subjective assessments with a centralized, data-driven solution to re-establish control and accountability over its security landscape.

Our Solution: A Unified Framework for Risk Intelligence

To bridge the gap between security spending and actual performance, our team partnered with both business and technical leaders. The goal was to build a data-driven framework that would replace subjective assessments with real-time, objective evidence.

Our comprehensive approach included:

  • Identifying and Defining KRIs: Through collaborative workshops, we identified and defined 68 meaningful Key Risk Indicators (KRIs) that accurately reflected the organization's unique risk landscape and captured critical aspects of cybersecurity and operational risk. Examples included: Devices with unhealthy or inactive antivirus software, number of domain administrators with elevated privileges, and third-party vendors with open findings, categorized by risk level.
  • Structuring the KRI Framework: We organized the 68 KRIs into 9 strategic categories (e.g., Cybersecurity & Incident Response, Sensitive Data Management, Vendor Risk) to align them with enterprise risk themes.
  • Mapping to Data Sources: We meticulously mapped each KRI to approximately 30 platforms spanning infrastructure, applications, monitoring tools, and third-party services. Key platforms included Microsoft Office 365, Proofpoint, Tenable, Prisma Cloud, Sumo Logic, and ServiceNow.
  • Assessing Data Extraction Capabilities: We evaluated each platform's API and export capabilities to design a secure, automated data pipeline, ensuring seamless integration into the KRI framework.
  • Ensuring Data Integrity and Security: We rigorously evaluated data sources for availability, reliability, and security, guaranteeing that each KRI could be reported consistently, accurately, and in full compliance with governance policies. Our team also governed the internal security function to establish secure, governed access to risk data.
  • Establishing Continuous Governance: We established a robust governance framework for KRI refinement, fostering collaboration between business and security teams for regular reviews, data validation, and indicator evolution as organizational needs changed.

The resulting KRI framework was embedded into an interactive dashboard, providing continuous, real-time insight to leadership, operational teams, and governance stakeholders.

An abstract blue network of connected data nodes

Results & Impact: A Transformation in Security Posture

Our engagement delivered a range of critical outcomes that fundamentally improved the organization's cybersecurity posture and risk management capabilities.

  • From Fragmented Data to a Single Source of Truth: We replaced siloed spreadsheets and manual reporting with a unified dashboard that provided a holistic view of enterprise risk. By integrating data from ~30 different platforms, we slashed the time and effort required for risk reporting from weeks to minutes, eliminating inconsistencies and enabling a single, trusted view of the security environment.
  • Enabled Proactive, Evidence-Based Decisions: For the first time, leaders had real-time visibility into 68 critical risk indicators, categorized by severity and business impact. This shifted board-level conversations from reactive incident reviews to strategic, data-driven planning, allowing the organization to clearly see the ROI of its $4.5M security investment and proactively address threats before they could be exploited.
  • Fostered a Culture of Accountability: The KRI framework established clear ownership and traceability for each risk indicator, embedding accountability into governance workflows. This bridged the historical gap between business, IT, and security teams, creating a shared understanding of the risk and aligning priorities, resource allocation, and remediation efforts across the enterprise.
  • Built a Foundation for Audit Readiness and Resilience: The structured, repeatable risk measurement process provides a defensible posture for regulatory audits and resilience assessments. The organization can now confidently demonstrate due diligence and data-backed compliance to regulators and stakeholders, strengthening its overall posture.

Conclusion: A Foundation for Continuous Security Maturity

This engagement marked a significant step forward in the organization's journey toward proactive, data-driven cybersecurity and operational risk management. By providing a single, trusted view of its security posture, we empowered the insurer to move from a reactive to a proactive one. The centralized dashboard and standardized reporting mechanisms not only empowered leadership with real-time insights but also fostered stronger cross-functional collaboration and accountability.

What began as an effort to address declining cybersecurity maturity evolved into a foundational capability that now supports continuous monitoring, better governance, and audit readiness. The organization is now positioned to make more informed decisions, align security efforts with business objectives, and advance toward its long-term resilience goals with confidence.

Turn these insights into impact

You've explored the resources. Now see how Fortellar helps you execute the strategy.

Explore Our Services