Venez rencontrer nos experts et partenaires à notre prochain Identity Excellence Day Paris | 17 septembre 2026

From IAM Optimization to Security Success: How a European Insurance Group Continuously Optimizes Its Identity Management with iC Consult – and Closed a Critical Security Gap in Record Time

Gouvernance et administration des identités, Services managés IAM
One Identity, One Identity Manager

A major European insurance group migrated its central IAM solution to One Identity Manager together with iC Consult, as part of a broader modernization project. It marked the start of a close partnership, one that has since driven new use cases, retired legacy systems, and pushed automation forward.

One moment in particular put that partnership to the test: iC Consult discovered a critical security vulnerability in One Identity Manager. Working together with the customer and the partner, One Identity, a hotfix was rolled out the very same day – a clear example of what fast, coordinated collaboration looks like in practice.

Content

Customer & Project Overview

Customer Profile

Industry: Insurance

Headquarters: Europe

Number Identities: > 100,000

About the Customer

The organization is an insurance group headquartered in Europe. It serves private and corporate clients with insurance and pension solutions, with a focus on long-term financial protection, innovative services, and the ongoing digitalization of its processes.

Project Description

Support for the ongoing development and operation of the group-wide IAM system One Identity Manager, including identity security services such as audits, security assessments, and penetration tests

Products & Services
  • One Identity Manager
  • Managed Services durch iC Consult

Results

Continuous implementation of new use cases for greater automation and less manual effort

Retirement of legacy systems and migration to One Identity Manager for lower operating costs and one unified platform

Management of around 100,000 identities with improved transparency and simplified compliance and audit handling

Migration of numerous applications to reduce complexity and security risks

Development and automation of a self-service portal to relieve IT and speed up provisioning

Support with role mining for clear role models and simplified recertification

Discovery and remediation of a critical security vulnerability

Background

Before modernizing its Identity and Access Management, the company’s IAM landscape had grown organically over time, shaped by several parallel solutions. The setup worked, but it came with a high degree of operational complexity. The goals were clear:

  • Reduce operational overhead
  • Create a unified foundation for security and compliance
  • Enable role mining and automated role management

The introduction of a modern IAM platform laid the groundwork. Within a short time, the team built a central, future-ready identity and access management environment, which transitioned smoothly into operations and has been developed further ever since.

Even so, complexity remained: several legacy applications still had to run in parallel. That extra effort also made clear which topics needed priority next:

  • Limited automation and self-service capabilities
  • Use cases not yet covered
  • Legacy applications already at end-of-life


In the coming years, all relevant applications will therefore be migrated into One Identity Manager. Anything no longer viable will be replaced with modern alternatives, moving IAM toward one unified, secure environment.

Solution

Close Collaboration in Daily Business

Day-to-day work centers on implementing new use cases in One Identity Manager. Legacy systems are phased out step by step, and new applications are integrated seamlessly. iC Consult supports the insurance company across the entire value chain – from analysis and architecture to solution design and software development. Numerous applications have been migrated into One Identity Manager so far, either directly or through a background mechanism.

The collaboration runs on trust, agility, and genuine partnership. « The teams work closely together, flexibly and with a hands-on mentality – taking on different roles as needed, » says the project lead.

Cleaning Up Identities and Role Mining

A key part of retiring the legacy system is cleaning up and logically consolidating all identities – with a clear separation between customer and enterprise identities, and defined role and permission models. The sheer volume poses a particular challenge:

  • Several tens of thousands of primary identities from internal and external employees
  • Additional sub-identities that also need to be maintained
  • Non-human identities (NHI) such as robots or AI agents

Altogether, the number of identities under management quickly climbs above 100,000.

The current focus is on defining standards for how sub- and non-human identities link to primary identities and get recertified regularly. At the same time, clear responsibilities are being defined and transferred into Identity Manager – building a solid foundation for cleaning up and reducing the identity portfolio sustainably.

Efficiency Through Self-Service and Automation

To manage its large number of identities efficiently and relieve its IT teams, the insurance group also uses One Identity Manager as a self-service portal. Through the integrated web shop, employees can request and manage identities and permissions on their own. Automation speeds up key processes further – for example, the fully automated creation of cloud objects for DevOps teams. This cuts manual effort significantly and improves turnaround times.

Security Services in Action: Critical Vulnerability Discovered and Fixed

Beyond day-to-day IAM management, iC Consult’s identity security services, including audits, security assessments, and penetration tests, help identify and close security gaps early. That groundwork paid off in a big way.

« I’m used to talking shop about IAM with Benedikt outside regular working hours. But when he tries to reach me on multiple channels almost at once, I know it’s time to pick up the phone, » recalls the responsible department head.

The case in question: a critical security bug in One Identity Manager, discovered by Benedikt Poller, Lead Consultant at iC Consult. The bug allowed any user in One Identity Manager to bypass permission management processes, assign arbitrary permissions, and alter permission configurations.

« I immediately contacted the vendor and told One Identity we urgently needed a patch, » says Benedikt Poller. « I also alerted the customer and their external penetration testers to the bug. It quickly became clear the vulnerability was present there too – and the pen testers classified it as critical. »

The insurer responded immediately: it declared a major incident, informed all relevant stakeholders, and launched monitoring to check the previous months’ documentation for anomalies. No misuse was found, and the bug was already fixed overnight via hotfix – so normal operations resumed quickly.

“Without Benedikt, we would never have detected this vulnerability so quickly. It was a truly exceptional achievement – one that ultimately benefited not just us, but all customers of iC Consult and One Identity.”

Responsible Project Lead at the Insurance Group

Outlook

Full Energy Ahead for the Next IAM Phase

Following the rapid remediation of the security vulnerability, the teams are continuing their work with full energy. The focus now is on fully retiring the remaining legacy systems and further optimizing identity management.

Upcoming milestones include completing the self-service portal and mapping all identity lifecycle processes in One Identity Manager – from request and approval through to recertification and permission revocation.

“With iC Consult, we feel well positioned to reach our mid- and long-term goals. And as the incident showed, we can count on them in spontaneous emergency scenarios too,” says the project lead.