Success Story

Merkur Versicherung AG Relies on Garancy® Identity Manager as Their Central Authorization Administration Tool

With the introduction of the Garancy® IAM Suite, now new authorizations are only granted based on defined roles. Supervisors can use the Garancy® portal to independently manage the access rights of their team members. This results in a high degree of flexibility for the business departments while at the same time reducing the IT overhead.

The Beta Systems Garancy® IAM Suite was the only product that integrated seamlessly with our home-grown core insurance software.

merkur-versicherung-logo.png
Nikola Birkic
IAM Administrator, Merkur Versicherung AG

Initial Situation

When Merkur Versicherung was founded in Graz in 1798, the Holy Roman Empire under Emperor Franz II was in its final stages. This makes today’s Merkur Versicherung AG, headquartered in Graz, undisputedly the oldest insurance company in Austria. Nonetheless, in terms of technology and organization it has always been a frontrunner. With the IAM solution from Beta Systems, the insurance company now has complete control over who accesses which systems and when. It thus meets all the requirements of the financial supervisory authority, while benefiting from streamlined internal workflows at the same time.

While other companies were still pondering how best to distribute paper inboxes during the pandemic, Merkur already had an “eWorkplace” – an electronic workplace where correspondence is received exclusively digitally and forwarded to the right employee via workflows. “Many similar applications have been added to our IT landscape in recent years,” reports certified insurance brokerEva Kainz-Kaufmann with the Information Technology – IT Management department of the insurance group. For all of these applications, the insurer must define who can access any given system in what manner and for how long. Up until recently, these permissions had been assigned via a ticket system (Jira). In this system, the specialist departments had to create tickets to submit their requirements as to who may use which software and to what extent, and the administrators of the individual target systems then implemented these for the individual user in the respective systems.

Challenge

An internal IT audit performed in 2017 uncovered the actual effort associated with this approach. Authorizations used to be based on individuals rather than roles. As a consequence, an individual ticket was created for each authorization request and there was no general transparency on who had which authorizations at any given time. “When the financial supervisory authority made inquiries, we always had to find this information in the individual tickets,” says Eva Kainz-Kaufmann. For security reasons, in particular, it is essential to know at all times who has what rights for which systems. It is equally crucial to be able to assign or revoke these rights without delay.

Therefore, the insurance company decided in 2019 to introduce a central authorization management tool. The market was sounded out together with an external consulting firm. Three vendors were shortlisted out of an initial selection of ten. Beta Systems ended up on top with its Garancy® IAM Suite. In addition to the MIS (Merkur Information System), Lotus Notes, eWorkplace and Microsoft Active Directory (including other systems connected via these, e.g. an automatic mail generation solution) had to be integrated with the IAM software.

Implementation

First step: Implement the role concept. Merkur Versicherung AG started to create a new role concept alongside the introduction of the Garancy® IAM Suite. Existing systems and IT authorization structures were assessed and cleaned up from the ground up.

Outcome

With the introduction of the Garancy® IAM Suite, now new authorizations are only granted based on defined roles. The insurance company creates the roles in the Infoniqa HR system. Information such as the date of entry of employees, the department they work in and the position they hold there are of interest. Based on this data, each employee is assigned two basic roles: an organizational role and a business role (corresponding to the job profile). The organizational role basically defines the department of the employee, while the business role describes their activities in detail. This classification was decided by IT in consultation with the system owners as well as with the division managers of the respective department.

To pull off such a huge project during the pandemic solely via Webex was a remarkable achievement.

merkur-versicherung-logo.png
Martin Majhen
IT Manager, Merkur Versicherungen AG

Customer

merkur-versicherung-logo.png
Year of foundation
1798
Number of employees
1000
Head office
Graz
Sector
Financial services
Merkur Versicherung AG
Conrad-von-Hötzendorf-Straße 84
8010 Graz
Austria

Tags

Identity ManagementIAM

Share

Further Resources

Blog Article
mainframe-z16-beta-systems-header.jpg

Solving the Mainframe Administration Challenge with an IAM Solution

Diminishing skills in administration staff of IBM zSystems (also known as Mainframes) have been a concern since the early 1990s, and there has been nearly no substantial improvement since then. Many z/OS administrators hired in the nineties have retired or are nearing retirement, with no skilled replacements in sight. This shortage of skilled z/OS administrators poses a significant challenge for companies that rely on mainframes for business-critical processes. This article demonstrates how to delegate typical mainframe administration tasks to employees with limited or no mainframe experience, thereby making more efficient use of the remaining mainframe skills within the company.
Blog Article
rechenzentren_wandel_blogpost.jpg

Data Centers in Transition: How Data, AI and Sustainability Shape the Future

Data centers are at a turning point: The constant increase in data volumes, the growing demand for AI applications and the growing complexity of hybrid IT landscapes are shaping the industry. While hyperscalers like Amazon are investing billions in IT infrastructure expansion, traditional data center operators need to adapt to keep pace with the demands of modern technologies. This article offers a glimpse into the future of data centers and highlights the most exciting trends and challenges.
Blog Article
blogpost_farmer_insurance_v2.jpg

US Insurance Transforms Report and Log Management with Beta Systems

A leading North American insurer, embarked on a transformative IT project to modernize its core report and log management systems. With over 20,000 employees and many more agents, the organization relies on efficient, reliable access to operational and business-critical reports in its daily workflows. These reports, generated and distributed by the legacy CA View and CA Deliver systems hosted on IBM z/OS platforms, were deeply embedded in the company’s operations. Virtually all business users depended on these reports for decision-making, creating a widespread dependency across the organization.