Berkley, a Fortune 500 company founded in 1967, is a major U.S. commercial lines property and casualty insurance provider. Its structure is built on decentralization: approximately 60 independent operating units empowered to respond locally to specific risk landscapes, a model that turns scale into agility. The parent entity, W. R. Berkley Corporation, provides the financial backbone - $13.6 billion in stockholders' equity - while its units operate with entrepreneurial autonomy across the United States and internationally in 52 cities.
This architecture creates a specific kind of risk environment. A cybersecurity team here isn't defending a single monolithic product; it's protecting a federation of specialized insurance businesses, each with its own data streams, client portfolios, and threat profiles. The attack surface isn't a single application - it's the operational fabric connecting underwriting, claims, and actuarial data across dozens of semi-autonomous entities. Protecting that requires a strategy that accommodates local variation while enforcing enterprise-wide security baselines.
The company operates across reinsurance and specialized insurance verticals, meaning threat models encompass not just direct cyber intrusion but also the integrity of financial models and sensitive commercial client data. Security operations must therefore balance centralized governance with the speed and specificity demanded by decentralized units, a classic tension in financial services that makes the engineering problems non-trivial.






