For a global insurance brokerage, protecting customer information is the mission itself. Howard Whyte, Chief Information Security Officer at CRC Group, holds a simple belief about the data his team safeguards: the personal information of CRC's customers deserves the same care as his own. That responsibility carries extra weight in a heavily regulated industry, where CRC must continually prove it meets requirements across identity, data protection, and governance, risk, and compliance.
Howard knows the journey well. He was CISO at Truist when CRC Group, then part of Truist Insurance Holdings, became an independent, privately held company. As an independent business, CRC set out to build and mature its own security program while integrating a number of companies, each with different infrastructure and applications.
In doing so, Howard and his team faced four interconnected challenges:
Building An Independent Security Program Under Regulatory Scrutiny
Sprawling Environments With An Unclear Exposure
Identity Was An Unprotected Point Of Failure
Recovery Expectations Were Tightening
With Rubrik in place, CRC Group has a cyber resilience foundation that lets it keep growing with confidence:
Regulatory Readiness Backed By Evidence:
CRC can show regulators and insurance brokers how far its posture has come, with recovery capabilities that support its risk management framework.
Faster, Clearer Exposure Assessment Across Acquired Businesses:
Rubrik lets the team trace access back to specific data sets to understand the scope of an event, and every new entity brought in through CRC's transformation office adopts the same protection technology stack.
Protected, Recoverable Identities:
Rubrik Identity Recovery backs up CRC's identities and gives the team confidence it can restore them to a known good state.
Confidence In Recovery From Known Good Data:
Continuous assessment of backup data takes the worry of restoring bad code off the table, and Rubrik and its integrated capabilities are helping bring tier zero recovery times toward manageable tolerances.
As CRC deployed Rubrik for data protection, Howard made identity a priority, having seen the need in other environments. For a regulated business that holds this much sensitive customer information, he considers identity backup and timely recovery essential. Support from Rubrik made the implementation seamless and easy, and the platform now covers CRC's enterprise and unstructured data, its SaaS applications (Microsoft 365 and Salesforce), and its identities in one place.
The value extends well beyond the technology. Howard shares CRC's recovery story with the board and executive team so they know the business can keep operating today and could reconstitute quickly if something happened tomorrow. It also supports how CRC responds to its regulators and insurance partners, showing steady gains in maturity over time. Because resilience is only real when practiced, Howard is now working with Rubrik to exercise recovery capabilities and confirm the deployment matches how top-tier customers run it.
Howard sees AI agents as the next big shift: machines that take on identities and act inside the environment like people do. Regulated organizations need to see every prompt, agent, and response, and be able to disable and rebuild an agent just as they would an employee. He sees Rubrik’s direction across data, SaaS, identity, and AI agents as a holistic platform that can help CRC move faster with the confidence to rebuild at the speed the business needs.