Monday, September 21, 2026

Beyond compliance: EML’s strategy to secure data and drive innovation

This may have necessitated the interesting structure which EITN observed - a cybersecurity function that actually spans throughout the whole organisation.

When EITN spoke with Leon Gelderblom, Head of Security and Infrastructure at EML Group, he had pointed out, “80% of the work that claims managers are doing is administrative, so they want to significantly reduce that… they want the case manager to focus on the relationship with the injured worker and not have to do admin work.”

As the injury management partner of choice for employers and government agencies, Australians have turned to  EML for its claims expertise for over 110 years.  It is a responsibility that it does not take lightly, as it extends protection to each person’s  personally identifiable information (PII). This may have necessitated the interesting structure which EITN observed – a cybersecurity function that actually spans throughout the whole organisation.

Critical assets

At the heart of EML’s operations is Leon’s role that combines oversight of both security and infrastructure. Unlike the conventional model of segregating these functions, EML opted for a unified approach, with a single leader reporting directly to the CIO. This integration allowed for streamlined decision-making and reduced friction between security and delivery, fostering a culture where security was not an afterthought but a core pillar cutting across the company’s operation from development to service desk to day-to-day infrastructure, as well as innovation.

Leon Gelderblom

Leon explained, ‘Everything we do is around claims management. We’ve got a system to manage claims, and we’ve got a system that does document management – basically all the artifacts that are linked to the claim that will be in a document management system. 

“So both of those, we’ve developed ourselves and are the crown jewels of our organisation.” 

The security team embedded a “shift left” mindset, integrating security tools throughout the DevOps pipeline so that vulnerabilities were detected and addressed early in the software development lifecycle.

With this same rigour EML’s CIO Shane Devlin and Leon had also identified that a zero trust architecture could address the root cause of their security and availability issues.

Innovating with digital trust

EML’s journey demonstrated that holistic security, enabled by modern solutions like Zscaler, could drive both resilience and agility – empowering the business to deliver securely, even amid rapid change.

Shane Devlin

The organisation has over a century of experience in personal injury claims management, an unique advantage that they leverage to create purposeful technologies for innovative programmes. It extends this expertise to building AI tools but recognises that it needs to balance AI innovation with careful usage.

Shane had explained before in another interview, “For example, we use Zscaler’s help to prevent our employees from accessing public AI tools and accidentally leaking proprietary data.”

Specifically this meant, EML used Zscaler’s URL filtering to create granular rules about sites, categories, and user groups, and apply acceptable use policies. This also controls the use of AI tools and helps limit risk.

Granularity

During the pandemic, Zscaler had been instrumental in helping EML transition from legacy VPN access and achieve core business objectives – enabling secure connectivity regardless of users’ locations, to authorised applications. 

This helped to solve critical productivity challenges, reduce connection times and eliminate frustrating disconnection issues that previously consumed up to three hours of employee productivity daily. “Some people are losing time because of disconnection and having to reconnect (to the Internet). And it happens to them between four or eight times a day…. We could offset that with Zscaler.

“Our immediate goal was to improve the work-from-home experience with a solution that meets our stringent technical and cybersecurity requirements,” said Leon.

As EML explored other Zscaler solutions in later phases of  implementation, it benefited from granular access controls that were lacking prior to Zscaler. “(The team) needs to be able to control what level of access people get and have visibility on how it’s being used,” Leon pointed out, and added, “Zscaler’s capabilities will give you that visibility so that you can make informed decisions if things do go wrong.”

Cat Yong
Cat Yong
Cat Yong is Editor-in-Chief of Enterprise IT News, a regional news website which began in Malaysia circa 2011. A common theme in all of her work - opinions, analysis, features and more - is how technology and innovation drives business and outcomes. A career tech journalist for 22 years, her work has evolved to also encompass narratives of tech powering human potential.
Powered byspot_img

Read more

News

Powered byspot_img