Insurance Agency Cyber Readiness
Insurance Agency Cybersecurity Requirements and Readiness
Infosec Check helps independent insurance agencies determine which cybersecurity requirements actually apply, verify whether required controls are operating, document the evidence, and correct gaps before an incident, regulatory inquiry, carrier review, or cyber insurance renewal.
Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check
Published · Last reviewed
Scope: Cybersecurity requirements, exemptions, and evidence expectations for independent insurance agencies · Jurisdiction: United States
General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.
Direct answer
Whether cybersecurity requirements apply to an independent insurance agency depends on its domicile, where it holds licenses, its affiliations, and its size. Many states have adopted a version of the NAIC Insurance Data Security Model Law, which generally calls for a written information security program, risk assessment, third-party oversight, and notification of certain cybersecurity events. Exemptions exist and are specific. Carrier contracts and the agency's own cyber insurance application can impose expectations that apply regardless of any exemption.
Why insurance agency cybersecurity is different
An independent agency sits in the middle of a lot of sensitive information that belongs to other people. Policyholder nonpublic information moves through agency management systems, carrier portals, and email every day. Producers work remotely. Vendors and managed service providers touch systems they did not build. None of that is unusual, but it does mean an agency's cybersecurity exposure looks different from a typical small business, and generic advice rarely accounts for it.
Which cybersecurity regulations apply to an insurance agency
Most agencies assume one of two things: that nothing applies to them, or that everything does. Both are usually wrong. The answer turns on where the agency is domiciled, where it holds licenses, how it is affiliated, and what else it does besides sell insurance.
State insurance data security laws
What is known: the NAIC Insurance Data Security Model Law has been adopted, in varying forms, by many states, and Virginia enacted its own Insurance Data Security Act. Adopted versions generally address an information security program, risk assessment, oversight of third-party service providers, and notification of certain cybersecurity events to the state insurance regulator. What depends on your facts: whether a given state has adopted the model, how that state defines a licensee and an exemption, which notification timelines and content apply, and whether an agency licensed in several states is subject to more than one framework. Confirm current state text and regulator guidance rather than relying on a summary.
Exemptions are real, and they are specific
Many states exempt smaller licensees from some or all information security program requirements based on employee count or similar measures. An agency already covered under another licensee's program, or one already meeting HIPAA requirements, may qualify for relief as well. Whether an exemption reaches your agency depends on how your state defines the threshold and how your operations are actually structured. Assuming an exemption applies, without confirming it, carries the same exposure as assuming none exists.
The FTC Safeguards Rule, and why it may be the wrong question
Under the Gramm-Leach-Bliley Act framework, insurance activities are generally supervised by state insurance regulators, and the FTC has stated that persons engaged in insurance activities regulated by a state are outside its Safeguards Rule enforcement for those activities. For a licensed agency's insurance operations, that often means state insurance data security law is the framework to examine first. The Safeguards Rule can still be relevant where an agency has affiliated non-insurance lines of business, such as premium finance or tax preparation. Establishing which framework governs which part of your operation matters before any program is built around the wrong one.
Contractual and carrier requirements sit on top
Regulation is only part of the picture. Carrier appointment agreements, agency management system terms, and the agency's own cyber insurance application can each impose security expectations that exist independently of any statute. An agency can be fully exempt from a state program requirement and still be contractually obligated to maintain specific controls.
Infosec Check is based in Virginia and works with independent agencies nationwide. This overview is general information, not a legal opinion. Confirming what applies to your agency requires reviewing your specific domicile, licensing, and affiliations against current state guidance, and where appropriate, with qualified counsel.
Where cybersecurity gaps cost an agency: carriers, renewals, and regulators
Carrier reviews.
Appointments and contracts increasingly reference security expectations, and an agency that cannot show what it has in place can lose standing with a carrier before any incident occurs.
Cyber insurance renewal.
The agency's own cyber policy application asks about controls like MFA, backups, and endpoint protection. Representations made at renewal matter if a claim is ever filed.
Regulatory exposure.
Depending on domicile, licensing, and affiliation, an agency may have direct reporting obligations under state insurance data security laws, or may be exempt because another licensee's program already covers it. Guessing wrong in either direction creates risk.
Referral relationships.
Agencies that can point to a documented program have an easier time being the trusted referral source for clients asking who handles their own cybersecurity questions.
What an insurance agency cybersecurity assessment covers
- • Agency management system access and configuration
- • Carrier portal credentials and access controls
- • Handling of policyholder nonpublic information
- • Email and Microsoft 365 security configuration
- • Remote producer and employee access
- • Vendor and managed service provider relationships
- • Cyber insurance application representations
- • Written information security program documentation
- • Incident investigation and notification readiness
- • Evidence that controls are actually operating, not just documented
How an agency cyber readiness engagement works
Education.
Understand what applies to your agency specifically, based on domicile, licensing, and affiliation, not a generic checklist.
Baseline review.
A focused evidence review against your actual environment, resulting in a scored baseline and a prioritized roadmap.
Buildout.
Correcting policies, controls, ownership, and evidence gaps identified in the baseline.
Managed readiness.
Ongoing maintenance of evidence and governance so the agency stays audit-ready and renewal-ready over time, not just for a single point in time.
Requirements, exemptions, and reporting deadlines vary by state and by license type. Nothing on this page is a legal opinion or a substitute for confirming your specific obligations with your state insurance regulator's guidance or with qualified counsel.
Authoritative sources
- NAIC, Model 668 state adoption map
Issuer: National Association of Insurance Commissioners
Supports: Current state adoption status of the NAIC Insurance Data Security Model Law. This map is not the complete model-law text and does not state how requirements apply to a particular agency.
- NAIC, Cybersecurity insurance topic
Issuer: National Association of Insurance Commissioners
Supports: Current status information on state adoption of insurance data security requirements.
- Virginia SCC, Insurance cybersecurity requirements and reporting
Issuer: Virginia State Corporation Commission, Bureau of Insurance
Supports: Virginia-specific licensee obligations, exemptions, and event-notification expectations.
- FTC Safeguards Rule: What Your Business Needs to Know
Issuer: Federal Trade Commission
Supports: Scope of the Safeguards Rule, relevant where an agency has affiliated non-insurance lines of business.
Primary sources are cited for the specific point noted. They do not determine how a rule, contract, or policy applies to a particular organization.
FAQ
Insurance agency cybersecurity questions
Does every insurance agency have to report cybersecurity events to a state regulator?
Is a written information security program required?
How is this different from a general small business cybersecurity assessment?
Can gaps in our cybersecurity program affect our own cyber insurance coverage?
What does the Agency Cyber Exposure Check involve?
Who is Infosec Check's guidance for?
Find Out Which Cybersecurity Rules Apply to Your Agency
If leadership is uncertain about applicability, exemptions, carrier expectations, or the evidence behind your cyber insurance representations, Infosec Check can help clarify the position.
A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.
Call Infosec Check
(855) 624-6262