Heights Consulting Group

Insurance Organizations

Insurance agencies, MGAs, TPAs and carriers operate under state insurance data security laws that require a written program, a designated responsible person and, in many states, an annual certification to the regulator. They need security leadership that can hold those licensing obligations, carrier requirements and real-world exposure in one governed program.

Obligations

What applies in this sector

Descriptions are of the published requirements, not claims about outcomes.

How we establish which obligations apply
Regimes that commonly apply to Insurance Organizations organizations, NIST Cybersecurity Framework, ISO/IEC 27001, SOC 2, all resolving into one governed security program.

Regimes in play

  • NIST CSF Voluntary framework
  • ISO 27001 Certifiable standard
  • SOC 2 Attestation examination

One control base

Mapped once, evidenced once, and maintained between assessments.

The environment

What shapes security decisions here

Insurance organizations hold exactly what identity thieves want: identities, health details, financials and claims histories, concentrated across books of business, and they hold it as licensed entities whose regulators can reach their license, not just their wallet.

The regulatory model changed when states began adopting insurance data security laws patterned on the NAIC model: a written information security program, risk assessment, board or executive oversight, incident response, and event notification to the insurance commissioner on short timelines. In many adopting states, licensees certify compliance annually.

Distribution adds a second layer of obligation. Carriers impose security requirements on the agencies, MGAs and administrators they appoint, and a licensee that cannot demonstrate its program risks appointments and contracts as directly as it risks regulatory attention.

Exposure

Risks that behave differently in this sector

Not a general threat list. These are the exposures that need a different response here than they would elsewhere.

  • Nonpublic information at book scale

    A single agency system can expose the identities, health and financial details of every insured in the book. The concentration is what makes small licensees consequential targets.

  • License-level consequences

    Insurance regulators examine licensees and can act against the license itself. A security failure is a regulatory matter in a way it is not for an unlicensed business.

  • Short-fuse notification duties

    State insurance data security laws commonly require notifying the commissioner within days of a determined cybersecurity event, a timeline an unprepared organization cannot meet honestly.

  • Fraud through the money flow

    Premium payments, claims disbursements and commission flows make insurance organizations standing targets for business email compromise and payment redirection.

Requirements

Regulatory and contractual pressure

General descriptions of published requirements. Which of them apply to a particular organization is the first question an engagement answers.

State insurance data security laws (NAIC model)
Adopted in a majority of states: a written information security program based on a risk assessment, a designated responsible person, executive oversight, service provider requirements, incident response and event notification duties for licensees.
Annual certification
Many adopting states require licensees to certify compliance with the insurance data security law to the commissioner each year, making the program's existence a signed representation.
NY DFS 23 NYCRR 500
New York's cybersecurity regulation for financial services companies, applying to insurers and producers licensed in New York, with prescriptive control, governance and certification requirements.
GLBA and state privacy rules
Privacy and safeguarding obligations for nonpublic personal financial and health information held by insurance licensees, alongside HIPAA where health plans are involved.
Carrier security requirements
Contractual obligations imposed through appointment and administration agreements, including questionnaires, audit rights and breach notification duties to the carrier.

How we establish which obligations apply

What we hear

What leadership raises with us

  • The annual certification is being signed, and the signer is not certain the program it attests to exists.
  • The designated responsible person named in the program is a title, not a function anyone performs.
  • A carrier audit or new appointment questionnaire is asking for evidence the organization has never produced.
  • Client files and policy data have accumulated in email and shared drives outside any system of record.
  • An event-notification clock measured in days would start before the organization could even determine what happened.

What prompts an engagement

  • The state adopted an insurance data security law and the first certification deadline is approaching.
  • A carrier made program evidence a condition of a new or continued appointment.
  • A regulator examination included cybersecurity questions the last one did not.
  • A payment-redirection or phishing incident touched premium or claims funds.
  • An acquisition is bringing another agency's systems and data into the fold.

Alignment

Frameworks that apply here

NIST Cybersecurity Framework
Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
ISO/IEC 27001
Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
SOC 2
Technology and service companies whose enterprise customers require evidence of a controlled environment.

FAQ

Questions from insurance Organizations leaders

General questions about the vCISO role are answered on the vCISO page.

What do state insurance data security laws require of an agency or MGA?

The laws patterned on the NAIC model require a written information security program built on a risk assessment, a designated person responsible for it, executive-level oversight, oversight of service providers, an incident response plan, and notification to the insurance commissioner within a defined number of days of a qualifying cybersecurity event. Many states add an annual compliance certification.

Some states exempt the smallest licensees by employee count or revenue, but carriers frequently impose equivalent requirements contractually, so the practical obligation often applies regardless of the statutory exemption.

Who can serve as the designated responsible person our state's law requires?

The laws generally allow the role to be filled by an employee, an affiliate or a third-party service provider, provided the licensee retains oversight. What matters to an examiner is that the function is real: someone who maintains the program, keeps the risk assessment current, and can speak for it.

That is a role fractional security leadership is well suited to hold for an agency or administrator that cannot justify a full-time hire, with the licensee's executives retaining the oversight the law expects of them.

We are appointed by several carriers. Whose security requirements do we follow?

All of them, which is the argument for running one program rather than answering each carrier separately. Build the program against your state law and a recognized framework, map each carrier's requirements to it, and close the genuine gaps rather than maintaining parallel compliance stories.

One governed program also produces one truthful set of questionnaire answers, which matters because those answers are representations to counterparties with audit rights.