The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law establishes baseline cybersecurity requirements for licensed insurers and insurance producers. Multiple states have adopted versions of the Model Law, and amendments are being considered or enacted that strengthen risk assessment obligations, incident response timelines, and third-party oversight. Leadership at insurance carriers, managing general agents, and large brokerages now faces updated compliance expectations without always having clear internal ownership of the work required to meet them.
What the Regulatory Requirement Means
The NAIC Model Law requires covered entities to develop, implement, and maintain a comprehensive information security program based on a risk assessment. Amendments being adopted at the state level typically strengthen three areas: more rigorous and documented risk assessment processes, tighter incident response and notification timelines, and expanded requirements for oversight of third-party service providers who handle nonpublic information.
The regulation does not prescribe specific technologies or controls. Instead, it requires that the information security program be appropriate to the size and complexity of the organization, the nature and scope of its activities, and the sensitivity of the information it holds. The program must be documented, approved by the board or senior leadership, and reviewed at least annually.
State implementations vary. Some states have adopted the Model Law with minimal changes; others have added stricter notification timelines, explicit requirements for multi-factor authentication or encryption, or mandatory annual certification by senior executives. Organizations operating in multiple jurisdictions must track which version applies in each state.
Why This Matters to Insurance Leadership
Non-compliance can result in enforcement actions, fines, and suspension or revocation of licenses. More immediately, leadership faces reputational and operational risk if the organization cannot demonstrate a documented, risk-based security program during examinations.
The business consequence is not primarily technical. It is a question of governance: can the organization show that a qualified individual or function is making informed risk decisions, documenting those decisions, and reporting to senior leadership and the board? Without clear ownership, the work either does not happen or happens inconsistently, creating gaps that become visible during audits or incidents.
Insurance entities often operate lean technology teams focused on systems availability and business continuity. Security risk management, vendor oversight, and regulatory interpretation require a different skill set and sustained executive attention. The amended Model Law requirements surface this gap plainly.
Updated Risk Assessment Requirements
Amendments strengthen expectations for risk assessment by requiring that the assessment be documented, reviewed at least annually, and updated when there are material changes to business operations or the threat environment. The risk assessment must identify reasonably foreseeable internal and external threats, assess the likelihood and potential damage of those threats, and evaluate the sufficiency of existing controls.
The assessment must consider the specific risks posed by third-party service providers. This means inventorying vendors who access or store nonpublic information, understanding the controls they maintain, and documenting the residual risk the organization accepts when relying on them.
Many organizations have informal or incomplete risk assessments. Meeting the updated standard requires a structured methodology, clear documentation, and someone with the authority and expertise to interpret findings and recommend action to leadership.
Incident Response and Notification Obligations
The Model Law has always required notification of cybersecurity events to the state insurance commissioner. Amendments being adopted tighten the definition of reportable events and shorten notification timelines, in some cases to as few as three days from discovery.
A reportable event typically includes unauthorized access to or acquisition of nonpublic information, material disruption to business operations, or the discovery that a third-party service provider has experienced a cybersecurity event affecting the insurer's data or systems. Organizations must be able to determine quickly whether an event is reportable, assemble the required information, and notify the appropriate regulator within the mandated window.
This requires a written incident response plan that defines roles, escalation paths, and decision criteria. The plan must be tested, and results documented. Leadership must know who is authorized to make the determination that an event is reportable and who will manage communication with regulators and, where necessary, affected individuals.
Third-Party Oversight and Vendor Management
Amended versions of the Model Law expand requirements for third-party service provider oversight. Covered entities must conduct due diligence before engaging a provider, require appropriate security controls by contract, and monitor compliance on an ongoing basis. If a third party experiences a cybersecurity event that affects the insurer, the insurer may be required to report it.
For many insurance entities, vendor risk management is informal or delegated to procurement or business units without security expertise. The regulation requires a centralized process: identifying which vendors handle sensitive information, assessing their security posture, documenting contractual requirements, and maintaining oversight throughout the relationship.
This is not a one-time exercise. Vendor risk must be reassessed periodically and when there are material changes to the vendor's operations, ownership, or security posture.
Who Owns Compliance and What Adequate Ownership Looks Like
The Model Law requires designation of a qualified individual responsible for the information security program. This person must have adequate authority, resources, and expertise. In practice, this means someone who can interpret regulatory requirements, assess technical and operational risk, make recommendations to senior leadership, and coordinate implementation across departments.
Compliance officers typically understand regulatory obligations but may lack security expertise. IT directors understand systems but may lack risk management experience or board-level reporting relationships. The gap is not a failure of competence; it is a structural issue. The role requires strategic thinking, regulatory fluency, and technical judgment—skills that do not always reside in a single existing position.
Adequate ownership means a named individual with clear accountability, a documented charter, regular reporting to the board or senior leadership, and the authority to request resources or escalate unresolved risks. The individual does not need to perform every task personally, but must orchestrate the work and own the outcome.
How This Relates to Regulatory and Framework Readiness
The NAIC Model Law does not mandate a specific framework, but it aligns closely with risk-based approaches such as the NIST Cybersecurity Framework. Organizations that have already adopted a structured framework will find it easier to demonstrate compliance, because the underlying activities—risk assessment, control selection, incident management, vendor oversight—are the same.
Framework readiness is not about checking boxes. It is about establishing governance: defining who makes security decisions, how those decisions are documented, and how leadership stays informed. The Model Law amendments make this governance requirement explicit and enforceable.
Organizations that treat compliance as a documentation exercise will struggle. Those that build genuine executive ownership of security risk will satisfy the regulation naturally, because the program will reflect actual risk decisions made by qualified leadership.
Practical Next Steps for Leadership
First, confirm which version of the Model Law applies in each state where the organization is licensed. Track pending amendments and effective dates. Assign someone to monitor regulatory developments and brief leadership quarterly.
Second, identify the qualified individual responsible for the information security program. If that person has not been formally designated, or if their charter is unclear, resolve it. Document their authority, reporting relationship, and accountability in writing.
Third, review the current risk assessment. If it exists only informally or has not been updated in the past year, schedule a documented assessment. Ensure it covers third-party risks explicitly and results in a written plan with priorities and ownership.
Fourth, examine the incident response plan. Confirm it defines reportable events consistent with applicable state law, establishes notification timelines, and assigns clear roles. Test the plan through a tabletop exercise and document the results.
Fifth, inventory third-party service providers who access or store nonpublic information. Assess whether contracts include appropriate security requirements and whether ongoing oversight is documented. If vendor risk management is informal, establish a centralized process.
Finally, schedule regular board or senior leadership briefings on information security program status, risk posture, and compliance gaps. The regulation requires oversight; leadership must be in a position to exercise it.
When Executive Ownership Is Missing
Many insurance entities do not have a full-time chief information security officer. Hiring one is expensive and difficult, particularly for mid-sized carriers and MGAs. The alternative is to establish executive ownership through a [virtual CISO (vCISO)](/vciso/) engagement, which provides qualified leadership without the cost or commitment of a permanent hire.
A vCISO interprets regulatory requirements, conducts or oversees risk assessments, designs governance structures, and reports directly to senior leadership. The result is compliance that reflects actual risk decisions, not documentation retrofitted after the fact.
If your organization is accountable for meeting amended NAIC Model Law requirements but lacks clear ownership or a defined path to compliance, a confidential consultation can clarify the gap and outline a practical approach. Heights Consulting Group provides fractional CISO leadership for regulated organizations. Schedule a conversation at a point where you are ready to resolve the ownership question, not when you are still gathering information.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.