For Insurance Agencies | Educational Resource

What Every Insurance Agency Should Know About Client Data, Cyber Rules, and Email Fraud

Agencies hold complete client profiles and sit in the middle of premium and claims money flows. Here’s what state regulators now require, how agencies actually get hit, and what well run agency IT looks like, in plain English.

NY DFS and state cyber requirements, translated
The 72 hour reporting clock, and what it assumes you have
How premium and claims payments get redirected
A baseline checklist to review with whoever runs your IT

Get the Free Insurance Agency Technology Guide

Six plain English pages: your obligations, the attacks, the agency security baseline, and the questions principals should ask. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.

72 Hours
is the DFS incident reporting clock
Annually
NY licensees certify their cyber compliance
Your AMS
holds every client's complete profile in one place
Both Ways
premiums in and claims out are targets

Your Obligations, In Plain English

Insurance became one of the most cyber regulated industries in the country, led by New York. The requirements reduce to three themes.

A Real Cybersecurity Program

New York’s DFS regulation requires licensed agents, brokers, and agencies to maintain a cybersecurity program: risk assessment, written policies, multifactor authentication, and someone responsible for it all. Many states have adopted similar requirements through the NAIC model law, and federal safeguards expectations apply on top.

Clocks and Certifications

Qualifying incidents must be reported to the regulator on a 72 hour clock, and New York licensees certify their compliance annually. Both assume detection, documentation, and an incident response plan exist before anything happens.

Carriers Are Watching Too

The carriers you represent increasingly require security measures from appointed agencies, ask about them in agreements, and expect prompt notice when client data is exposed. Your book of business depends on relationships that now have security terms attached.

How Agencies Actually Get Hit

Agency incidents follow the data and the money. Four patterns cover most of the damage.

01

The Redirected Payment

Attackers compromise or impersonate an inbox in the payment flow, then send updated instructions: a premium payment to a new account, a claims payout to different banking details. Everything matches the real correspondence because they read it first. The defense is procedural: payment instructions and banking changes verified by phone at a known number, every time.

02

The Impersonated Policyholder

A convincing email from a client’s compromised account requests a beneficiary change, a policy loan, an address update before a payout, or copies of documents full of identity data. Routine sounding requests moving money and identities are exactly what verification procedures exist for.

03

The Compromised Agency Management System

Your AMS is the crown jewels: every client’s SSN, license, financials, property details, and for benefits brokers, health information, in one searchable place. One phished login with no MFA hands all of it over, and triggers the reporting clocks in every state your clients live in.

04

Ransomware, Then the Certification Problem

Encrypted systems stop quoting, binding, and servicing. Then comes the second act: the 72 hour report, carrier notifications, and the awkward question of what last year’s compliance certification claimed. Tested, isolated backups and a written response plan turn a career event into a bad week.

What Well Run Agency IT Looks Like

Whoever manages your agency’s technology, this is the baseline worth reviewing together. Every item maps to a rule or an attack above.

MFA on Everything

Email, the AMS, carrier portals, and remote access, every account, every producer, no exceptions. It’s the single control regulators name and attackers test first.

Written Verification Procedures

Payment instructions, banking changes, and beneficiary updates confirmed by phone at a known number before anything moves. Written, trained, and followed on the busy days too.

A Program on Paper

Risk assessment, policies, training records, and an incident response plan documented and current, so the annual certification describes reality and the 72 hour clock is survivable.

Impersonation Resistant Email

Advanced phishing protection tuned for client and carrier impersonation, plus enforced SPF, DKIM, and DMARC so criminals can’t send as your agency.

Backups That Survive

Daily backups of the AMS, documents, and email with one copy ransomware can’t reach, restore tested and timed, because quoting stops when systems do.

Monitoring and Same Day Offboarding

Systems watched around the clock, and departing producers and staff losing every access the day they leave, with documentation to prove it.

Common Questions

Yes. New York’s Department of Financial Services cybersecurity regulation applies to insurance agents, brokers, and agencies licensed in New York, requiring a cybersecurity program, multifactor authentication, incident reporting on a 72 hour clock, and annual certification. Many other states have adopted versions of the NAIC Insurance Data Security Model Law with similar written program and commissioner notification requirements, and federal safeguards expectations apply as well.

Agency files and management systems hold complete client profiles: Social Security numbers, driver’s licenses, financial details, property information, and for benefits brokers, health information. Agencies also sit in the middle of premium payments and claims payouts, which gives attackers both identities to steal and money flows to redirect.

Under New York’s DFS regulation, covered entities must notify the regulator within 72 hours of determining a qualifying cybersecurity event occurred. That clock is only manageable if detection, an incident response plan, and contact procedures exist before the incident. Agencies that discover a breach weeks late have already failed the requirement.

Generally yes, though smaller agencies may qualify for limited exemptions from some provisions. Core expectations like protecting nonpublic information, MFA, and incident reporting still apply, and carriers increasingly require security measures from their appointed agencies regardless of size.

A six page plain English guide covering your regulatory obligations, the attack patterns that hit agencies most, an agency security baseline checklist, the 72 hour readiness question, and the questions principals should ask about their IT.

Start With the Guide. Decide From There.

Download the Insurance Agency Technology Guide and review the baseline with whoever runs your IT. If you’d rather have the answers verified for you, a free confidential security assessment for your agency is available too.

Fill the information below to download a PDF with everything you need to know about Penetration Test: