What Every Insurance Agency Should Know About Client Data, Cyber Rules, and Email Fraud
Agencies hold complete client profiles and sit in the middle of premium and claims money flows. Here’s what state regulators now require, how agencies actually get hit, and what well run agency IT looks like, in plain English.
Get the Free Insurance Agency Technology Guide
Six plain English pages: your obligations, the attacks, the agency security baseline, and the questions principals should ask. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.
Your Obligations, In Plain English
Insurance became one of the most cyber regulated industries in the country, led by New York. The requirements reduce to three themes.
A Real Cybersecurity Program
New York’s DFS regulation requires licensed agents, brokers, and agencies to maintain a cybersecurity program: risk assessment, written policies, multifactor authentication, and someone responsible for it all. Many states have adopted similar requirements through the NAIC model law, and federal safeguards expectations apply on top.
Clocks and Certifications
Qualifying incidents must be reported to the regulator on a 72 hour clock, and New York licensees certify their compliance annually. Both assume detection, documentation, and an incident response plan exist before anything happens.
Carriers Are Watching Too
The carriers you represent increasingly require security measures from appointed agencies, ask about them in agreements, and expect prompt notice when client data is exposed. Your book of business depends on relationships that now have security terms attached.
How Agencies Actually Get Hit
Agency incidents follow the data and the money. Four patterns cover most of the damage.
The Redirected Payment
Attackers compromise or impersonate an inbox in the payment flow, then send updated instructions: a premium payment to a new account, a claims payout to different banking details. Everything matches the real correspondence because they read it first. The defense is procedural: payment instructions and banking changes verified by phone at a known number, every time.
The Impersonated Policyholder
A convincing email from a client’s compromised account requests a beneficiary change, a policy loan, an address update before a payout, or copies of documents full of identity data. Routine sounding requests moving money and identities are exactly what verification procedures exist for.
The Compromised Agency Management System
Your AMS is the crown jewels: every client’s SSN, license, financials, property details, and for benefits brokers, health information, in one searchable place. One phished login with no MFA hands all of it over, and triggers the reporting clocks in every state your clients live in.
Ransomware, Then the Certification Problem
Encrypted systems stop quoting, binding, and servicing. Then comes the second act: the 72 hour report, carrier notifications, and the awkward question of what last year’s compliance certification claimed. Tested, isolated backups and a written response plan turn a career event into a bad week.
What Well Run Agency IT Looks Like
Whoever manages your agency’s technology, this is the baseline worth reviewing together. Every item maps to a rule or an attack above.
MFA on Everything
Email, the AMS, carrier portals, and remote access, every account, every producer, no exceptions. It’s the single control regulators name and attackers test first.
Written Verification Procedures
Payment instructions, banking changes, and beneficiary updates confirmed by phone at a known number before anything moves. Written, trained, and followed on the busy days too.
A Program on Paper
Risk assessment, policies, training records, and an incident response plan documented and current, so the annual certification describes reality and the 72 hour clock is survivable.
Impersonation Resistant Email
Advanced phishing protection tuned for client and carrier impersonation, plus enforced SPF, DKIM, and DMARC so criminals can’t send as your agency.
Backups That Survive
Daily backups of the AMS, documents, and email with one copy ransomware can’t reach, restore tested and timed, because quoting stops when systems do.
Monitoring and Same Day Offboarding
Systems watched around the clock, and departing producers and staff losing every access the day they leave, with documentation to prove it.
Common Questions
Do insurance agencies have cybersecurity regulations?
Yes. New York’s Department of Financial Services cybersecurity regulation applies to insurance agents, brokers, and agencies licensed in New York, requiring a cybersecurity program, multifactor authentication, incident reporting on a 72 hour clock, and annual certification. Many other states have adopted versions of the NAIC Insurance Data Security Model Law with similar written program and commissioner notification requirements, and federal safeguards expectations apply as well.
Why do criminals target insurance agencies?
Agency files and management systems hold complete client profiles: Social Security numbers, driver’s licenses, financial details, property information, and for benefits brokers, health information. Agencies also sit in the middle of premium payments and claims payouts, which gives attackers both identities to steal and money flows to redirect.
What does a 72 hour reporting requirement actually mean?
Under New York’s DFS regulation, covered entities must notify the regulator within 72 hours of determining a qualifying cybersecurity event occurred. That clock is only manageable if detection, an incident response plan, and contact procedures exist before the incident. Agencies that discover a breach weeks late have already failed the requirement.
Our agency is small. Do these rules still apply?
Generally yes, though smaller agencies may qualify for limited exemptions from some provisions. Core expectations like protecting nonpublic information, MFA, and incident reporting still apply, and carriers increasingly require security measures from their appointed agencies regardless of size.
What is in the free insurance agency technology guide?
A six page plain English guide covering your regulatory obligations, the attack patterns that hit agencies most, an agency security baseline checklist, the 72 hour readiness question, and the questions principals should ask about their IT.
Start With the Guide. Decide From There.
Download the Insurance Agency Technology Guide and review the baseline with whoever runs your IT. If you’d rather have the answers verified for you, a free confidential security assessment for your agency is available too.