The National Association of Insurance Commissioners (NAIC) Data Security Law (Model Law) requires insurers and other entities licensed by state insurance departments to develop, implement, and maintain an information security program; investigate any cybersecurity events; and notify the state insurance commissioner of such events. The NAIC model law provides a blueprint for state-level laws regulating insurance companies. The main recommendations of the law include:
The law applies to licensees of each state insurance bureau. This includes (with some exceptions) insurance industry companies, agencies, agents, public adjusters, and brokers.
The National Association of Insurance Commissioners officially adopted the Data Security Law in the fourth quarter of 2017. As of May 2023, 22 states have enacted versions of the law: Alabama, Alaska, Connecticut, Delaware, Hawaii, Indiana, Iowa, Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi, New Hampshire, North Dakota, Ohio, South Carolina, Tennessee, Vermont, Virginia, and Wisconsin.
The suggested penalties for non-compliance with the NAIC Data Security Law are up to $500 per violation (subject to a maximum of $10,000). If the insurer/producer violates the commissioner’s cease and desist order, suggested penalties are up to $10,000 per violation (subject to a maximum of $50,000). Individuals at those institutions can be fined up to $10,000 for each violation and may also be sentenced to up to five years in prison.
Thales’ solutions can help insurance providers comply with NAIC Data Security Law by simplifying compliance and automating security, reducing the burden on security and compliance teams. We help address essential requirements for risk management in an organization’s NAIC-mandated Information Security Program.
We provide comprehensive cyber security solutions in three key areas of cybersecurity: Application Security, Data Security, and Identity & Access Management.
Protect applications and APIs at scale in the cloud, on-premises, or in a hybrid model. Our market leading product suite includes Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) and malicious BOT attacks, security for APIs, a secure Content Delivery Network (CDN), and Runtime Application Self-Protection (RASP).
Discover and classify sensitive data across hybrid IT and automatically protect it anywhere, whether at rest, in motion, or in use, using encryption tokenization and key management. Thales solutions also identify, evaluate, and prioritize potential risks for accurate risk assessment as well as identify anomalous behavior, and monitor activity to verify compliance, allowing organizations to prioritize where to spend their efforts.
Provide seamless, secure and trusted access to applications and digital services for customers, employees and partners. Our solutions limit the access of internal and external users based on their roles and context with granular access policies and Multi-Factor Authentication that help ensure that the right user is granted access to the right resource at the right time.
Data Security
Identity & Access Management
Application Security
Data Security
Identity & Access Management
Application Security
Data Security
Identity & Access Management