top of page
Search

Insurance Cybersecurity Failures Lead to More Than $21 Million in Regulatory Penalties

Cybersecurity requirements for insurance organizations are no longer theoretical.


Recent enforcement actions demonstrate that state regulators are prepared to impose substantial financial penalties when insurers fail to protect nonpublic information, maintain effective cybersecurity controls, or report cybersecurity events promptly.


Between October 2025 and April 2026, the New York State Department of Financial Services imposed more than $21 million in cybersecurity penalties against ten insurance entities.


These enforcement actions provide an important warning for insurance companies, agencies, brokers, third-party administrators, and other organizations licensed by state insurance departments: having cybersecurity policies on paper is not enough.


Regulators expect organizations to demonstrate that their information security programs are properly designed, implemented, monitored, and improved.


Eight Insurance Organizations Fined More Than $19 Million

On October 14, 2025, the New York State Department of Financial Services announced cybersecurity settlements totaling more than $19 million with eight automobile insurance organizations:

  • Farmers Insurance Exchange — $2.775 million

  • Hagerty Insurance Agency, LLC — $1.85 million

  • Hartford Fire Insurance Company — $3 million

  • Infinity Insurance Company — $2.25 million

  • Liberty Mutual Insurance Company — $2.7 million

  • Metromile Insurance Company — $2.05 million

  • Midvale Indemnity Company — $2 million

  • State Automobile Mutual Insurance Company — $2.5 million


According to the Department, inadequate cybersecurity controls allowed threat actors to obtain nonpublic consumer information through online automobile insurance quoting applications and agent portals.


The exposed information included driver’s-license numbers and dates of birth. The Department also found that Farmers and Infinity failed to report their respective cybersecurity events promptly.


The eight organizations agreed to pay civil monetary penalties totaling approximately $19.125 million and undertake corrective actions, including comprehensive reviews of how consumer nonpublic information could be accessed through their information systems.



Delta Dental Fined $2.25 Million

On April 30, 2026, the New York State Department of Financial Services announced a separate $2.25 million cybersecurity settlement with Delta Dental Insurance Company and Delta Dental of New York.


The companies used MOVEit Transfer servers to exchange files among affiliates, customers, business partners, medical professionals, and employees. In 2023, threat actors exploited a previously unknown vulnerability in the MOVEit software and obtained unauthorized access to files containing sensitive consumer information.


The compromised information included:

  • Names and addresses

  • Social Security numbers

  • Driver’s-license numbers

  • Financial-account information

  • Patient health information


The Department found that the companies’ cybersecurity program did not comply with regulatory requirements governing retention settings, policies, procedures, internal controls, incident response, and protection of consumer information.


The Department also concluded that the companies failed to report their cybersecurity events promptly.



The Enforcement Message Is Clear

These enforcement actions were brought under New York’s cybersecurity regulation, 23 NYCRR Part 500, rather than a state law specifically identified as an adoption of the NAIC Insurance Data Security Model Law.


That distinction is legally important, but it should not distract insurance organizations from the broader compliance message. New York’s cybersecurity regulation and the NAIC Insurance Data Security Model Law contain many similar control expectations.


Both regulatory approaches emphasize the need for organizations to:

  • Maintain a risk-based information security program.

  • Conduct cybersecurity risk assessments.

  • Protect nonpublic information.

  • Establish appropriate administrative, technical, and physical safeguards.

  • Manage cybersecurity risks arising from third-party service providers.

  • Develop and maintain incident-response procedures.

  • Investigate cybersecurity events.

  • notify regulators within the required period.

  • Provide effective board and senior-management oversight.

  • Document the organization’s compliance activities.


The failures identified in the recent enforcement actions are exactly the types of weaknesses these requirements are intended to prevent.


Cybersecurity Compliance Is an Internal-Control Responsibility

Insurance organizations sometimes treat cybersecurity as a technical function owned exclusively by the chief information officer or information technology department. That approach is inadequate.


Cybersecurity is an enterprise internal-control responsibility involving:

  • The board of directors

  • Executive management

  • Information technology

  • Information security

  • Legal counsel

  • Compliance

  • Risk management

  • Internal audit

  • Privacy personnel

  • Business-process owners

  • Vendor-management personnel

  • Human resources

  • Crisis-communications professionals


Technical personnel may configure systems and security tools, but management remains responsible for the effectiveness of the organization’s controls.


The board must provide oversight. Management must establish expectations, assign responsibilities, provide resources, monitor results, and correct identified deficiencies. Internal audit should independently evaluate whether the program is designed appropriately and operating effectively.


Public-Facing Applications Create Significant Exposure

The October 2025 automobile insurance cases demonstrate the risks associated with public-facing applications.


Online quoting systems, customer portals, agent portals, mobile applications, and application programming interfaces can provide convenient services to customers and business partners. They can also provide attackers with an entry point into an organization’s information systems.


Insurance organizations should determine:

  • What nonpublic information is accessible through each application?

  • Is access to sensitive information necessary for the business process?

  • Are authentication and authorization controls appropriate?

  • Have application security tests identified significant vulnerabilities?

  • Are failed access attempts and unusual activities monitored?

  • Are system logs complete, protected, and reviewed?

  • Are software vulnerabilities remediated promptly?

  • Can unauthorized users extract large quantities of information?

  • Do third-party developers follow secure development practices?

  • Has management evaluated the application’s residual cyber risk?


Organizations should not wait for a cybersecurity event to discover that a quoting tool or customer portal provides unnecessary access to sensitive information.


Incident Reporting Is a Compliance Control

Several of the penalized organizations were cited for failing to report cybersecurity events promptly.


Cybersecurity-event notification should not depend on an improvised decision made during a crisis. Organizations need documented procedures that specify:

  • What constitutes a reportable cybersecurity event?

  • Who evaluates whether reporting is required?

  • Which regulators must be notified?

  • What reporting deadlines apply?

  • Who has authority to submit the notification?

  • What information must be included?

  • How will incomplete information be addressed?

  • How will management document its decision?

  • Who monitors subsequent reporting obligations?


A technically effective response can still result in a regulatory violation if the organization does not meet its reporting obligations.


Third-Party Software Does Not Transfer Accountability

The Delta Dental enforcement action also highlights the risk associated with third-party technology.


Insurance organizations depend on software vendors, cloud-service providers, claims processors, data centers, payment processors, professional firms, and other outside parties. These relationships can expose nonpublic information to risks that management does not directly control.


Outsourcing a service does not outsource accountability.


A mature third-party cybersecurity program should include:

  • Risk-based vendor classification

  • Cybersecurity due diligence

  • Contractual security requirements

  • Defined incident-notification obligations

  • Restrictions on subcontractors

  • Data-retention and destruction requirements

  • Access-control requirements

  • Independent assurance reports

  • Vulnerability and patch-management expectations

  • Continuing monitoring

  • Documented termination procedures


Management should know which vendors hold sensitive information, where that information is stored, how long it is retained, and what happens when the vendor experiences a cybersecurity event.


Questions Boards and Audit Committees Should Ask

Board members and audit committees do not need to become cybersecurity engineers.


They do, however, need to ask informed questions and challenge incomplete answers.


Important oversight questions include:

  1. What are the organization’s most significant cybersecurity risks?

  2. What categories of nonpublic information do we collect, process, transmit, and retain?

  3. Which public-facing systems provide access to that information?

  4. When was the last formal cybersecurity risk assessment completed?

  5. Have all high-risk deficiencies been corrected?

  6. Which third parties have access to sensitive information?

  7. How does management monitor the cybersecurity controls of those providers?

  8. Has the incident-response plan been tested through a tabletop exercise?

  9. Are regulatory-notification requirements documented by state?

  10. Has internal audit independently evaluated the information security program?

  11. What cybersecurity information is reported to the board?

  12. Can management support its annual compliance certification with reliable evidence?


The board should not accept “we have not experienced a significant breach” as evidence that the cybersecurity program is effective.


Internal Audit’s Role

Internal audit can help the board and management determine whether the cybersecurity program is producing the intended results.


A cybersecurity audit should go beyond verifying that policies exist. Auditors should evaluate whether:

  • The cybersecurity risk assessment is complete and current.

  • Controls address the organization’s significant risks.

  • Responsibility for each control has been assigned.

  • Controls have been implemented consistently.

  • Cybersecurity events are identified and escalated promptly.

  • Third-party providers are assessed and monitored.

  • Identified vulnerabilities are remediated within defined periods.

  • Board reporting is accurate and complete.

  • Annual certifications are supported by sufficient evidence.

  • Management tests and continually improves the program.


Internal audit should distinguish between control design effectiveness and control operating effectiveness. A properly written policy is only a designed control. The organization must also demonstrate that personnel consistently perform the required activities.


Learn How to Strengthen an Insurance Cybersecurity Program

The recent penalties show what can happen when cybersecurity governance, internal controls, incident response, and regulatory reporting fail.


Insurance and cybersecurity professionals can examine these responsibilities in greater depth during Corporate Compliance Seminars’ NAIC Cybersecurity Model Law Academy, presented as a live webinar on Wednesday and Thursday, September 30–October 1, 2026.


This two-day program provides 12 CPE credits and addresses:

  • The goals and requirements of the NAIC Insurance Data Security Model Law

  • The definition and protection of nonpublic information

  • Cybersecurity risk assessments

  • Information security program requirements

  • Board oversight

  • Third-party service-provider controls

  • Continuous monitoring

  • Incident-response planning

  • Cybersecurity-event reporting

  • Annual certification requirements

  • Cybersecurity maturity assessments

  • Comparison with New York’s cybersecurity regulation

  • SOC for Cybersecurity concepts


The program is appropriate for insurance executives, auditors, compliance officers, risk managers, cybersecurity professionals, IT managers, board members, and other professionals responsible for protecting insurance information.



The Bottom Line

State regulators are demonstrating that cybersecurity violations can result in multimillion-dollar penalties. The underlying problems are not limited to sophisticated technical failures. Regulators are identifying basic control weaknesses involving data access, incident response, regulatory reporting, third-party systems, governance, and accountability.


Insurance organizations should not wait for a breach or regulatory investigation to evaluate their cybersecurity programs.


Management should assess the risks now, test the controls now, correct the deficiencies now, and make certain that the organization can prove—not merely assert—that its nonpublic information is adequately protected.

 
 
 

Recent Posts

See All
How Arizona CPAs Actually Get in Trouble

Lessons From the Arizona State Board of Accountancy Most CPAs do not begin their careers expecting to face professional discipline. They pass the CPA examination. They satisfy experience requirements.

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page