Insurance Cybersecurity Failures Lead to More Than $21 Million in Regulatory Penalties
- John Blackshire
- 15 hours ago
- 6 min read
Cybersecurity requirements for insurance organizations are no longer theoretical.
Recent enforcement actions demonstrate that state regulators are prepared to impose substantial financial penalties when insurers fail to protect nonpublic information, maintain effective cybersecurity controls, or report cybersecurity events promptly.
Between October 2025 and April 2026, the New York State Department of Financial Services imposed more than $21 million in cybersecurity penalties against ten insurance entities.
These enforcement actions provide an important warning for insurance companies, agencies, brokers, third-party administrators, and other organizations licensed by state insurance departments: having cybersecurity policies on paper is not enough.
Regulators expect organizations to demonstrate that their information security programs are properly designed, implemented, monitored, and improved.
Eight Insurance Organizations Fined More Than $19 Million
On October 14, 2025, the New York State Department of Financial Services announced cybersecurity settlements totaling more than $19 million with eight automobile insurance organizations:
Farmers Insurance Exchange — $2.775 million
Hagerty Insurance Agency, LLC — $1.85 million
Hartford Fire Insurance Company — $3 million
Infinity Insurance Company — $2.25 million
Liberty Mutual Insurance Company — $2.7 million
Metromile Insurance Company — $2.05 million
Midvale Indemnity Company — $2 million
State Automobile Mutual Insurance Company — $2.5 million
According to the Department, inadequate cybersecurity controls allowed threat actors to obtain nonpublic consumer information through online automobile insurance quoting applications and agent portals.
The exposed information included driver’s-license numbers and dates of birth. The Department also found that Farmers and Infinity failed to report their respective cybersecurity events promptly.
The eight organizations agreed to pay civil monetary penalties totaling approximately $19.125 million and undertake corrective actions, including comprehensive reviews of how consumer nonpublic information could be accessed through their information systems.
Delta Dental Fined $2.25 Million
On April 30, 2026, the New York State Department of Financial Services announced a separate $2.25 million cybersecurity settlement with Delta Dental Insurance Company and Delta Dental of New York.
The companies used MOVEit Transfer servers to exchange files among affiliates, customers, business partners, medical professionals, and employees. In 2023, threat actors exploited a previously unknown vulnerability in the MOVEit software and obtained unauthorized access to files containing sensitive consumer information.
The compromised information included:
Names and addresses
Social Security numbers
Driver’s-license numbers
Financial-account information
Patient health information
The Department found that the companies’ cybersecurity program did not comply with regulatory requirements governing retention settings, policies, procedures, internal controls, incident response, and protection of consumer information.
The Department also concluded that the companies failed to report their cybersecurity events promptly.
The Enforcement Message Is Clear
These enforcement actions were brought under New York’s cybersecurity regulation, 23 NYCRR Part 500, rather than a state law specifically identified as an adoption of the NAIC Insurance Data Security Model Law.
That distinction is legally important, but it should not distract insurance organizations from the broader compliance message. New York’s cybersecurity regulation and the NAIC Insurance Data Security Model Law contain many similar control expectations.
Both regulatory approaches emphasize the need for organizations to:
Maintain a risk-based information security program.
Conduct cybersecurity risk assessments.
Protect nonpublic information.
Establish appropriate administrative, technical, and physical safeguards.
Manage cybersecurity risks arising from third-party service providers.
Develop and maintain incident-response procedures.
Investigate cybersecurity events.
notify regulators within the required period.
Provide effective board and senior-management oversight.
Document the organization’s compliance activities.
The failures identified in the recent enforcement actions are exactly the types of weaknesses these requirements are intended to prevent.
Cybersecurity Compliance Is an Internal-Control Responsibility
Insurance organizations sometimes treat cybersecurity as a technical function owned exclusively by the chief information officer or information technology department. That approach is inadequate.
Cybersecurity is an enterprise internal-control responsibility involving:
The board of directors
Executive management
Information technology
Information security
Legal counsel
Compliance
Risk management
Internal audit
Privacy personnel
Business-process owners
Vendor-management personnel
Human resources
Crisis-communications professionals
Technical personnel may configure systems and security tools, but management remains responsible for the effectiveness of the organization’s controls.
The board must provide oversight. Management must establish expectations, assign responsibilities, provide resources, monitor results, and correct identified deficiencies. Internal audit should independently evaluate whether the program is designed appropriately and operating effectively.
Public-Facing Applications Create Significant Exposure
The October 2025 automobile insurance cases demonstrate the risks associated with public-facing applications.
Online quoting systems, customer portals, agent portals, mobile applications, and application programming interfaces can provide convenient services to customers and business partners. They can also provide attackers with an entry point into an organization’s information systems.
Insurance organizations should determine:
What nonpublic information is accessible through each application?
Is access to sensitive information necessary for the business process?
Are authentication and authorization controls appropriate?
Have application security tests identified significant vulnerabilities?
Are failed access attempts and unusual activities monitored?
Are system logs complete, protected, and reviewed?
Are software vulnerabilities remediated promptly?
Can unauthorized users extract large quantities of information?
Do third-party developers follow secure development practices?
Has management evaluated the application’s residual cyber risk?
Organizations should not wait for a cybersecurity event to discover that a quoting tool or customer portal provides unnecessary access to sensitive information.
Incident Reporting Is a Compliance Control
Several of the penalized organizations were cited for failing to report cybersecurity events promptly.
Cybersecurity-event notification should not depend on an improvised decision made during a crisis. Organizations need documented procedures that specify:
What constitutes a reportable cybersecurity event?
Who evaluates whether reporting is required?
Which regulators must be notified?
What reporting deadlines apply?
Who has authority to submit the notification?
What information must be included?
How will incomplete information be addressed?
How will management document its decision?
Who monitors subsequent reporting obligations?
A technically effective response can still result in a regulatory violation if the organization does not meet its reporting obligations.
Third-Party Software Does Not Transfer Accountability
The Delta Dental enforcement action also highlights the risk associated with third-party technology.
Insurance organizations depend on software vendors, cloud-service providers, claims processors, data centers, payment processors, professional firms, and other outside parties. These relationships can expose nonpublic information to risks that management does not directly control.
Outsourcing a service does not outsource accountability.
A mature third-party cybersecurity program should include:
Risk-based vendor classification
Cybersecurity due diligence
Contractual security requirements
Defined incident-notification obligations
Restrictions on subcontractors
Data-retention and destruction requirements
Access-control requirements
Independent assurance reports
Vulnerability and patch-management expectations
Continuing monitoring
Documented termination procedures
Management should know which vendors hold sensitive information, where that information is stored, how long it is retained, and what happens when the vendor experiences a cybersecurity event.
Questions Boards and Audit Committees Should Ask
Board members and audit committees do not need to become cybersecurity engineers.
They do, however, need to ask informed questions and challenge incomplete answers.
Important oversight questions include:
What are the organization’s most significant cybersecurity risks?
What categories of nonpublic information do we collect, process, transmit, and retain?
Which public-facing systems provide access to that information?
When was the last formal cybersecurity risk assessment completed?
Have all high-risk deficiencies been corrected?
Which third parties have access to sensitive information?
How does management monitor the cybersecurity controls of those providers?
Has the incident-response plan been tested through a tabletop exercise?
Are regulatory-notification requirements documented by state?
Has internal audit independently evaluated the information security program?
What cybersecurity information is reported to the board?
Can management support its annual compliance certification with reliable evidence?
The board should not accept “we have not experienced a significant breach” as evidence that the cybersecurity program is effective.
Internal Audit’s Role
Internal audit can help the board and management determine whether the cybersecurity program is producing the intended results.
A cybersecurity audit should go beyond verifying that policies exist. Auditors should evaluate whether:
The cybersecurity risk assessment is complete and current.
Controls address the organization’s significant risks.
Responsibility for each control has been assigned.
Controls have been implemented consistently.
Cybersecurity events are identified and escalated promptly.
Third-party providers are assessed and monitored.
Identified vulnerabilities are remediated within defined periods.
Board reporting is accurate and complete.
Annual certifications are supported by sufficient evidence.
Management tests and continually improves the program.
Internal audit should distinguish between control design effectiveness and control operating effectiveness. A properly written policy is only a designed control. The organization must also demonstrate that personnel consistently perform the required activities.
Learn How to Strengthen an Insurance Cybersecurity Program
The recent penalties show what can happen when cybersecurity governance, internal controls, incident response, and regulatory reporting fail.
Insurance and cybersecurity professionals can examine these responsibilities in greater depth during Corporate Compliance Seminars’ NAIC Cybersecurity Model Law Academy, presented as a live webinar on Wednesday and Thursday, September 30–October 1, 2026.
This two-day program provides 12 CPE credits and addresses:
The goals and requirements of the NAIC Insurance Data Security Model Law
The definition and protection of nonpublic information
Cybersecurity risk assessments
Information security program requirements
Board oversight
Third-party service-provider controls
Continuous monitoring
Incident-response planning
Cybersecurity-event reporting
Annual certification requirements
Cybersecurity maturity assessments
Comparison with New York’s cybersecurity regulation
SOC for Cybersecurity concepts
The program is appropriate for insurance executives, auditors, compliance officers, risk managers, cybersecurity professionals, IT managers, board members, and other professionals responsible for protecting insurance information.
The Bottom Line
State regulators are demonstrating that cybersecurity violations can result in multimillion-dollar penalties. The underlying problems are not limited to sophisticated technical failures. Regulators are identifying basic control weaknesses involving data access, incident response, regulatory reporting, third-party systems, governance, and accountability.
Insurance organizations should not wait for a breach or regulatory investigation to evaluate their cybersecurity programs.
Management should assess the risks now, test the controls now, correct the deficiencies now, and make certain that the organization can prove—not merely assert—that its nonpublic information is adequately protected.
Comments