Insurance
NAIC, state regulators, and cyber underwriting requirements
Insurance companies face regulatory requirements from state insurance commissioners, NAIC model laws, and increasing cyber underwriting standards. Thalorin helps insurers maintain compliance across jurisdictions while supporting the security evidence required for cyber insurance underwriting.
Insurance cybersecurity regulation is state-based, which means the compliance question is not what the rule requires but how many versions of it you are subject to. The NAIC Insurance Data Security Model Law provides the template — risk assessment, written information security programme, incident response plan, third-party oversight, and notification to the commissioner — but each adopting state enacts its own variant, with its own notification window and its own exemption thresholds.
New York remains the strictest and most influential. NYDFS Part 500, substantially amended in November 2023 and phased in through November 2025, imposes obligations that go beyond the NAIC model: multi-factor authentication across all systems, annual certification of compliance signed by the highest-ranking executive and the CISO, expanded governance duties, and asset inventory requirements. Insurers licensed in New York generally build to Part 500 and treat it as the ceiling other states fall under.
Insurers also sit on both sides of cyber risk. The same organisation that must demonstrate its own security posture is underwriting cyber policies whose pricing depends on assessing someone else's — and increasingly, on evidence rather than questionnaires.
Thalorin maintains one control state and projects it into each state's requirements, so the multi-jurisdiction question becomes which obligations a given control already satisfies rather than which programme to run next.
Financial institutions operate under intense scrutiny
One model law, many state variants
The NAIC model is adopted with state-specific modifications to notification windows, exemption thresholds, and certification duties. Multi-state insurers track a matrix, not a rule.
NYDFS Part 500 sets the real bar
The 2023 amendments phased through November 2025 added MFA across all systems, expanded governance, asset inventory, and executive-signed annual certification. Compliance built to the NAIC model alone falls short in New York.
Certification carries personal exposure
Annual certification signed by senior leadership converts a compliance gap into an attestation problem. Signing officers increasingly want evidence, not assurances.
Underwriting cyber while being cyber-regulated
Insurers must evidence their own posture and evaluate insureds' postures. The two functions rarely share tooling, and neither benefits from the separation.
How Thalorin helps
NAIC model law compliance
Track NAIC Insurance Data Security Model Law obligations as adopted, per state, rather than as a single generic standard.
Multi-state regulatory tracking
Maintain a multi-state regulatory matrix so notification windows and exemption thresholds are visible per jurisdiction.
Cyber underwriting evidence
Produce security evidence in a form usable for cyber underwriting decisions rather than as questionnaire responses.
Privacy regulation compliance
Carry privacy obligations alongside security ones, including state insurance privacy requirements.
Third-party data protection
Manage third-party data protection duties, including the vendor oversight the model law requires.
Claims system security
Evidence claims system security as part of the broader control state rather than as a separate audit.
Insurance: common questions
Which states have adopted the NAIC Insurance Data Security Model Law?
A substantial majority of states have adopted some version, but the adoptions differ — notification timelines, exemption thresholds for small insurers, and certification requirements all vary by state. Treating the model law as a single uniform standard is the most common multi-state compliance error, because the obligation you are actually held to is the enacted state statute.
Does NYDFS Part 500 apply if we are not headquartered in New York?
It applies to entities operating under a New York banking, insurance, or financial services licence, regardless of where they are headquartered. Many insurers licensed in New York find Part 500 becomes their de facto enterprise standard, because building two postures is more expensive than building to the stricter one.
What did the 2023 Part 500 amendments change?
They expanded governance obligations, required multi-factor authentication across all systems rather than for remote access alone, added asset inventory requirements, strengthened incident response and business continuity duties, and revised the annual certification to be signed by the highest-ranking executive and the CISO. The requirements phased in through November 2025.
Can our security evidence support cyber underwriting?
It should. The evidence an insurer collects to demonstrate its own controls — access management, patching cadence, backup integrity, incident response testing — is structurally the same evidence underwriters increasingly want from insureds. Holding it in a queryable form serves both, which is why keeping the two functions on separate tooling is usually an accident rather than a decision.
How does this interact with state privacy laws?
Insurance data security statutes govern safeguards and breach notification; state consumer privacy laws govern collection, use, and consumer rights, and many exempt data already regulated under GLBA or insurance statutes. The exemptions are partial and vary, so multi-state insurers generally map both and identify where an exemption genuinely applies rather than assuming it does.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Insurance.
See how one evidence artifact satisfies Insurance requirements alongside every other framework you carry.