Public beta — features are evolving and AI-generated outputs may contain errors. Not legal, regulatory or compliance advice. Review before relying on any output. Share feedback
All starter packs

Insurance starter pack

Three example forms an insurance carrier commonly maintains under the NAIC Insurance Data Security Model Law and NY DFS 23 NYCRR Part 500.

Example company: Summit Mutual Insurance Co. (US, P&C, 4 states, 410 employees)

Educational examples only. Fictional data; not legal, regulatory or compliance advice.

Insurance Data Security Model Law
NAIC Model #668

NAIC Information Security Program Summary

Summary of the licensee's written information security program, including risk assessment, controls and third-party oversight.

Regulator
State insurance commissioners · Adopting US states (e.g. CT, DE, OH, SC, VA)
Frequency
Maintained continuously; annual board report

Program profile

Licensee
Summit Mutual Insurance Co.
Designated information security lead
R. Patel, VP Information Security
States where licensed
CT, DE, OH, VA
Last risk assessment date
November 2025

Controls in place

Access management
MFA on all remote access and privileged accounts; quarterly access review; immediate revocation on separation.
Encryption
All NPI encrypted at rest (AES-256) and in transit (TLS 1.2+); key management via HSM.
Vendor oversight
Risk-tiered TPRM with SOC 2 / ISO 27001 evidence reviewed at onboarding and annually for tier-1 vendors.
Workforce training
Annual security awareness training with monthly phishing simulations; 96% completion in 2025.

Board reporting

Most recent board report
February 11, 2026
Topics covered
Overall program status, risk assessment outcomes, material events, recommendations for changes.
↳ Cited: NAIC Model #668 §4F
Reviewer notes

Illustrative summary. The Model Law has been adopted with variations in different states — confirm the specific elements required by each state where you are licensed.

NY DFS Cybersecurity Regulation
23 NYCRR § 500.17(b)

23 NYCRR Part 500 Certification of Material Compliance

Annual certification or acknowledgement filed by covered entities concerning material compliance with Part 500.

Regulator
New York State Department of Financial Services · New York
Frequency
Annual (by April 15)

Filing entity

Covered entity
Summit Mutual Insurance Co.
NY DFS license number(s)
NY-XXXXXX
Filing type
Certification of Material Compliance
Period covered
January 1 – December 31, 2025

Certification

Statement
The undersigned certify that, to the best of their knowledge after reasonable inquiry, Summit Mutual Insurance Co. materially complied with the requirements of 23 NYCRR Part 500 for the period above. This certification is based on documentation including the cybersecurity risk assessment dated 2025-11-04, internal and external audit reports, and the report of the CISO to the Board.
↳ Cited: 23 NYCRR § 500.17(b)(1)(i)
Signatories
R. Patel, CISO; L. Chen, Chair of the Board.

Supporting documentation retained

Risk assessment
2025 Cybersecurity Risk Assessment, dated 2025-11-04
Penetration test
External pen test report, dated 2025-09-22
Vulnerability scans
Bi-weekly scans throughout 2025; remediation tickets closed
Incident log
No reportable cybersecurity events under § 500.17(a) in 2025
Reviewer notes

Sample text. Where material compliance cannot be certified, file an Acknowledgement of Noncompliance per § 500.17(b)(1)(ii) with a remediation plan and timeline.

NY DFS / NAIC Data Security
23 NYCRR § 500.17(a) / NAIC §6

Cybersecurity Event Notice (72-hour)

Initial notice to the regulator following determination that a reportable cybersecurity event has occurred.

Regulator
NY DFS / state insurance commissioner · United States
Frequency
Within 72 hours of determination

Reporting entity

Entity
Summit Mutual Insurance Co.
Primary contact
R. Patel, CISO — r.patel@example.com
Date of determination
May 6, 2026, 09:14 ET

Event details

Date / time event began
On or about May 4, 2026, 22:30 ET
Date discovered
May 5, 2026
Description
Unauthorised access to a claims processing application via compromised vendor credentials. Threat actor accessed claim files for approximately 7,400 policyholders before access was revoked.
Consumer information involved
Name, address, policy number, claim details; no SSN or financial account numbers.

Response status

Containment
Vendor credentials revoked; vendor's access path disabled; MFA enforced on all vendor accounts; forensic investigation engaged with Mandiant.
Consumer notice plan
Direct notice to affected policyholders within 60 days; substitute notice on website; toll-free hotline with credit monitoring offer.
Next update
Supplemental report to be filed within 7 days, then weekly until investigation closed.
Reviewer notes

Sample only. Specific reporting thresholds, fields and timelines vary between NY DFS and individual NAIC-adopting states; check each jurisdiction's portal and form requirements.

Want forms tailored to your business?

The free AI assessment maps these requirements to your industry, region and data profile.