top of page
Search

Insurance Cybersecurity Failures Result in More Than $21 Million in Penalties

Recent enforcement actions demonstrate that cybersecurity compliance is a serious financial and regulatory concern for insurance organizations.


Between October 2025 and April 2026, the New York State Department of Financial Services imposed more than $21 million in penalties against ten insurance entities for cybersecurity control failures.


Eight Insurance Organizations Fined More Than $19 Million

On October 14, 2025, the Department announced settlements with eight automobile insurance organizations:

  • Farmers Insurance Exchange — $2.775 million

  • Hagerty Insurance Agency, LLC — $1.85 million

  • Hartford Fire Insurance Company — $3 million

  • Infinity Insurance Company — $2.25 million

  • Liberty Mutual Insurance Company — $2.7 million

  • Metromile Insurance Company — $2.05 million

  • Midvale Indemnity Company — $2 million

  • State Automobile Mutual Insurance Company — $2.5 million


According to the Department, weaknesses in the organizations’ cybersecurity controls allowed attackers to obtain driver’s-license numbers, dates of birth, and other consumer information through public-facing automobile insurance quoting applications and agent portals.


Farmers and Infinity were also cited for failing to report their cybersecurity events promptly.


In addition to paying approximately $19.125 million in penalties, the organizations agreed to take corrective actions, including reviewing how consumer nonpublic information could be accessed through their systems.



Delta Dental Assessed a $2.25 Million Penalty

On April 30, 2026, the Department announced a separate $2.25 million settlement with


Delta Dental Insurance Company and Delta Dental of New York.


Attackers exploited a vulnerability in the companies’ MOVEit Transfer software and obtained access to files containing:

  • Social Security numbers

  • Driver’s-license numbers

  • Financial-account information

  • Patient health information

  • Names and addresses


The Department identified deficiencies involving incident-response policies, data-retention settings, security controls, and regulatory reporting. The companies were also cited for failing to report their cybersecurity events promptly.



What These Enforcement Actions Mean for Insurance Organizations

These cases were enforced under New York’s cybersecurity regulation, 23 NYCRR Part 500, rather than a state law specifically identified as an adoption of the NAIC Insurance Data Security Model Law. However, the regulatory expectations overlap significantly.

Insurance organizations are expected to:

  • Maintain a risk-based information security program.

  • Protect consumer nonpublic information.

  • Conduct periodic cybersecurity risk assessments.

  • Implement effective administrative, technical, and physical controls.

  • Manage third-party cybersecurity risks.

  • Maintain and test an incident-response plan.

  • Investigate and report cybersecurity events promptly.

  • Provide meaningful board and senior-management oversight.

  • Support annual compliance certifications with reliable evidence.


Cybersecurity cannot be treated solely as an IT responsibility. It is also a governance, compliance, risk-management, and internal-control responsibility.


Questions Management and the Board Should Ask

Insurance executives, board members, audit committees, and internal auditors should consider the following questions:

  1. What nonpublic information does the organization collect and retain?

  2. Which public-facing applications provide access to that information?

  3. When was the last cybersecurity risk assessment completed?

  4. Have all significant vulnerabilities been corrected?

  5. Which third-party providers have access to sensitive information?

  6. Has the incident-response plan been tested?

  7. Are state notification requirements documented?

  8. Can management support its annual cybersecurity certification?

  9. Has internal audit evaluated the design and operating effectiveness of the cybersecurity controls?


The absence of a known breach does not prove that an information security program is effective.


Learn How to Strengthen Your Cybersecurity Compliance Program

Corporate Compliance Seminars will present the NAIC Cybersecurity Model Law Academy on Wednesday and Thursday, September 30–October 1, 2026.


This live, interactive webinar provides 12 CPE credits and addresses:

  • NAIC Insurance Data Security Model Law requirements

  • Cybersecurity risk assessments

  • Information security programs

  • Protection of nonpublic information

  • Board oversight responsibilities

  • Third-party service-provider controls

  • Incident-response planning

  • Cybersecurity-event reporting

  • Continuous monitoring

  • Annual certification requirements

  • Cybersecurity maturity assessments

  • Comparison with New York’s cybersecurity regulation

  • SOC for Cybersecurity concepts


The academy is designed for insurance executives, auditors, compliance officers, risk managers, cybersecurity professionals, information technology managers, board members, and other professionals responsible for protecting insurance information.


The recent penalties send a direct message: cybersecurity policies are not enough. Insurance organizations must be able to demonstrate that their controls are properly designed, consistently performed, monitored, tested, and improved.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page