NAIC Cybersecurity Model Law Academy: Build a Stronger Insurance Information Security Program
Cybersecurity is no longer solely an information technology concern. For insurance organizations, it is a regulatory, governance, operational, and enterprise-risk responsibility.
CCS will present the NAIC Cybersecurity Model Law Academy as a live, interactive webinar on Wednesday and Thursday, September 30–October 1, 2026. This comprehensive two-day program provides insurance, compliance, audit, risk, and information technology professionals with practical guidance for implementing and assessing an effective information security program under the NAIC Insurance Data Security Model Law.
Participants who complete the program can earn 12 CPE credits.
Event Details
Dates: Wednesday–Thursday, September 30–October 1, 2026
Time: 9:00 a.m.–3:00 p.m. Central Time each day
Lunch break: Noon–12:30 p.m. Central Time
Delivery method: Live, Group Internet Based webinar
CPE credits: 12
Fields of study: Auditing and Information Technology
Program level: Basic
Prerequisites: None
Advance preparation: None
Registration fee: $825 per attendee
Why the NAIC Insurance Data Security Model Law Matters
Insurance companies, agencies, and other licensed entities collect and maintain significant amounts of nonpublic information. This may include personally identifiable information, financial information, health-related information, policyholder records, claims data, and business information.
A cybersecurity event involving this information can produce consequences far beyond the immediate technical disruption. An organization may face regulatory scrutiny, notification obligations, legal exposure, financial losses, operational interruptions, and reputational damage.
The NAIC Insurance Data Security Model Law establishes expectations for how covered insurance organizations protect nonpublic information and respond to cybersecurity events. Depending on how the law has been adopted in a particular state, regulated entities may be required to maintain a risk-based information security program, oversee third-party service providers, implement an incident response plan, investigate cybersecurity events, notify regulators, and submit annual certifications.
Merely having cybersecurity policies is not enough. Management must be able to demonstrate that the organization’s cybersecurity controls are appropriate for its risks and are operating effectively.
Move Beyond Regulatory Theory
The NAIC Cybersecurity Model Law Academy is designed to help participants translate regulatory language into practical cybersecurity governance, risk management, and internal control activities.
Attendees will examine questions such as:
Which organizations are subject to the NAIC Model Law?
What qualifies as nonpublic information?
What constitutes a cybersecurity event?
What must be included in an information security program?
How should an organization conduct a cybersecurity risk assessment?
What security measures should management implement?
What oversight should the board of directors provide?
How should third-party cybersecurity risk be managed?
What must be included in an incident response plan?
What documentation supports the annual certification process?
The program also compares the NAIC Insurance Data Security Model Law with the cybersecurity requirements contained in New York Department of Financial Services Regulation 23 NYCRR Part 500.
Building an Effective Information Security Program
A central focus of the academy is the development and continual improvement of an effective information security program.
Participants will learn how to connect business objectives, cyber risks, internal controls, monitoring activities, and management reporting. Topics include:
Cybersecurity governance and leadership
Risk appetite and risk tolerance
Identification and classification of information assets
Cybersecurity risk assessments
Security policies and procedures
Authorized users and access controls
Password and identity management
Desktop and mobile-device security
Email and wireless-network security
Physical and personnel security
Systems and application controls
Secure systems-development practices
Configuration management
Security awareness and employee training
Disaster recovery and business continuity
Continuous monitoring
Program testing and improvement
The academy emphasizes that an information security program must be appropriate for the organization’s size, complexity, activities, use of third parties, and exposure to cybersecurity risk.
Board and Senior Management Oversight
Cybersecurity governance cannot be delegated entirely to the IT department. Boards and senior management must understand the organization’s significant cyber risks and determine whether management has established an appropriate control environment.
The academy examines the board’s cybersecurity oversight responsibilities and the information directors need to make informed decisions. Participants will consider how organizations can report cybersecurity risks, control deficiencies, significant events, remediation activities, and program maturity to the board.
Effective oversight requires more than periodic technical reports. Directors need clear information about:
The organization’s most significant cyber risks
Its exposure to internal and external threats
The effectiveness of critical cybersecurity controls
Third-party and supply-chain dependencies
Unresolved control deficiencies
Incident-response readiness
Available cybersecurity resources
Progress toward management’s desired maturity level
Managing Third-Party Cybersecurity Risk
Insurance organizations frequently rely on service providers for cloud computing, claims processing, policy administration, payment processing, data hosting, communications, software, and other critical activities.
Outsourcing an activity does not eliminate the organization’s responsibility for protecting nonpublic information.
The academy addresses how organizations can establish a risk-based approach to third-party oversight. This includes due diligence, contractual requirements, access restrictions, ongoing monitoring, incident-notification requirements, and management’s response when a provider’s controls are inadequate.
Preparing for a Cybersecurity Event
Even organizations with mature controls cannot eliminate every cyber threat. They must be prepared to identify, contain, investigate, and recover from a cybersecurity event.
Participants will examine the major elements of an incident response program, including:
Establishing the incident response team
Defining roles and decision-making authority
Identifying escalation requirements
Preserving evidence
Evaluating affected systems and information
Coordinating legal, compliance, technical, and communication activities
Determining regulatory and customer notification requirements
Restoring business operations
Conducting a post-event evaluation
Correcting the control weaknesses that contributed to the event
The program also explores the Observe–Orient–Decide–Act methodology as a practical approach to improving decision-making during rapidly developing cyber incidents.
Evaluating Cybersecurity Maturity
Organizations need a structured method for determining whether their cybersecurity controls are keeping pace with their changing risks.
The academy discusses cybersecurity maturity, inherent risk, control effectiveness, and management assessment techniques. Participants will consider governance, threat intelligence, cybersecurity controls, external dependencies, and incident-management resilience.
This analysis can help management move beyond a basic compliance checklist and determine whether the organization’s cybersecurity program is genuinely capable of protecting its operations and information.
SOC for Cybersecurity
The program also introduces the AICPA’s SOC for Cybersecurity framework and explains how it can help organizations communicate information about their cybersecurity risk-management programs.
Participants will examine:
The distinction between cybersecurity and information security
Cybersecurity program description criteria
Cybersecurity control criteria
Management’s description of its cybersecurity program
Management’s assertion
The independent practitioner’s opinion
Entity, service-provider, and supply-chain reporting considerations
This knowledge can be particularly valuable to internal auditors, external auditors, compliance professionals, and organizations seeking independent assurance over their cybersecurity programs.
Practical Resources Included
Academy attendees will receive access to 35 documents used in developing the program. These resources provide examples, references, and supporting materials that participants can use when evaluating or improving their own cybersecurity programs.
The objective is not simply to explain the Model Law. The objective is to give attendees practical tools they can take back to their organizations.
Who Should Attend?
The NAIC Cybersecurity Model Law Academy is appropriate for:
Insurance company executives
Chief information security officers
Information technology managers
Cybersecurity professionals
Internal and external auditors
Risk management professionals
Compliance officers
Privacy professionals
Insurance regulators
Legal and governance professionals
Board members and audit committee members
Project managers responsible for cybersecurity initiatives
Third-party risk management professionals
No previous cybersecurity experience is required. The course is structured to help both technical and nontechnical professionals understand their respective responsibilities.
What Participants Will Learn
By completing the academy, attendees should be better prepared to:
Explain the purpose and principal requirements of the NAIC Insurance Data Security Model Law.
Identify the components of an effective information security program.
Understand how to conduct a cybersecurity risk assessment.
Evaluate examples of minimum cybersecurity standards and controls.
Assess controls over third-party service providers.
Understand board and senior management oversight responsibilities.
Develop or evaluate a cybersecurity incident reporting and notification plan.
Consider the relationship between inherent cyber risk and control maturity.
Prepare for annual cybersecurity compliance certifications.
Communicate cybersecurity risks and control deficiencies more effectively.
Strengthen Cybersecurity Compliance Before an Incident Occurs
A cybersecurity event is the wrong time to discover that responsibilities were unclear, controls were inadequately documented, third-party risks were overlooked, or the incident response plan had never been tested.
The NAIC Cybersecurity Model Law Academy gives insurance professionals a structured opportunity to evaluate their current practices, identify gaps, and strengthen their organization’s cybersecurity governance and compliance program.
Join Corporate Compliance Seminars on September 30–October 1, 2026, for this live, interactive 12-CPE webinar.

Comments