top of page
Search

NAIC Cybersecurity Model Law Academy: Build a Stronger Insurance Information Security Program

Aug 11
5 min read

Cybersecurity is no longer solely an information technology concern. For insurance organizations, it is a regulatory, governance, operational, and enterprise-risk responsibility.


CCS will present the NAIC Cybersecurity Model Law Academy as a live, interactive webinar on Wednesday and Thursday, September 30–October 1, 2026. This comprehensive two-day program provides insurance, compliance, audit, risk, and information technology professionals with practical guidance for implementing and assessing an effective information security program under the NAIC Insurance Data Security Model Law.


Participants who complete the program can earn 12 CPE credits.


Event Details

  • Dates: Wednesday–Thursday, September 30–October 1, 2026

  • Time: 9:00 a.m.–3:00 p.m. Central Time each day

  • Lunch break: Noon–12:30 p.m. Central Time

  • Delivery method: Live, Group Internet Based webinar

  • CPE credits: 12

  • Fields of study: Auditing and Information Technology

  • Program level: Basic

  • Prerequisites: None

  • Advance preparation: None

  • Registration fee: $825 per attendee


Why the NAIC Insurance Data Security Model Law Matters

Insurance companies, agencies, and other licensed entities collect and maintain significant amounts of nonpublic information. This may include personally identifiable information, financial information, health-related information, policyholder records, claims data, and business information.


A cybersecurity event involving this information can produce consequences far beyond the immediate technical disruption. An organization may face regulatory scrutiny, notification obligations, legal exposure, financial losses, operational interruptions, and reputational damage.


The NAIC Insurance Data Security Model Law establishes expectations for how covered insurance organizations protect nonpublic information and respond to cybersecurity events. Depending on how the law has been adopted in a particular state, regulated entities may be required to maintain a risk-based information security program, oversee third-party service providers, implement an incident response plan, investigate cybersecurity events, notify regulators, and submit annual certifications.


Merely having cybersecurity policies is not enough. Management must be able to demonstrate that the organization’s cybersecurity controls are appropriate for its risks and are operating effectively.


Move Beyond Regulatory Theory

The NAIC Cybersecurity Model Law Academy is designed to help participants translate regulatory language into practical cybersecurity governance, risk management, and internal control activities.


Attendees will examine questions such as:

  • Which organizations are subject to the NAIC Model Law?

  • What qualifies as nonpublic information?

  • What constitutes a cybersecurity event?

  • What must be included in an information security program?

  • How should an organization conduct a cybersecurity risk assessment?

  • What security measures should management implement?

  • What oversight should the board of directors provide?

  • How should third-party cybersecurity risk be managed?

  • What must be included in an incident response plan?

  • What documentation supports the annual certification process?


The program also compares the NAIC Insurance Data Security Model Law with the cybersecurity requirements contained in New York Department of Financial Services Regulation 23 NYCRR Part 500.


Building an Effective Information Security Program

A central focus of the academy is the development and continual improvement of an effective information security program.


Participants will learn how to connect business objectives, cyber risks, internal controls, monitoring activities, and management reporting. Topics include:

  • Cybersecurity governance and leadership

  • Risk appetite and risk tolerance

  • Identification and classification of information assets

  • Cybersecurity risk assessments

  • Security policies and procedures

  • Authorized users and access controls

  • Password and identity management

  • Desktop and mobile-device security

  • Email and wireless-network security

  • Physical and personnel security

  • Systems and application controls

  • Secure systems-development practices

  • Configuration management

  • Security awareness and employee training

  • Disaster recovery and business continuity

  • Continuous monitoring

  • Program testing and improvement


The academy emphasizes that an information security program must be appropriate for the organization’s size, complexity, activities, use of third parties, and exposure to cybersecurity risk.


Board and Senior Management Oversight

Cybersecurity governance cannot be delegated entirely to the IT department. Boards and senior management must understand the organization’s significant cyber risks and determine whether management has established an appropriate control environment.

The academy examines the board’s cybersecurity oversight responsibilities and the information directors need to make informed decisions. Participants will consider how organizations can report cybersecurity risks, control deficiencies, significant events, remediation activities, and program maturity to the board.


Effective oversight requires more than periodic technical reports. Directors need clear information about:

  • The organization’s most significant cyber risks

  • Its exposure to internal and external threats

  • The effectiveness of critical cybersecurity controls

  • Third-party and supply-chain dependencies

  • Unresolved control deficiencies

  • Incident-response readiness

  • Available cybersecurity resources

  • Progress toward management’s desired maturity level


Managing Third-Party Cybersecurity Risk

Insurance organizations frequently rely on service providers for cloud computing, claims processing, policy administration, payment processing, data hosting, communications, software, and other critical activities.


Outsourcing an activity does not eliminate the organization’s responsibility for protecting nonpublic information.


The academy addresses how organizations can establish a risk-based approach to third-party oversight. This includes due diligence, contractual requirements, access restrictions, ongoing monitoring, incident-notification requirements, and management’s response when a provider’s controls are inadequate.


Preparing for a Cybersecurity Event

Even organizations with mature controls cannot eliminate every cyber threat. They must be prepared to identify, contain, investigate, and recover from a cybersecurity event.


Participants will examine the major elements of an incident response program, including:

  • Establishing the incident response team

  • Defining roles and decision-making authority

  • Identifying escalation requirements

  • Preserving evidence

  • Evaluating affected systems and information

  • Coordinating legal, compliance, technical, and communication activities

  • Determining regulatory and customer notification requirements

  • Restoring business operations

  • Conducting a post-event evaluation

  • Correcting the control weaknesses that contributed to the event


The program also explores the Observe–Orient–Decide–Act methodology as a practical approach to improving decision-making during rapidly developing cyber incidents.


Evaluating Cybersecurity Maturity

Organizations need a structured method for determining whether their cybersecurity controls are keeping pace with their changing risks.


The academy discusses cybersecurity maturity, inherent risk, control effectiveness, and management assessment techniques. Participants will consider governance, threat intelligence, cybersecurity controls, external dependencies, and incident-management resilience.


This analysis can help management move beyond a basic compliance checklist and determine whether the organization’s cybersecurity program is genuinely capable of protecting its operations and information.


SOC for Cybersecurity

The program also introduces the AICPA’s SOC for Cybersecurity framework and explains how it can help organizations communicate information about their cybersecurity risk-management programs.


Participants will examine:

  • The distinction between cybersecurity and information security

  • Cybersecurity program description criteria

  • Cybersecurity control criteria

  • Management’s description of its cybersecurity program

  • Management’s assertion

  • The independent practitioner’s opinion

  • Entity, service-provider, and supply-chain reporting considerations


This knowledge can be particularly valuable to internal auditors, external auditors, compliance professionals, and organizations seeking independent assurance over their cybersecurity programs.


Practical Resources Included

Academy attendees will receive access to 35 documents used in developing the program. These resources provide examples, references, and supporting materials that participants can use when evaluating or improving their own cybersecurity programs.

The objective is not simply to explain the Model Law. The objective is to give attendees practical tools they can take back to their organizations.


Who Should Attend?

The NAIC Cybersecurity Model Law Academy is appropriate for:

  • Insurance company executives

  • Chief information security officers

  • Information technology managers

  • Cybersecurity professionals

  • Internal and external auditors

  • Risk management professionals

  • Compliance officers

  • Privacy professionals

  • Insurance regulators

  • Legal and governance professionals

  • Board members and audit committee members

  • Project managers responsible for cybersecurity initiatives

  • Third-party risk management professionals


No previous cybersecurity experience is required. The course is structured to help both technical and nontechnical professionals understand their respective responsibilities.


What Participants Will Learn

By completing the academy, attendees should be better prepared to:

  • Explain the purpose and principal requirements of the NAIC Insurance Data Security Model Law.

  • Identify the components of an effective information security program.

  • Understand how to conduct a cybersecurity risk assessment.

  • Evaluate examples of minimum cybersecurity standards and controls.

  • Assess controls over third-party service providers.

  • Understand board and senior management oversight responsibilities.

  • Develop or evaluate a cybersecurity incident reporting and notification plan.

  • Consider the relationship between inherent cyber risk and control maturity.

  • Prepare for annual cybersecurity compliance certifications.

  • Communicate cybersecurity risks and control deficiencies more effectively.


Strengthen Cybersecurity Compliance Before an Incident Occurs

A cybersecurity event is the wrong time to discover that responsibilities were unclear, controls were inadequately documented, third-party risks were overlooked, or the incident response plan had never been tested.


The NAIC Cybersecurity Model Law Academy gives insurance professionals a structured opportunity to evaluate their current practices, identify gaps, and strengthen their organization’s cybersecurity governance and compliance program.


Join Corporate Compliance Seminars on September 30–October 1, 2026, for this live, interactive 12-CPE webinar.


 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page