Insurance firms under DFS don't get a different examination. They get the same documentation requests.
IT On Demand builds and maintains the governance program that makes your DFS cybersecurity certification defensible — year-round, not just in April.
The DFS certification applies to insurance. The documentation standard is identical.
23NYCRR500 covers both financial services firms and DFS-regulated insurance companies. The examination standard — and the personal liability of the certifying officer — is the same.
Insurance firms often assume that their cybersecurity posture is covered by their existing compliance program or their IT provider’s tooling. The examination tests neither of those. It tests the evidence: the documented proof that governance controls are implemented, tested, and current.
For insurance firms managing policyholder data, third-party distribution relationships, and multi-state regulatory obligations, the documentation gap is typically significant — and the consequences of a finding are not limited to DFS. Cyber insurance underwriters, reinsurers, and plaintiff’s counsel apply the same standard.
The governance layer insurance firms don't have — and regulators expect.
IT On Demand serves DFS-regulated insurance companies with governance programs built to the standard that DFS examiners examine. We build and maintain the penetration test documentation, vendor risk assessments, tested incident response plans, MFA verification records, and WISP that make the annual certification defensible — not just filed.
We also understand the specific documentation complexity that insurance distribution relationships create. Third-party agents, brokers, and managing general agents with access to nonpublic policyholder information are each a vendor risk documentation obligation. That inventory is part of what we build and maintain.
Questions we hear from insurance firms.
- Q: Does 23NYCRR500 apply to insurance companies the same way it applies to financial services firms?
- A: Yes. DFS-regulated insurance companies are covered entities under 23NYCRR500. The regulation's requirements — including the annual certification by a senior officer — apply fully. The examination standard is the same as it is for financial services firms: documented evidence of implemented controls, not policies alone.
- Q: Our distribution network includes dozens of agents and brokers with access to our systems. Is that a compliance issue?
- A: Yes. Under 23NYCRR500's vendor management requirements, every third party with access to your nonpublic information — including agents, brokers, and MGAs operating on your systems or with access to your data — is a third-party service provider that must be identified, risk-tiered, and documented. For insurance firms with large distribution networks, this is typically the most significant documentation gap we find.
- Q: Can a denied cyber insurance claim result from a governance documentation gap?
- A: Yes. Cyber insurance policies increasingly require the insured to maintain specific governance controls as a condition of coverage. If a claim is made and the insurer's investigation reveals that documented controls were not in place — or that the controls claimed at underwriting were not verifiably implemented — the claim can be denied. The governance documentation IT On Demand produces serves both the regulatory examination and the insurance defensibility standard.
Start with a Compliance Gap Assessment.
A 30-minute private diagnostic, specific to your firm’s regulatory exposure. No pitch. No obligation. A clear picture of what you have, what is missing, and what an examiner would find next month.