City of Columbia
Follow Us



Hiring a CISO is the Next Step for Insurance Carriers

Mitchell Wein | July 10, 2017

Cybersecurity is top of mind for insurers following the implementation of New York State’s new cybersecurity regulations this spring. While these currently only affect carriers operating in New York, other states seem likely to adopt versions of the regulations rather than wait on the NAIC’s Model Law.

These regulations are notable for their unprecedented standards and strict requirements, including instituting a formal CISO, documenting policies, and submitting to regular assessments. Despite having until February 2018 to comply with the new regulations, carriers are already anticipating shifts in both resources and strategies.

One of the greatest challenges insurers will face in light of these new regulations will be hiring a dedicated CISO, as they come with a hefty price tag and are in relatively short supply. This will be especially difficult for small carriers that may need to consider partnering with certified vendors that would operate on behalf of the insurer and be subject to the same regulatory standards as the carrier. While many mid-sized insurers will name their CIO or COO the CISO with a domain expert to support them, Novarica believes that hiring a designated CISO is a good idea given the risks and complexity involved.

Additionally, carriers will be required to establish and maintain cybersecurity programs with a host of regulatory requirements, as well as submit to risk assessments at least annually, and vulnerability assessments bi-annually. Insurers will also need to establish policies and procedures for the destruction of nonpublic information that is no longer required.

It should be noted that the definition of “nonpublic information” in New York General Business Law is substantially more expansive than “private information” as defined in the proposed NAIC regulation, making for a significant data management burden. Novarica studies show that insurers spend an average of 10 percent of IT budgets on security, but it is clear that these additional requirements, along with any possible technology investments necessitated by the new regulations, will drive that cost up, requiring CIOs to rethink other IT priorities.

Featured articles

Majesco RH



The Email Chat is a regular feature of the ITA Pro magazine and website. We send a series of questions to an insurance IT leader in search of thought-provoking responses on important issues facing the insurance industry.


ITA is pleased to present the 2014 Webinar Series. We have many topics for you to choose from and attendance is open to all ITA members. The webinar topics are current and exciting — ranging from predictive analytics to telematics and will focus on the direction insurance carriers need to follow for the future. All webinars are presented by insurance IT professionals along with some of the leading analysts and consultants in the field. There is no cost to attend an ITA webinar. For more information and to register for the webinar, click the “title” of the webinar below.


only online

Only Online Archive

ITA Pro Buyers' Guide

Vendor Views

Partner News