NAIC: Cybercrime Response Needed to Stem Millions in Losses - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Washington Insider Newsletter
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
INN Daily Newsletter INN Exclusives
Washington Insider Newsletter RSS Get our newsletter
Order Prints
September 11, 2015 Washington Insider Newsletter
Share
Share
Post
Email

NAIC: Cybercrime Response Needed to Stem Millions in Losses

By Cyril Tuohy

The insurance industry is losing tens of millions of dollars annually to cybersecurity breaches and officials want to do something about it.

The National Association of Insurance Commissioners’ “Consumer Cybersecurity Bill of Rights,” is expected to be finished in the coming weeks. The document will then be disseminated to consumers, Adam Hamm, chair of the NAIC’s Cybersecurity Task Force, said Thursday.

Portions of the Cybersecurity Bill of Rights are also expected to find their way into the NAIC model laws and eventually into state statutes, Hamm also said during a discussion on data breaches hosted by Center for Strategic & International Studies in Washington, D.C.

Hamm didn’t elaborate on which parts of the Cybersecurity Bill of Rights would make it into the NAIC’s model laws, but the association is taking into account industry feedback filed during the comment period earlier this summer. Cybersecurity is seen as one of the biggest threats facing businesses across the spectrum.

Hamm, the North Dakota insurance commissioner, used Thursday’s forum to update the industry on steps the NAIC is taking with regard to the protecting consumers and the industry from network attacks.

In addition to the Cybersecurity Bill of Rights, Hamm said the NAIC has updated carrier examination protocols to find out how prepared insurance companies are to handle data breaches.

“The challenge for cyberrisk management for insurers goes well beyond that of other businesses,” Hamm said. “Today’s criminals target insurers because they keep personal, financial and health information.”

On Wednesday, Excellus BlueCross Blue Shield in Rochester, New York, announced it had been the target of a data breach affecting 10.5 million records.

In March, Boston-based health insurer Premera Blue Cross announced it had been the target of a breach affecting financial information involving 11 million customers.

Indianapolis-based Anthem Inc. earlier this year mailed letters to as many as 80 million customers whose data might have been compromised in separate data breaches affecting its subsidiaries in different states.

The regularity with which companies are being targeted has even caused Wired to proclaim 2015 as the year of the health insurer data breach.

In an industry governed by state regulations, developing a national framework to deal with data breaches is a priority for the NAIC.

As many as 47 statutes govern how the state-based insurance industry must respond in the event of a cyberattack.

While there remain variations among the different laws, the core message to insurers remains the same across all states, and “as of now, we’re not seeing anything moving toward pre-emption,” of state laws by federal regulators, Hamm said.

During a panel discussion, representatives from the U.S. Treasury Department and the Department of Homeland Security (DHS) outlined the holistic steps they are taking to coordinate responses across government agencies and network risks.

Taking an enterprise risk management approach to fighting cybercrime is critical, said Suzanne Spaulding, undersecretary for the National Protection and Programs Directorate at DHS.

The staccato of network breaches affecting retailers, government agencies and insurers over the past three to four years is a sign that data networks are under attack every day, according to the security experts invited to speak on the panel.

Many attempted intrusions are being repelled by commercially available technologies like antivirus software, officials said. But when a company admits a breach, it’s often because management has only recently discovered the intrusion, which may have taken place months ago.

Network security experts say the supply chain is a frequent entry point for data breaches. The retailer Target, for example, suffered huge losses from an intrusion traced to a vulnerability affecting an HVAC contractor.

All of which makes it difficult for insurance regulators who strive to deal with insurers that meet the highest security standards, to feel comfortable when dealing dozens of carriers doing business in their respective states.

“We as regulators are looking at insurers to have a certain standard,” said Wisconsin Insurance Commissioner Ted Nickel.

Jake Olcott, vice president of BitSight Technologies, a Massachusetts company that develops security ratings scores similar to a FICO score used to evaluate consumer borrowers, said standards of care remain a fundamental issue among insurers.

International standards like ISO 27001 or the National Information Sharing Standards offer examples of good security practices, but the data technology changes so fast that it’s hard to keep up, other security experts on the panel said.

Olcott, however, also faulted states for underinvesting in information technology and data network protection. “Clearly, there’s been underinvestment at the state level,” he said.

A report issued in February by the New York Department of Financial Services found that 98 percent of 43 life, health and property-casualty insurers surveyed reported having some form of information security framework in 2013-14.

The survey also found that 98 percent of insurers employed data loss prevention tools, 98 percent employed file encryption and 95 percent used vulnerability scanning tools in the same two-year period.

The majority of insurers — 70 percent — reported suffering no financial loss in the past 12 months as a result of the network breaches, and 23 reported suffering losses of less than $250,000, the survey also found.

One institution reported a loss of between $6 million and $10 million, the survey revealed.

Hamm said that as part of the NAIC’s push for a cybersecurity framework, information about carrier losses from network breaches would be published in the association’s annual report beginning in the first quarter of next year.

Loss information related to claims, the name of insurance companies, raw numbers, solvency issues and loss trends will be included in the annual report’s cybersecurity supplement.

 

 

Cyril Tuohy

Cyril Tuohy is a writer based in Pennsylvania. He has covered the financial services industry for more than 15 years. He can be reached at [email protected].

Older

Smaller Insurance Companies Keeping Pace Among Top 20 Carriers

Newer

Schwab Survey: RIA Mergers & Acquisitions up by 28 Percent

Advisor News

  • NAIFA: Financial professionals are essential to the success of Trump Accounts
  • Changes, personalization impacting retirement plans for 2026
  • Study asks: How do different generations approach retirement?
  • LTC: A critical component of retirement planning
  • Middle-class households face worsening cost pressures
More Advisor News

Annuity News

  • Trademark Application for “INSPIRING YOUR FINANCIAL FUTURE” Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Jackson Financial ramps up reinsurance strategy to grow annuity sales
  • Insurer to cut dozens of jobs after making splashy CT relocation
  • AM Best Comments on Credit Ratings of Teachers Insurance and Annuity Association of America Following Agreement to Acquire Schroders, plc.
  • Crypto meets annuities: what to know about bitcoin-linked FIAs
More Annuity News

Health/Employee Benefits News

  • $2.67B settlement payout: Blue Cross Blue Shield customers to receive compensation
  • Sen. Bernie Moreno has claimed the ACA didn’t save money. But is that true?
  • State AG improves access to care for EmblemHealth members
  • Arizona ACA enrollment plummets by 66,000 as premium tax credits expire
  • HOW A STRONG HEALTH PLAN CAN LEAD TO HIGHER EMPLOYEE RETENTION
More Health/Employee Benefits News

Life Insurance News

  • Corporate PACs vs. Silicon Valley
  • IUL tax strategy at center of new lawsuit filed in South Carolina
  • National Life Group Announces 2025-2026 LifeChanger of the Year Grand Prize Winner
  • International life insurer Talcott to lay off more than 100 in Hartford office
  • International life insurer to lay off over 100 in Hartford office
Sponsor
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

LIMRA’s Distribution and Marketing Conference
Attend the premier event for industry sales and marketing professionals

Get up to 1,000 turning 65 leads
Access your leads, plus engagement results most agents don’t see.

What if Your FIA Cap Didn’t Reset?
CapLock™ removes annual cap resets for clearer planning and fewer surprises.

Press Releases

  • RFP #T22521
  • Hexure Launches First Fully Digital NIGO Resubmission Workflow to Accelerate Time to Issue
  • RFP #T25221
  • LIDP Named Top Digital-First Insurance Solution 2026 by Insurance CIO Outlook
  • Finseca & IAQFP Announce Unification to Strengthen Financial Planning
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet