For Insurance Agencies

Your agency management system is an NPI goldmine and NAIC Model Law 668 says you are responsible for it.

Every client SSN, DOB, driver license, and bank account lives in your AMS and your email archive. One compromised producer account is a reportable breach under most state adoptions of NAIC Model Law 668. Most agencies your size have zero monitoring on that layer.

7-day free trial No setup fees Cancel anytime
0 + states

Have adopted NAIC Model Law 668 with cyber-security obligations for insurance licensees

Source: NAIC Insurance Data Security Model Law tracker
Credentialed · Insured · Operational
Licensed
ND LLC
IRS registered
EIN 41-5213020
E&O insured
$1M / $2M agg
Encrypted
AES-256-GCM
MFA required
TOTP + passkey
Audit trail
365-day retention
Threats We Actually Catch

Every attack that targets insurance agencies, live-monitored.

36 detection engines sweep your Microsoft 365, Google Workspace, AWS, and Cloudflare accounts every five minutes. Critical threats surface instantly. Normal activity gets filed away.

NPI theft at scale

A producer inbox holds quotes with full SSNs, DOBs, driver license numbers, and prior-claim history. One account takeover exfiltrates the entire book of business — and every state you write in imposes notification obligations.

Carrier credential harvesting

Phishing targeted at producers to steal carrier-portal logins. The attacker binds fraudulent policies, cancels real ones, or rebates commissions to their own accounts before you notice.

Client bank-account rerouting

Auto-pay setup emails intercepted in a hijacked inbox, then replayed with new routing numbers. Clients think they are paying their premium; the money goes to the attacker and the policy lapses.

Why this is your problem, not your IT person’s.

Compliance Alignment

The rules and frameworks we line up to.

SentinelSMB provides the continuous-monitoring, access-control, and incident-response controls these frameworks require. Pro subscribers get the audit-ready evidence package.

NAIC Model Law 668

Insurance Data Security Model Law

Adopted by a majority of states as state law, Model Law 668 requires licensees to implement a written information security program with ongoing risk assessment, access controls, and continuous monitoring of systems holding NPI.

GLBA Safeguards Rule

Non-public personal information

Insurance producers are financial institutions under GLBA. The amended Safeguards Rule (effective June 2023) requires continuous monitoring, designated qualified individual, and incident response plan.

State insurance department regs

Cyber-event notification windows

Most state insurance department regs require notification to the commissioner within 72 hours of a determined cyber event. SentinelSMB provides the exact detection timestamps and evidence you need to meet those windows.

NY DFS 23 NYCRR 500

Financial services cybersecurity

If you are licensed in New York, 23 NYCRR 500 imposes specific continuous-monitoring, access-control, and audit-logging requirements. SentinelSMB covers the monitoring and logging controls directly.

Questions insurance agencies ask.

Does SentinelSMB make us NAIC Model Law 668 compliant?

SentinelSMB provides the continuous-monitoring, access-logging, and incident-response components Model Law 668 requires. You still need a written information security program, designated qualified individual, and documented risk assessment. Pro subscribers get the policy-template foundation for the written program.

How does this fit with our carrier appointment requirements?

Most carriers now include cybersecurity attestations in the appointment agreement. Documented continuous monitoring is the evidence carriers increasingly ask for. We generate the underwriter-ready evidence package automatically for Pro subscribers.

What if we write in multiple states with different requirements?

SentinelSMB maps your monitoring to NAIC Model Law 668, GLBA, NY DFS 23 NYCRR 500, and the patchwork of state insurance department regs. The compliance page in your dashboard shows framework-by-framework status.

Can you help with our cyber-event notification window?

Yes. When we detect a threat, you get an exact timestamp, the affected accounts, and the evidence we saw — which is what the commissioner will ask for. For Pro subscribers, Incident Response Access is included.

Every producer, every carrier portal, every AMS login — watched around the clock.

NAIC 668 compliance is not a binder of policies. It is actual monitoring. Get live in under 10 minutes. 7-day free trial, cancel anytime.