Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call

IT Support for Insurance Agencies: 13 Questions Owners Ask

Brick storefront office of a small independent insurance agency on a main street at golden hour

Insurance agencies have an IT problem most small businesses don't: a regulator with a checklist. If you hold a New York license, the state has opinions about your multi-factor authentication and your asset inventory, and it wants a signed certification every April. Everything else — the agency management system, the carrier portals, the email your producers live in — sits on top of that.

Key takeaways:

  • If you're licensed under New York Insurance Law, 23 NYCRR Part 500 almost certainly applies to you.
  • The "limited exemption" is partial. It drops eight sections and leaves the rest.
  • MFA and the asset inventory requirement took effect November 1, 2025.
  • Your compliance certification is due April 15 for the prior calendar year.

Here are the questions agency owners and principals actually ask us.

NYDFS Part 500 questions

Does NYDFS cybersecurity apply to my insurance agency?

Almost certainly. Part 500 covers any person operating under, or required to operate under, a license or similar authorization under New York's Banking, Insurance, or Financial Services Law. That sweeps in independent agencies and brokers, not just carriers. DFS's own cybersecurity FAQs state that individual insurance brokers and agents must submit an annual compliance notification unless they are fully exempt under Section 500.19.

Is there any way we're fully exempt?

Rarely. The one that fits some agencies is Section 500.19(b): an employee, agent, wholly owned subsidiary, representative, or designee is exempt to the extent it's covered by another covered entity's cybersecurity program.

Watch the language people get wrong here. Section 500.19(c), for an entity with no information systems and no nonpublic information, is a limited exemption, not a full one, and DFS still expects an annual compliance notification from entities relying on it. Almost no working agency qualifies for it anyway.

We have eight employees. Doesn't that exempt us?

It gets you the limited exemption, not an exit. You qualify by meeting any one of three tests, and all three count your affiliates: fewer than 20 employees and independent contractors; less than $7.5 million in gross annual revenue in each of the last three fiscal years; or less than $15 million in year-end total assets under GAAP.

So what do we still have to do?

Section 500.19(a) drops eight sections:

  • 500.4 — the CISO requirement
  • 500.5 — penetration testing and vulnerability management
  • 500.6 — audit trails
  • 500.8 — application security
  • 500.10 — cybersecurity personnel and intelligence
  • 500.14(a)(1), (a)(2) and (b) — monitoring, malware protection, and the Class A endpoint detection and centralized logging requirements
  • 500.15 — encryption
  • 500.16 — the written incident response and business continuity plans

Everything else stands:

  • A cybersecurity program (500.2)
  • A written cybersecurity policy, approved at least annually by a senior officer or your senior governing body (500.3)
  • Access privilege reviews and a written password policy (500.7)
  • An annual risk assessment (500.9)
  • Third-party service provider security policies (500.11)
  • Multi-factor authentication (500.12)
  • Asset inventory and secure data disposal (500.13)
  • Annual cybersecurity awareness training that covers social engineering (500.14(a)(3))
  • A 72-hour cybersecurity event notice, plus a 24-hour notice if you make an extortion payment and a written explanation within 30 days (500.17(a) and (c))
  • The April 15 certification (500.17(b))
  • A Notice of Exemption filed within 30 days of qualifying (500.19(h))

What took effect on November 1, 2025?

The two requirements that hit small agencies hardest. MFA under Section 500.12 is now required for any individual accessing your information systems — with a narrower version for limited-exemption entities covering remote access to information systems, remote access to third-party applications including cloud apps from which nonpublic information is reachable, and all privileged accounts other than non-interactive service accounts.

Section 500.13(a) is the other one. It requires written policies and procedures designed to produce and maintain a complete, accurate, documented asset inventory, tracking — as applicable — owner, location, classification or sensitivity, support expiration date, and recovery time objectives, plus how often you update and validate it.

When is the annual certification due?

April 15, covering the prior calendar year. You file either a Certification of Material Compliance or an Acknowledgment of Noncompliance with a remediation plan, signed by your highest-ranking executive and your CISO — or, if you don't have a CISO, by the senior officer responsible for the cybersecurity program. DFS publishes a small business resources page with the filing steps. Signing the certification when the controls aren't actually in place is the expensive mistake. Our guide to 23 NYCRR 500 for small firms walks through what evidence to keep.

Day-to-day IT questions

Can you support Applied Epic, EZLynx, AMS360, or HawkSoft?

Yes, and the answer matters more than it sounds. Your agency management system is the business. What an IT provider owns is the environment around it: the workstations, the network, identity and MFA, backups, printing and scanning, and the escalation path to the vendor when the platform itself is the problem. We manage that layer and coordinate with your AMS vendor rather than replacing them.

How do we handle carrier portal logins?

With a business password manager and shared credential vaults, not a spreadsheet and not a browser's saved-password list. Producers work across a long list of carrier portals, and many still don't support single sign-on. A vault gives you MFA on the vault itself, per-user access you can revoke the day someone leaves, and an actual record of who could reach what.

What's the biggest security risk for an agency?

Email. Agencies move premium payments, binders, and client PII through email all day, and business email compromise targets exactly that. The controls that work are unglamorous: MFA everywhere, email authentication records that actually pass, a callback rule for any change in payment instructions, and training that uses your own workflows as the examples.

What does managed IT cost for an agency our size?

Most small agencies land in the same per-user, per-month range as other professional services firms, with the compliance work priced separately or bundled depending on the engagement. The variables are headcount, number of offices, whether you still run a server, and how much of the regulatory documentation you want handled for you. Our breakdown of managed IT cost per user has the current ranges. If you are also weighing automation, AI automation for insurance agencies covers where it pays off.

Do we need cyber insurance if we sell insurance?

Yes, and your carriers and lenders will likely require it. The underwriting questionnaire will ask about MFA, backups, endpoint detection, and employee training, and the answers have to be true — a misstatement on the application can give the carrier grounds to rescind the policy when you need it. Getting the controls in place before renewal usually helps on premium too. Our cyber insurance requirements guide covers what underwriters check.

What about producers working from home or in the field?

Treat every device as untrusted until it proves otherwise. Company-managed laptops with disk encryption and endpoint detection, MFA on everything, and remote access through a VPN or ZTNA rather than an exposed remote desktop. If producers use personal phones for agency email, a mobile management policy that can wipe agency data without touching their photos is the minimum.

How long does it take to get an agency compliant?

In our engagements, a ten-to-thirty-person agency starting from scratch takes roughly 60 to 90 days to get the technical controls in place and the documentation written. MFA and backups move fast. The asset inventory, the written policies, the vendor risk reviews, and the training records take longer, because they need decisions from you rather than configuration from us.

Where to start

Pull two documents before you call anyone: your last cyber insurance application and your most recent Part 500 certification. The gap between what those say and what's actually running is your project list.

If you'd rather someone else find that gap, request a complimentary risk assessment. We work with agencies across New York, New Jersey, Connecticut, Pennsylvania, and Southwest Florida, and we'll tell you where you stand before anyone talks about a contract. You can also see our full managed IT and cybersecurity services.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.