Ohio Becomes the Third U.S. State to Adopt the NAIC’s Insurance Data Security Model Law

Stu Sjouwerman | Apr 22, 2019
NAIC

Ohio joins South Carolina and Michigan to create cybersecurity legislation modeled after the National Association of Insurance Commissioners’ (NAIC) Insurance Data Security Model Law.

Rather than start from scratch and spend a material amount of time and taxpayer’s money on crafting a new cybersecurity law, states are beginning to instead look to the NAIC’s Insurance Data Security Model Law as the basis for their own legislation. While the NAIC “Law” isn’t actual legislation, it is written as such to meet the very need previously outlined. It provides details around data to be protected, risk assessments, oversight, incident response, investigations, notifications, and more.

With Ohio joining the pack in enacting cybersecurity regulations for insurance companies, credence is given to the NAIC’s model law. This elevates the credibility of the model law when other states begin their own task of crafting similar legislation.

Mandate to include Security Awareness Training

One aspect that we here at KnowBe4 are particularly happy to see included in NAIC’s model law is the mandate to include Security Awareness Training as part of Risk Assessment and Risk Management initiatives. A critical part of the security strategy, this training heightens the employees understanding of the need for security as part of their daily routine to help protect the organization from phishing attacks, social engineering, data breaches, ransomware and more.

And while the current legislation is focused on the insurance industry, the tide is moving towards more personal data protection laws. So, expect to see both more regulated industries having similar legislation and/or personal data laws that cover every industry.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.