Skip to content

Managed IT and Cybersecurity for Columbus Insurance Agencies

Your cyber insurance renewal has a date on it, and the questions on the application are about your systems rather than your book. Is multifactor authentication enforced on email and on the agency management system. Is endpoint detection deployed on every machine. Have the backups been restored from. Does a written incident response plan exist. You sign those answers about an environment where a full financial profile for every household and business you write sits behind a handful of logins, a comparative rater, an e-signature tool and a carrier portal for every appointment you hold. That profile holds Social Security numbers, dates of birth, driver’s license numbers, bank details, and in benefits work, health information. Those same facts are the ground the state’s own rules cover. Ohio Revised Code Chapter 3965 has been in effect since March 20, 2019, and it is written to reach agents as well as carriers.

What does your cyber insurance renewal actually ask you to prove?

You know the mechanics from the other side of the desk. An application is a set of statements about facts, made on a date. What changes when the application is about your own network is that most agencies have never had to produce the evidence behind an answer, only the answer. So the useful question at renewal is what proving each line actually looks like.

Start with the line the questionnaires lead with. "Is multifactor authentication enforced for all users" is a different question from "is multifactor authentication available." Enforced means a policy that applies to every account, plus the list of accounts it does not apply to. Almost every agency has that list: a break-glass administrator account, a shared mailbox someone signs into directly, a service account wired into the rater, a producer whose phone was a problem in March and got an exclusion nobody removed. The evidence is the policy showing what it covers and the exception list with a reason and an owner beside each line. When nobody can produce that list, the list is the finding.

The rest work the same way. Endpoint detection is evidenced by a coverage report counting devices rather than licenses, because the gap is usually the laptop that was rebuilt and never re-enrolled. A tested backup is evidenced by a restore with a date and the name of the person who ran it. A green checkmark on a backup job says a file was copied. It does not say the file can be brought back. Training is evidenced by completion records per person, which means the record has to include everyone hired since the last renewal. A written incident response plan is evidenced by a document that existed before the week you needed it. Chapter 3965 reaches some of the same ground in its own vocabulary. Division (D)(5) requires cybersecurity awareness training updated to reflect the risks the licensee’s risk assessment identified, and division (H) requires a written incident response plan. That is why one body of evidence tends to serve both.

Assembling all of that in the three weeks before a renewal date is how agencies end up guessing at answers. Our Virtual CISO and Compliance-as-a-Service work is built to keep the record current between renewals: a gap analysis against the controls you are being asked about, evidence tracking, control maintenance, and a renewal worked from a file that was already being kept. The same file answers a carrier’s security questionnaire and a commercial client’s, which ask most of the same questions in a different order.

Which insurance businesses does Chapter 3965 reach, and which are exempt from the program requirement?

Coverage is set by a definition, not by size. Section 3965.01(M) defines a licensee as any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered, under the insurance laws of this state, and the definition includes an insurer. It excludes a purchasing group, a risk retention group chartered and licensed in another state, and a licensee acting as an assuming insurer domiciled in another state or jurisdiction. Nothing in that sentence turns on headcount or revenue, so a two-person agency and a national carrier are both licensees.

Size enters one section later, and only as an exemption. Section 3965.07(A) exempts a licensee from section 3965.02 if it meets any of three criteria: fewer than twenty employees, less than five million dollars in gross annual revenue, or less than ten million dollars in assets measured at the end of the licensee’s fiscal year. The statute says "any of the following criteria", so one is enough. A licensee does not have to satisfy all three.

One thing the chapter does not do is say how to count. Section 3965.07(A)(1) sets a threshold of twenty employees and Chapter 3965 defines no term for employee, gives no treatment of part-time staff, and says nothing about contracted or 1099 producers. In an industry that runs on independent producers that is the question the threshold turns on most often, and the chapter’s text does not settle it.

There is a second route out of section 3965.02 that has nothing to do with size. Section 3965.07(B)(1) provides that a licensee subject to and in compliance with the privacy and security rules at 45 CFR Parts 160 and 164 is deemed to meet the requirements of the chapter, apart from notification under section 3965.04, and it requires a written statement to the superintendent certifying that compliance. Records supporting the certificate are kept five years for examination.

What the exemption does not reach is set out in the section on cybersecurity events below. Section 3965.07(A) is written against section 3965.02 and no other section, so the duties in sections 3965.03 and 3965.04 stand whether or not a licensee is exempt from building the program.

What does Ohio Revised Code Chapter 3965 require of a licensee?

Ohio adopted a version of the NAIC Insurance Data Security Model Law as Senate Bill 273 of the 132nd General Assembly. The chapter binds a “licensee,” and section 3965.01(M) defines that term broadly: any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered, pursuant to the insurance laws of this state. That is the sentence that pulls agencies inside the chapter, and it reaches captive and independent agencies alike. This is not a carrier-only law.

One phrase trips agencies up. Section 3965.04 uses a narrower term in one of its reporting triggers: whether “this state is the licensee’s home state, in the case of an independent insurance agent.” That is not the test for everyone. “Independent insurance agent” is a defined term with a fixed meaning, and section 3965.01(I) takes that meaning from section 3905.49, which turns on how the agency’s contract with the carrier is written. A captive or exclusive agency is unlikely to meet it. Such an agency is still a licensee either way, and the 250-consumer trigger in section 3965.04(A)(2) applies to every licensee regardless of home state. If which side of that line an agency sits on matters, read the definition.

The core duty in section 3965.02 is a comprehensive written information security program based on the licensee’s own risk assessment, sized to the licensee and to the sensitivity of the information it holds. Division (D) is a list the risk assessment sorts. It says that based on that risk assessment the licensee determines which of the listed security measures are appropriate, and then implements them.

Those measures include access controls that authenticate and permit access only to authorized individuals; encryption or other appropriate protection of nonpublic information both while it is transmitted over an external network and while it is stored on a laptop computer or other portable computing or storage device or media, which is the full requirement in division (D)(2)(d); restricted physical access; effective controls “which may include multifactor authentication procedures for accessing nonpublic information”; regular testing and monitoring to detect actual and attempted attacks; audit trails; and secure disposal of nonpublic information in any format. Division (D)(5) requires cybersecurity awareness training updated to reflect the risks the licensee’s risk assessment identified. Division (H) requires a written incident response plan.

Read the encryption line twice. The half about laptops and portable media is the one that drives a purchasing decision. Division (D)(2)(d) names portable devices and media on their own terms, alongside transmission over an external network, so an agency whose producers carry client files on the road should expect that hardware to be inside the program rather than beside it.

What does Ohio law require of a licensee after a cybersecurity event?

The duties in sections 3965.03 and 3965.04 survive the exemptions in section 3965.07(A) and (C), because both of those are written against section 3965.02 and nothing else. The HIPAA route in section 3965.07(B) is the one exception worth knowing: it is deemed to satisfy the chapter apart from section 3965.04 notification, which it does not touch.

Where a licensee learns that a cybersecurity event has or may have occurred, section 3965.03 requires a prompt investigation: determine whether an event occurred, assess its nature and scope, identify the nonpublic information involved, and perform or oversee reasonable measures to restore the security of the affected systems. Section 3965.03(A) lets an outside vendor or service provider designated to act on the licensee’s behalf do that work, which matters for a small agency with no internal security staff. It does not let the work go undone. Where the event happened in a system a third-party service provider maintains, section 3965.03(C) requires the licensee to take those steps or make reasonable efforts to confirm and document that the provider did. The chapter also requires records of all cybersecurity events kept for at least five years from the date of the event and produced on the superintendent’s demand.

Notice to the superintendent is due as promptly as possible and no later than three business days after the licensee determines that a cybersecurity event occurred. Whether it is owed turns on either of two tests in section 3965.04(A), and each test pairs a scope condition with a harm condition that both have to be true. One runs on Ohio being the licensee’s home state as an independent insurance agent. The other runs on nonpublic information relating to 250 or more consumers residing in Ohio. A bare headcount is not the trigger by itself. Read section 3965.04(A).

The superintendent filing is not the end of it, and this is the step agencies miss. Where notice to the superintendent is owed under section 3965.04(A), section 3965.04(C) also requires the licensee to comply with section 1349.19 of the Revised Code as applicable, and to give the superintendent a copy of the notice sent to consumers. Under section 1349.19(B)(2), notice to affected consumers is due in the most expedient time possible and no later than forty-five days following discovery of the breach or notification of it. Section 1349.19 also carries qualifiers and carve-outs that can change that answer: the deadline is subject to the legitimate needs of law enforcement, and the section does not apply at all to a HIPAA covered entity, which runs HIPAA’s own sixty-day breach notification clock at 45 C.F.R. 164.404. That carve-out is narrower than it reads: an agency writing benefits is usually a business associate of the plan or carrier rather than a covered entity itself, and the exclusion is written for covered entities. It also does not reach certain federally examined financial institutions already required to notify customers. Read the section.

The two clocks do not start on the same day. The three-business-day superintendent deadline runs from determination. The forty-five-day consumer deadline runs from discovery. An agency can file with the superintendent on time and still blow the consumer deadline, and still fail to send the superintendent the required copy. None of this is waived by the section 3965.07(A) exemption.

One more threshold rides along with section 1349.19. Where a breach requires notice to more than one thousand Ohio residents in a single occurrence, section 1349.19(G) also requires notice to all nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution and content of the notices sent to residents. That step may not be used to delay the forty-five-day resident deadline. One thousand is the highest count on this page. It is not the first line an agency crosses. Consumer notice under section 1349.19 can be owed over a single affected Ohio resident, and 250 Ohio consumers can put a licensee in front of the superintendent. An agency with a large book crosses one thousand easily, so the step is worth planning for rather than discovering mid-week.

Section 3965.11 directs the superintendent to consider the nature, scale and complexity of licensees, so a small agency is measured as a small agency. But none of these duties are achievable without logging, retained backups and written procedure put in place before the bad week.

Why do attackers go after insurance agencies specifically?

Because you aggregate. One agency file carries what an attacker needs for identity theft, account takeover and follow-on fraud, and your book concentrates hundreds or thousands of those files in one system. On June 16, 2025, John Hultquist, chief analyst at Google’s Threat Intelligence Group, warned that the crew tracked as Scattered Spider had turned to the US insurance sector after a run at retail, and said the industry should be on high alert “especially for social engineering schemes which target their help desks and call centers.”

That is the realistic shape of the threat. A convincing caller talks someone into a password reset or a fresh MFA enrollment. A lookalike domain arrives on a renewal thread. A carrier portal password gets reused from a personal account. The countermeasures are unglamorous and they work: phishing-resistant multifactor authentication, a verification script your staff follows before any credential change, conditional access on email and the agency management system, and alerting that catches a sign-in from a place your team has never worked.

What is still yours to secure when the software belongs to someone else?

Count what the agency actually runs on. The management system. A comparative rater. An e-signature tool. A document repository. Cloud email. A carrier portal for every appointment you hold. Almost none of it runs on hardware in your office. You cannot patch any of it, you will not see its architecture, and its outages are not yours to fix. A plant has the same shape of problem with a controller that cannot take another patch, and it gets the same treatment: stop working on the part you cannot control, and be exact about the parts you can. TTS Cyber works with any major agency management system that carries a current support contract from its software provider. That condition is practical rather than commercial. A system its vendor no longer supports stops receiving security patches, which leaves an agency relying on controls built around the software instead of fixes inside it.

The way in is yours. Every one of those systems is reached by an account belonging to a person, from a device, over a network. The identity controls this page covers above are the floor. What sits under them is the account hygiene nobody is assigned: an administrator account kept separate from the daily login of the person who holds it, no shared logins on a portal two people use, and a unique password from a password manager on every platform that still cannot enforce multifactor authentication, with a named human owner instead of a shared note.

The device is yours too, and it is where the browser runs. Full-disk encryption on every laptop that leaves the office, patching that actually completes rather than pending forever, endpoint protection, and a screen lock. The portal belongs to the carrier. The machine reading it on a passenger seat belongs to the agency. So does the office network: the firewall, the switches, the access points and the wireless. Managed IT and Network Operations Center work cover that layer, down to the guest wireless that should have no path to the workstation your accounting runs on.

The accounts you cannot see are the ones held inside someone else’s portal. A carrier portal is not in your directory, so disabling someone’s email on their last day does nothing to the eight portals they also held. Start from an inventory of every vendor touching client data, with a named owner against each one. Review the user list inside each portal on a schedule, and treat offboarding as a per-system checklist with a date and a name against each line. That record is what the third-party duties set out above on this page get answered from, rather than memory.

Two more pieces stay yours regardless of whose software it is. The first is a copy of your own data: cloud email and cloud documents get backed up separately from the platform holding them, because a deletion or a lockout inside a tenant is not repaired by that tenant. The second is who answers when the whole agency is down at six in the morning. Customers under a signed agreement have first-response targets: one hour for a P1, meaning the whole company is down or disrupted, covered around the clock; two hours for a P2, meaning three or more people cannot work or are severely degraded; four hours for a P3, a single person affected. P2 and P3 run during business hours, Monday through Friday, 8:00 AM to 5:00 PM Eastern. Those are targets for first response. They do not promise a repair time, because how long a repair takes depends on what broke.

If you want to know where the agency actually stands before the next renewal questionnaire lands, the Security Analysis at https://outreach.ttscyber.com/analysis is a $349 independent assessment mapped to 38 compliance frameworks. It does not require buying anything else, and the findings are yours either way, including the exception lists you would otherwise discover while filling out the application.

Start here

Find out where you actually stand

The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.

Questions we get asked

Which agency management systems does TTS Cyber support?

All the major ones, on one condition: the system has to carry a current support contract from its software provider. That takes in the platforms agencies in this market usually run, Applied Epic, AMS360, EZLynx and HawkSoft among them. The condition is practical rather than commercial. A system its vendor no longer supports stops receiving security patches, so the agency ends up relying on controls built around the software instead of fixes inside it, which is a different position to defend at renewal.

What are the size thresholds in the section 3965.07(A) exemption?

Section 3965.07(A) exempts a licensee from section 3965.02 if it meets any of three criteria: fewer than twenty employees, less than five million dollars in gross annual revenue, or less than ten million dollars in assets measured at the end of the licensee’s fiscal year. The statute says "any of the following criteria", so one is enough. Chapter 3965 does not define what counts as an employee and says nothing about part-time staff or contracted producers, so the threshold in division (A)(1) is not settled by the chapter’s own text. The exemption is written against section 3965.02 alone, which leaves the duties in sections 3965.03 and 3965.04 in place. TTS Cyber is not a law firm; this is not legal advice.

Which licensees does the February 15 certification filing apply to?

Insurers domiciled in this state. Section 3965.02(I)(1) sets a February 15 annual deadline for a written statement certifying compliance, and it is written for each insurer domiciled in this state. Division (I)(2) gives an insurer domiciled here and licensed exclusively to do business in Ohio an alternative: certify as part of its corporate governance annual disclosure under section 3901.073, which is a June 1 filing. Either way it is a carrier obligation. An Ohio agency or agent is a licensee under section 3965.01(M), so the security program, investigation and notification duties reach agencies, but that annual certification does not. The absence of that filing deadline is not an absence of duty. One separate filing rides with the HIPAA route in section 3965.07(B): that route works only where the licensee submits a written statement to the superintendent certifying compliance with 45 C.F.R. Parts 160 and 164 and keeps supporting records for five years. TTS Cyber is not a law firm; this is not legal advice.

Is there anything to gain from compliance beyond staying out of trouble with the department?

Yes, and Ohio put it in the statute. Section 3965.08 gives a licensee that satisfies the provisions of the chapter an affirmative defense to any cause of action sounding in tort brought under Ohio law or in Ohio courts alleging that a failure to implement reasonable information security controls resulted in a data breach concerning nonpublic information, and it does not limit any other affirmative defense otherwise available. That defense runs on evidence. A risk assessment with a date on it, a written program, training records and incident logs are the documentation that records whether the chapter was satisfied. TTS Cyber is not a law firm; this is not legal advice.

How long does a licensee have to build the program after it stops qualifying for an exemption?

Section 3965.07(D) gives a licensee that ceases to qualify for an exemption one hundred eighty days from the date it ceases to qualify to come into compliance. That is enough time to do it properly and not much more, because the risk assessment has to come first and every control in section 3965.02 is scaled to it. Start with the assessment, then multifactor authentication on email and the agency management system, encryption on every laptop and portable drive that leaves the office, no shared logins, an offboarding checklist that truly kills carrier portal access, and backups you have restored from at least once. TTS Cyber is not a law firm; this is not legal advice.

Does notice to the Ohio superintendent within three business days finish the notification duties?

Usually not. ORC 3965.04(A) sets notice to the superintendent at no later than three business days after the licensee determines a cybersecurity event occurred, but 3965.04(C) additionally requires the licensee to comply with ORC 1349.19 as applicable and to give the superintendent a copy of the notice sent to consumers. Those two clocks do not start on the same day: the three business days run from determination, while consumer notice under ORC 1349.19(B)(2) is due in the most expedient time possible and no later than forty-five days following discovery of the breach or notification of it. None of that is waived by the small-licensee exemption in ORC 3965.07(A), which is written against ORC 3965.02 and nothing else, and a single occurrence requiring notice to more than one thousand Ohio residents also pulls in notice to the nationwide consumer reporting agencies under ORC 1349.19(G). TTS Cyber is not a law firm; this is not legal advice.

Does Chapter 3965 still reach a captive agency covered under its carrier’s information security program?

Partly, and less than the carrier’s reassurance implies. ORC 3965.07(C) exempts a licensee that is an employee, agent, representative, independent contractor or designee of another licensee from section 3965.02 only to the extent it is actually covered by that other licensee’s information security program, so the exemption is measured part by part against what that program actually covers rather than granted as a status. An agency is a licensee in its own right under ORC 3965.01(M) regardless, and the duties in sections 3965.03 and 3965.04 survive that exemption entirely, because 3965.07(C) is written against section 3965.02 and nothing else. That means the prompt post-event investigation, the five-year event records, the three-business-day notice to the superintendent and the consumer notice that follows sit with the agency itself. TTS Cyber is not a law firm; this is not legal advice.

Primary sources

Read the rules yourself

Everything on this page rests on the text below. Where a section is named above, it is worth reading in the instrument rather than taking a summary for it, including this one.

TTS Cyber is an IT and cybersecurity company, not a law firm, and nothing on this page is legal advice. This page summarises published rules and cites them so they can be read directly; where this page and the source differ, the source governs. Whether a particular rule reaches a particular business, and what it requires of that business, are legal questions for that business's own attorney.

Let’s Get in Touch!

Security Analysis

Find out where you actually stand.

Most businesses do not discover a gap until something goes wrong. This is a fixed-scope analysis of your environment, run independently, so you get an answer rather than an opinion.

What the analysis covers