New York's Department of Financial Services secured more than US$19 million in penalties from eight auto insurance companies on 14 October 2025, one of them an insurance agency, after threat actors reached consumers' driver's license numbers "via public-facing web applications and agent portals that the insurance companies used to provide automobile insurance quotes to prospective customers" (DFS). In November 2024, GEICO and Travelers had paid US$11.3 million to the state Attorney General and DFS over the same campaign, which DFS first flagged to every regulated entity in a February 2021 industry letter (DFS, 25 November 2024). In both rounds DFS concluded that the companies had not complied with 23 NYCRR Part 500. The attacks belonged to the campaign DFS had warned about in 2021, before the regulation's 2023 amendment; since 29 April 2024 the same regulation has required New York-licensed insurers, agents and brokers, unless exempt, to conduct penetration testing "from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually."
Outside New York the rules say less, and say it differently. The NAIC's Insurance Data Security Model Law, listed as adopted in 28 NAIC member jurisdictions, never uses the words "penetration testing." OSFI's Guideline B-13 names penetration testing and red teaming as examples of tests federally regulated insurers "should" perform, with no frequency. A SOC 2 point of focus says risk and control evaluations "may include" penetration testing. The FTC Safeguards Rule, which does set an annual test, generally does not reach licensed insurers at all. This guide reads each rule from its source text as it stood on 2 October 2026, for carriers (P&C, life, health and title), MGAs and MGUs, agencies and brokers, TPAs and insurtechs in the United States and Canada. It explains the rules; it is not legal advice.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office. Every human-led engagement is staffed by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, and team members are listed in the bug bounty Halls of Fame of the US Department of Defense and the US Federal Reserve. For an insurer that means a test built around the systems the regulators' own findings point at: quote and bind applications, policyholder, agent and broker portals tested across every role, the claims and document intake path, Active Directory, Microsoft 365 and Entra ID, AWS and Azure, and vishing aimed at the help desk and contact centre. It runs as a one-time annual engagement on the regulator's calendar or as a continuous program, with findings posted to the PTaaS portal as they are confirmed, retesting included, and an attestation letter on human-led and hybrid engagements. Published pricing covers one web application and its APIs (pricing); every other scope is quoted.
Quick answer: which rules require an insurance company to run a penetration test?
It depends on the licence. New York requires it by name: 23 NYCRR 500.5(a)(1) obliges covered entities, which include insurers, agents and brokers licensed under the Insurance Law, to run penetration testing from inside and outside their information systems' boundaries at least annually, unless an exemption in 500.19 removes section 500.5. The NAIC model law, adopted in some form in 28 jurisdictions, requires a written program, a risk assessment and an assessment of key controls "no less than annually," and lists "Regularly test and monitor systems and procedures to detect actual and attempted attacks on, or intrusions into, Information Systems" among the measures to implement where appropriate, without naming a penetration test; state texts vary. The FTC Safeguards Rule generally does not apply to licensed insurers, because the Gramm-Leach-Bliley Act gives enforcement for "any person engaged in providing insurance" to state insurance authorities. In Canada, OSFI Guideline B-13 and the AMF's ICT guideline expect penetration testing as one of several tests, with the frequency left to the institution. Contracts do the rest: PCI DSS 11.4 where premiums are paid by card, and carriers' periodic vendor assessments, which New York's October 2025 guidance says may consider vendors' "penetration testing summaries."

Rule or standard | Who it reaches | What the text says about testing | Requirement or expectation | Cadence in the text |
|---|---|---|---|---|
NYDFS 23 NYCRR 500.5(a)(1) | Anyone licensed under New York's Banking, Insurance or Financial Services Law | "penetration testing of their information systems from both inside and outside the information systems' boundaries" | Requirement ("shall") | At least annually |
NAIC Model Law #668, as adopted by a state | Licensees of the adopting state: insurers, producers and other licensees | "Regularly test and monitor systems and procedures to detect actual and attempted attacks" | Requirement to assess key controls; testing is a listed measure where appropriate | Key controls assessed no less than annually |
NAIC Model Regulation #673 | Licensees in states that adopted it | "Regularly tests or otherwise regularly monitors the key controls, systems and procedures" | Non-exclusive example of a method | Set by the risk assessment |
FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Financial institutions under FTC jurisdiction, not licensed insurers | Annual penetration testing absent effective continuous monitoring | Requirement, for those it covers | Annual |
PCI DSS v4.0.1, Requirement 11.4 | Entities whose card payment environment is in scope | Internal and external penetration testing | Contractual requirement | At least once every 12 months and after significant change |
HIPAA Security Rule, proposed 164.312(h)(2)(iii) | Health plans and business associates | "Perform penetration testing" | Proposed only, not in force | At least once every 12 months, as proposed |
OSFI Guideline B-13, 3.1.2 | Federally regulated insurers, including foreign insurance branches | "(e.g., penetration testing and red teaming)" | Expectation ("should") | Set by the institution |
OSFI I-CRT framework | Systemically important banks and internationally active insurance groups | Intelligence-led red team assessment overseen by OSFI | Advisory, "not a policy instrument" | Three-year supervisory cycle |
AMF ICT risk guideline (Quebec) | Insurers and other financial institutions the AMF supervises | "penetration testing and red team exercises" | Expectation ("should") | None fixed |
FSRA GR0016INT (Ontario) | Ontario-incorporated insurers and reciprocals, plus agents and agencies | "regular testing of its data management controls" | Outcomes required of Ontario insurers; testing is an example | Regular |
SOC 2, CC4.1 point of focus | Service organizations seeking a SOC 2 report | Evaluations "may include" penetration testing | Optional point of focus | None |
PIPEDA 4.7 and Quebec's private-sector act (CQLR c P-39.1), section 10 | Private-sector organizations handling personal information | Security safeguards appropriate to sensitivity | Requirement, no test named | None |
Why insurers are being tested on this now
Insurance sits inside a sector the Verizon 2026 Data Breach Investigations Report calls "a favorite among attackers." The report, covering incidents from 1 November 2024 to 31 October 2025, counted 3,809 incidents, 1,300 with confirmed data disclosure, in its Financial and Insurance sector (NAICS 52, which combines banks, insurers and other financial firms). Its industry summary lists the initial access vector breakdown for those breaches as exploitation of vulnerabilities (22%), phishing (20%) and credential abuse (15%), and says "Human error and third-party exposure remain significant contributing factors." It adds that "we saw significant examples of compromises targeting this industry being initiated by social engineering attacks against third parties this past year." The figures describe the whole sector, not insurers alone.
The New York cases show what that looks like inside an insurer. DFS's February 2021 alert described a "systemic and aggressive campaign" against "Instant Quote Websites" that displayed a redacted driver's license number back to the user. The full number was still present in the data the page received, so the redaction protected the screen and not the information. The same letter recorded a second route: attackers requested a quote, received an agent's contact details, then called the agent "using social engineering to elicit NPI from the agent." DFS urged entities to review whether public-facing sites needed to display nonpublic information at all and to "consider a quote limit per user session." For carriers that also write cyber cover, our cyber insurance statistics track that market.

New York: what 23 NYCRR 500.5 requires of insurers, agents and brokers
Who is covered
Part 500 applies to every "covered entity," which section 500.1(e) defines as "any person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether the covered entity is also regulated by other government agencies." For insurance, that reaches New York-licensed carriers wherever they are headquartered, and licensed agents, brokers and agencies. The October 2025 settlements show the reach in practice: one of the eight companies was Hagerty Insurance Agency, LLC, which agreed to pay US$1.85 million.
What the rule says
The second amendment, effective 1 November 2023, rewrote section 500.5 under the title "Vulnerability management." The adopted text reads:
Each covered entity shall, in accordance with its risk assessment, develop and implement written policies and procedures for vulnerability management that are designed to assess and maintain the effectiveness of its cybersecurity program. These policies and procedures shall be designed to ensure that covered entities: (a) conduct, at a minimum: (1) penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually; and (2) automated scans of information systems, and a manual review of systems not covered by such scans, for the purpose of discovering, analyzing and reporting vulnerabilities at a frequency determined by the risk assessment, and promptly after any material system changes; (b) are promptly informed of new security vulnerabilities by having a monitoring process in place; and (c) timely remediate vulnerabilities, giving priority to vulnerabilities based on the risk they pose to the covered entity.
Section 500.1(l) defines penetration testing as "testing the security of information systems by attempting to circumvent or defeat the security features of an information system by authorizing attempted penetration of databases or controls from outside or inside the covered entity's information systems." The amendment removed the old alternative that let a covered entity rely on effective continuous monitoring instead of annual testing. Under the transition rules in 500.22, the annual test applied from 29 April 2024, the scan and manual review obligation in 500.5(a)(2) from 1 May 2025, and multi-factor authentication "for any individual accessing any information systems of a covered entity" under 500.12 from 1 November 2025. Our NYDFS penetration testing guide works through the rest of the regulation clause by clause.
Three neighbouring clauses decide what the test has to feed. Section 500.9(a) requires the risk assessment to be reviewed and updated "at a minimum annually, and whenever a change in the business or technology causes a material change to the covered entity's cyber risk," so the scope should move with it. Section 500.14(a)(3) requires training "that includes social engineering for all personnel" at least annually. Section 500.17(b) requires an annual filing by 15 April, either a certification that the entity "materially complied" during the prior calendar year or an acknowledgment of noncompliance with a remediation timeline, signed by the highest-ranking executive and the CISO, and 500.17(b)(3) requires five years of supporting records, including "all remedial efforts undertaken" and "remediation plans and timelines for their implementation."
Which exemptions remove the annual test
Small agencies and some insurers do not have to run the annual test. The exemptions differ in what they remove:
Exemption in 500.19 | Who qualifies | Effect on the annual penetration test |
|---|---|---|
(a) Limited exemption | Fewer than 20 employees and independent contractors of the entity and its affiliates; or less than US$7,500,000 gross annual revenue in each of the last three fiscal years; or less than US$15,000,000 in year-end total assets | Removes 500.5, along with 500.4, 500.6, 500.8, 500.10, 500.14(a)(1), (a)(2) and (b), 500.15 and 500.16 |
(b) Covered by another entity's program | An employee, agent, wholly owned subsidiary, representative or designee covered by a covered entity's cybersecurity program | Exempt from Part 500 to the extent covered |
(c) No information systems or nonpublic information | Does not operate or control information systems and does not hold nonpublic information | Removes 500.5, with 500.2, 500.3, 500.4, 500.6, 500.7, 500.8, 500.10, 500.12, 500.14, 500.15 and 500.16 |
(d) Captive insurers | A covered entity under Article 70 of the Insurance Law holding nonpublic information only about its parent or affiliates | Removes 500.5, with the same list as (c) |
(e) Inactive individual brokers | An individual broker who qualifies under (c) and has not acted as a broker for at least one year | Exempt from Part 500 |
(g) Other listed persons | Including reinsurers recognized under 11 NYCRR Part 125 and individual agents in inactive status | Exempt from Part 500 |
A covered entity that qualifies for an exemption in (a) to (e) "shall file electronically a Notice of Exemption" within 30 days of determining it is exempt (500.19(f)), and one that stops qualifying for an exemption has 180 days to comply (500.19(h)). The limited exemption does not lift the rest of the regulation: the risk assessment, access privileges under 500.7, third-party service provider policies under 500.11, multi-factor authentication in the narrower form 500.12(a) sets for exempt entities, the annual social engineering training in 500.14(a)(3) and the 72-hour incident notice in 500.17 all still apply. Meeting any one of the three tests is enough, so an agency falls outside the limited exemption, and needs the annual test, only if it has 20 or more employees and independent contractors, US$7.5 million or more in gross annual revenue in at least one of the last three fiscal years, and US$15 million or more in year-end total assets, each counted with affiliates as the rule specifies.
Class A companies
A Class A company under 500.1(d) is a covered entity with at least US$20,000,000 in gross annual revenue in each of the last two fiscal years from its own business and its affiliates' New York business, plus either over 2,000 employees or over US$1,000,000,000 in gross annual revenue, counting affiliates "no matter where located." Class A status does not change 500.5, but it adds controls a test should exercise: independent audits of the cybersecurity program (500.2(c)), "a privileged access management solution" and automated blocking of commonly used passwords (500.7(c)), and "an endpoint detection and response solution to monitor anomalous activity, including but not limited to lateral movement" with "a solution that centralizes logging and security event alerting" (500.14(b)). An internal test that records when, and whether, the endpoint tooling and central logging caught each step gives the independent auditor something to examine.
Third-party service providers: 500.11 and the October 2025 guidance
Section 500.11(a) requires written policies addressing "the identification and risk assessment of third-party service providers," "minimum cybersecurity practices required to be met," "due diligence processes," and "periodic assessment of such third-party service providers based on the risk they present and the continued adequacy of their cybersecurity practices." Section 500.11(b) adds guidelines on access controls including multi-factor authentication, encryption, incident notice and "representations and warranties."
DFS's guidance on managing third-party service provider risk, issued 21 October 2025, says it "does not impose new requirements or obligations on Covered Entities," but it is explicit about what a periodic assessment can draw on: "These assessments may consider, among other things, security attestations (e.g., SOC2, ISO 27001), penetration testing summaries, policy updates, evidence of security awareness training, and compliance audits." It also says covered entities "should request updates on vulnerability management, assess patching practices, and confirm remediation of previously identified deficiencies." For an MGA, TPA, rating vendor or insurtech holding a New York carrier's nonpublic information, that is the list of documents to have ready, and a penetration test summary with retest results is on it.
What enforcement has looked like
The settlements turned on the systems a penetration test would cover. In its consent order with GEICO, applying the regulation as it stood before the 2023 amendment, DFS found that the company's "principal assessment of its risks came in the form of a 2018 penetration test/risk assessment" that "was limited in scope" and did not evaluate its claims website. It found that "the session ID for GEICO's auto insurance purchase page was a valid identifier for accessing the API" used by its agents, and that the API "received thousands of queries a day related to New Yorkers' NPI, a volume of traffic incompatible with the actual number of GEICO's New York-based auto insurance agents." An auditor had recommended penetration testing of GEICO's most critical applications, and "no such tests were performed." The order required a cybersecurity risk assessment within 30 days, an action plan within 60 days and penetration tests "of its information systems based on relevant identified risks" within 120 days, unless such tests had already been run in the fiscal year starting 1 January 2024, with results submitted to DFS within 60 days of completion.
Travelers' agent portal "was password protected but did not use multifactor authentication or any other compensating controls," and the company "did not detect the breach of its agent portal for more than seven months and was alerted to the attack by a third-party prefill data provider" (DFS). In October 2025, DFS said two of the eight companies also "failed to timely report their respective cybersecurity events." Each finding maps to something a test checks: authorization between consumer and agent functions, multi-factor authentication on every portal, whether anyone notices unusual query volume, and what a third-party data feed exposes.
The NAIC Insurance Data Security Model Law (#668) in the other states
Where it applies
The NAIC adopted the Insurance Data Security Model Law in October 2017. It applies to "Licensees," meaning "any Person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered pursuant to the insurance laws of this State," which covers insurers, producers and any other entity licensed under the state's insurance laws, including MGAs and TPAs where the state licenses them. An unlicensed vendor that holds a licensee's nonpublic information is a "Third-Party Service Provider" instead.
The NAIC's state page for Model #668, Summer 2026 edition, lists 28 NAIC member jurisdictions in its Model Adoption column: 27 states and Puerto Rico, with Tennessee noted as adopting "portions of model." They are Alabama, Alaska, Connecticut, Delaware, Hawaii, Illinois, Indiana, Iowa, Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Hampshire, North Dakota, Ohio, Oklahoma, Pennsylvania, Puerto Rico, Rhode Island, South Carolina, Tennessee, Vermont, Virginia and Wisconsin. The NAIC's August 2025 legislative brief, with its map "as of August 8, 2025," gives the same 28. New York appears only under Related Activity, cited to 23 NYCRR 500, and a drafting note in the model states that a licensee in compliance with Part 500 is intended to be in compliance with the model as well.
What it says about testing
The model text never uses the words "penetration testing." Three clauses carry the testing obligation:
Section 4C(5), a requirement. The licensee shall "Implement information safeguards to manage the threats identified in its ongoing assessment, and no less than annually, assess the effectiveness of the safeguards' key controls, systems, and procedures."
Section 4D(2)(h), a listed measure. Based on its risk assessment, the licensee shall "Determine which security measures listed below are appropriate and implement such security measures," and the list includes "Regularly test and monitor systems and procedures to detect actual and attempted attacks on, or intrusions into, Information Systems."
Section 4D(2)(e), applications. The list also includes "procedures for evaluating, assessing or testing the security of externally developed applications utilized by the Licensee," which is the clause for licensed policy administration, claims and rating platforms.
So the model fixes the outcome and the annual clock for assessing controls, and leaves the method to the risk assessment. A licensee that chooses a penetration test is choosing a way to evidence 4C(5) and 4D(2)(h), and a licensee that relies on scanning alone needs a risk assessment that explains why scanning tests whether its controls detect attacks. Wording varies by state. Of the sixteen enactments we read on 2 October 2026 (Connecticut, Delaware, Illinois, Iowa, Maine, Maryland, Michigan, Minnesota, Missouri, New Hampshire, North Dakota, Rhode Island, South Carolina, Vermont, Virginia and Wisconsin), none names penetration testing. Fifteen keep the test-and-monitor item in some form; Virginia's statute, section 38.2-623, does not list it, and we did not review Virginia's implementing regulation.
Board reporting, third parties, certification and incident notice
Board oversight (4E). Where a licensee has a board, executive management must "report in writing at least annually" on the program, including material matters such as "risk assessment, risk management and control decisions, Third-Party Service Provider arrangements, results of testing, Cybersecurity Events or violations and management's responses thereto."
Third parties (4F). A licensee "shall exercise due diligence in selecting its Third-Party Service Provider" and "shall require a Third-Party Service Provider to implement appropriate administrative, technical, and physical measures." The model gave licensees two years from the effective date to implement 4F.
Annual certification (4I). "Annually, each insurer domiciled in this State shall submit to the Commissioner, a written statement by February 15, certifying that the insurer is in compliance with the requirements set forth in Section 4 of this Act." The insurer keeps supporting records for five years and must document any areas "that require material improvement, updating or redesign" with "the remedial efforts planned and underway."
Incident notice (6A). Notice to the commissioner "as promptly as possible but in no event later than 72 hours from a determination that a Cybersecurity Event has occurred," where the state is the insurer's domicile or the producer's home state, or 250 or more of the state's consumers are involved and other criteria are met.
Exemptions, and how states changed them
Section 9A of the model exempts "A Licensee with fewer than ten employees, including any independent contractors" from Section 4, treats a licensee that maintains an information security program under HIPAA as meeting Section 4 if it "submits a written statement certifying its compliance," and exempts an employee, agent or designee who is also a licensee "to the extent" covered by another licensee's program. A licensee that stops qualifying has 180 days to comply. States moved the small-licensee line:
State | Small-licensee exemption in the enacted text |
|---|---|
South Carolina, 38-99-70 | Fewer than ten employees, including independent contractors |
Delaware, 18 Del. C. 8609 | Fewer than 15 employees |
Vermont, 8 V.S.A. 4728 | Fewer than 20 employees, including independent contractors |
Iowa, 507F.4 | Fewer than 20 individuals on its workforce, or less than US$5 million in gross annual revenue, or less than US$10 million in year-end total assets |
Illinois, 215 ILCS 215/35 | Fewer than 50 employees, including independent contractors |
Wisconsin, 601.952(9) | Less than US$10 million in year-end total assets, or less than US$5 million in gross annual revenue, or fewer than 50 employees working at least 30 hours a week |
An agency should read its own state's text, and its New York text if it holds a New York licence, because the thresholds differ.
States that have not adopted the model
In states outside the 28, the safeguards rule for insurance licensees is often an older regulation based on the NAIC's Standards for Safeguarding Customer Information Model Regulation (#673), adopted in 2002 to implement GLBA section 501(b) for insurance. The NAIC's Fall 2024 state page for #673 lists adoptions including California, Florida and New Jersey. Its testing language is permissive: the licensee "Regularly tests or otherwise regularly monitors the key controls, systems and procedures of the information security program," with frequency and nature "determined by the licensee's risk assessment," and section 5 calls that one of several "non-exclusive illustrations of actions and procedures that licensees may follow."
How regulators check
The NAIC's compliance and enforcement guide for the model says an insurance department's review "can take the form of a market regulation examination" or "the IT Review performed during a financial condition examination," and calls the IT Review "the most obvious source of compliance." It recommends that other states rely on a domestic regulator's 4I certificate and, for New York-domiciled licensees, on the 500.17(b) certificate. So the test report, the retest and the remediation record are likely to be read by an IT examiner, and should be written for one.
Why the FTC Safeguards Rule usually does not apply to insurers
The FTC's Safeguards Rule names annual penetration testing, so it is easy to assume it covers insurers. It generally does not bind a licensed insurer, agent or broker, and the reason is in the statute. 15 U.S.C. 6801(b) tells each "agency or authority described in section 6805(a)" to set safeguards standards for "the financial institutions subject to their jurisdiction." Section 6805(a)(6) assigns enforcement "Under State insurance law, in the case of any person engaged in providing insurance, by the applicable State insurance authority of the State in which the person is domiciled," and 6805(a)(7) leaves the FTC "any other financial institution or other person that is not subject to the jurisdiction of any agency or authority under paragraphs (1) through (6)." The rule itself, at 16 CFR 314.1(b), applies to financial institutions "not otherwise subject to the enforcement authority of another regulator under section 505." State insurance regulators wrote Model #673 for exactly that purpose.
Two cautions. First, the FTC rule is still a useful benchmark for an unlicensed vendor, because it sets annual penetration testing and six-month vulnerability assessments absent effective continuous monitoring. Second, a business in the insurance chain that is not "engaged in providing insurance," such as a data or payments company serving carriers, may fall under the FTC rule if it is significantly engaged in a financial activity; that is a question for counsel. Our FTC Safeguards Rule guide explains who the rule does cover.
Health insurers and TPAs: the HIPAA Security Rule
Health plans are HIPAA covered entities, and the proposed changes would reach their business associates as well. The current HIPAA Security Rule does not name penetration testing. In its January 2025 proposed rule (90 FR 898), HHS proposed a new 164.312(h)(2)(iii): "Perform penetration testing of the covered entity's or business associate's relevant electronic information systems by a qualified person," at least "once every 12 months or in accordance with the covered entity's or business associate's risk analysis ... whichever is more frequent." It is not in force. The 2026 Unified Agenda entry for RIN 0945-AA22 lists the rule under Long-Term Actions with final action planned for July 2027. Under the NAIC model, a health insurer that maintains a HIPAA program and certifies compliance is treated as meeting Section 4, so a health carrier's HIPAA risk analysis is the natural place to record its testing decision.
Canada: OSFI, the AMF, FSRA and privacy law
OSFI Guideline B-13 for federally regulated insurers
Guideline B-13, Technology and Cyber Risk Management, published in July 2022 and effective 1 January 2024, applies to all federally regulated financial institutions, and OSFI lists life insurance and fraternal companies, property and casualty companies and foreign insurance branches among its sectors. Section 3.1.2 reads:
FRFIs should adopt a risk-based approach to threat assessment and testing. FRFIs should set defined triggers, and minimum frequencies, for intelligence-led threat assessments to test cyber security processes and controls. FRFIs should also regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach.
Every verb is "should": B-13 is a guideline setting supervisory expectations, not a statute. The defined triggers and minimum frequencies attach to intelligence-led threat assessments; penetration testing and red teaming are examples of the tests and exercises an insurer should regularly perform, and B-13 sets no cadence for them. Section 3.1.3 separately expects "regular vulnerability assessments" with processes that "articulate the frequency." OSFI's incident reporting advisory adds a firm clock: an insurer "must report a technology or cyber security incident" to OSFI "within 24 hours, or sooner if possible." Our OSFI B-13 guide sets out what a defensible cadence looks like.
Guideline B-10: what reaches MGAs, TPAs and vendors
Federal insurers carry B-13 into their supply chain through Guideline B-10, Third-Party Risk Management. Among the due diligence factors for high-risk and critical arrangements, Annex 1 lists "The third party's capacity to: manage technology and cyber risks in accordance with the expectations outlined in OSFI's Guideline B-13," and Principle 8 says a federal insurer "should also have the right to conduct or commission an independent audit of a third party." A Canadian MGA, TPA or claims platform serving a federal carrier should expect to be asked for testing evidence on that basis.
OSFI I-CRT: four insurance groups in scope
OSFI's Intelligence-led Cyber Resilience Testing framework, an advisory dated 1 April 2023, says of itself: "This document is not a policy instrument used to set regulatory expectations." Its "current scope" covers all systemically important banks and internationally active insurance groups (IAIGs), with an I-CRT recommended once per three-year supervisory cycle and event-driven assessments where risk warrants. Other institutions "may request an I-CRT assessment." OSFI's register of OSFI-regulated IAIGs names four: Canada Life Assurance Company, Intact Financial Corporation, Manufacturers Life Insurance Company and Sun Life Assurance Company of Canada. The IAIS register, as of 3 June 2026, lists the same four with OSFI as group-wide supervisor. Other federally regulated insurers plan around B-13. Our I-CRT guide covers how those exercises run.
The AMF in Quebec
The AMF's Guideline on Information and Communications Technology Risk Management, dated February 2020 and listed among its guidelines for insurers, expected institutions to adopt its expectations by 27 February 2021. Its appendix of complementary standards says: "The financial institution should subject its information security controls to various types of periodic independent assessments, tests and reviews as well as penetration testing and red team exercises." A footnote adds a caution worth repeating to a board: "penetration testing and vulnerability assessments are not substitutes for an ICT risk assessment." Like B-13, it is an expectation, and it sets no fixed frequency.
FSRA in Ontario
FSRA's IT risk management guidance (GR0016INT), effective 1 April 2024, does not name penetration testing. It says Ontario-incorporated insurance companies and reciprocals "must achieve the desired outcomes" of its practices to satisfy the Insurance Act, lists "Conducts regular testing of its data management controls and develops a process for addressing deficiencies" among the characteristics supervisors look for, and requires those insurers to notify FSRA of a material IT risk incident "no later than 72 hours" after determining it occurred. It also applies an approach section to agents, agencies, adjusters and to federally or other-province incorporated insurers licensed in Ontario, and says FSRA considers insurers responsible for "ensuring that IT risks are being effectively managed through all of its distribution channels and outsourced functions."
Privacy statutes
PIPEDA's Principle 4.7 requires that "Personal information shall be protected by security safeguards appropriate to the sensitivity of the information" (Justice Laws). Quebec's private-sector privacy act requires an enterprise to "take the security measures necessary to ensure the protection of the personal information" that "are reasonable given the sensitivity of the information" (section 10) and, since Law 25, to notify the Commission d'accès à l'information of a confidentiality incident that "presents a risk of serious injury" (section 3.5) (LegisQuébec). Neither names a test. For insurers holding health, financial and claims data, a penetration test is one way to show the safeguards are proportionate to that sensitivity.
SOC 2 for insurtechs, MGAs and TPAs that serve carriers
For an insurtech or service provider, the trigger is often a carrier's vendor review, and DFS's October 2025 guidance shows what such a review may draw on: SOC 2 or ISO 27001 attestations and penetration testing summaries. The AICPA's 2017 Trust Services Criteria, with points of focus revised in 2022, address evaluations under CC4.1: "The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning." The 2022 point of focus says that, "Depending on the entity's objectives, such risk and control evaluations may include first- and second-line monitoring and control testing, internal audit assessments, compliance assessments, resilience assessments, vulnerability scans, security assessment, penetration testing, and third-party assessments." The criteria also state that "Use of the trust services criteria does not require an assessment of whether each point of focus is addressed."
So SOC 2 itself does not require a penetration test. If a carrier contract requires one, or a service organization writes one into its own control description, the carrier and the auditor will look for it. A published Stingrai case study shows the pattern: a London B2B insurtech building a financial intelligence platform for insurers and captives had its application, infrastructure and integrations tested, and its founder said the findings "were presented clearly, with practical remediation steps that were easy to understand and prioritize" (case study). Our SOC 2 penetration testing guide covers timing inside a Type 2 period.
PCI DSS where premiums are paid by card
Where an insurer, agency or MGA takes premium payments by card, PCI DSS applies to the cardholder data environment. PCI DSS v4.0.1 has been the only active version since v4.0 retired on 31 December 2024, and the PCI Security Standards Council says the revision has "no additional or deleted requirements" (PCI SSC). Requirements 11.4.2 and 11.4.3 call for internal and external penetration testing "At least once every 12 months" and "After any significant infrastructure or application upgrade or change," by "a qualified internal resource or qualified external third-party," with "Organizational independence of the tester" (wording quoted from the PCI SSC's SAQ D for Merchants for PCI DSS v4.0). Requirement 11.4.4 requires exploitable findings to be corrected and the testing repeated, and 11.4.5 tests segmentation where it is used to reduce scope. How much of 11.4 applies depends on how the payment page is built and which validation route applies. Our PCI DSS Requirement 11.4 guide explains the scoping.
What to test at an insurer
None of these rules lists targets. The New York findings, the AMF and OSFI guidelines and the vendor-oversight clauses point at the same eight areas.

Area | Why it is in scope | What to test |
|---|---|---|
Quote and bind applications and APIs | DFS February 2021 alert; GEICO consent order | Whether redacted fields arrive unredacted in the response, rate limits and quote-per-session limits, prefill API authorization, tampering with rating inputs between quote and bind |
Agent and broker portals | Travelers settlement: no MFA, breach undetected for more than seven months | Multi-factor authentication on every sign-in path, agency hierarchy and book-of-business isolation, report exports, session reuse between consumer and agent functions |
Policyholder portals and mobile apps | 500.12 MFA; 4D(2)(a) access controls | One policyholder reaching another's policy, claim or payment record by changing an identifier, account recovery flows |
Claims systems and document intake | GEICO's limited 2018 test skipped the claims website | Upload handling, claim file access across adjusters and claimants, and AI document processing tested for prompt injection through submitted files |
Active Directory and Microsoft 365 | Verizon 2026 Data Breach Investigations Report, Financial and Insurance: Phishing (20%) and Credential abuse (15%) in the initial access vector breakdown (breaches) | Path from one phished user to domain admin, Entra ID Conditional Access exclusions, mailbox rules used in payment fraud |
Cloud (AWS and Azure) | 500.5(a)(1) "their information systems"; B-13 3.1.3 | Identity and role paths, storage exposure for claims documents, management-plane access |
Help desk and contact centre | DFS vishing advisory, 6 February 2026; 2021 alert on calls to agents | Vishing for password and MFA resets, policyholder account takeover by phone, payment-change requests |
Third-party integrations | 500.11; NAIC 4F; OSFI B-10; Verizon on third-party exposure | Prefill and data providers, MGA and TPA connections, rating and policy platforms, within what each vendor permits in writing |
Two of those rows need care in planning. AI document processing in claims intake is a newer path: a model that reads submitted documents and passes its output to downstream systems can be steered by instructions hidden in a file, which is why it belongs in an AI and LLM penetration test scope rather than a standard web test. And for the help desk and contact centre, DFS's February 2026 advisory describes attackers "posing as IT help desk staff in calls to personnel" to collect "login credentials and multi-factor authentication (MFA) codes"; it recommends procedures to "confirm the identity of individuals requesting credential resets, remote access, or other activity," and a social engineering engagement that calls both staff and the help desk is how you find out whether those procedures hold. Portals and APIs map to web application penetration testing, the tenant and identity layer to cloud penetration testing and Active Directory assessment.
Carriers with their own offensive security team
Some carriers run their own offensive security teams, and the rules allow internal testers: Part 500 accepts "a qualified internal or external party," and PCI DSS accepts "a qualified internal resource" with organizational independence. An external engagement still adds value in three forms. A purple team exercise runs real attack techniques with the carrier's SOC watching, so detection gaps are fixed during the week rather than written up after it. An assumed-breach or intelligence-led red team tests the scenario B-13 3.1.2 describes, starting from threat intelligence about who targets insurers. And an independent test of the systems the internal team built or operates gives a Class A auditor or an OSFI supervisor evidence that does not mark its own homework.
How often an insurer should test
The answer differs by regime, and the strictest one that applies sets the calendar.
New York covered entities: at least annually under 500.5(a)(1), with scans and manual review "promptly after any material system changes" under 500.5(a)(2), and a risk assessment updated at least annually and on material change.
NAIC model states: key controls assessed "no less than annually" under 4C(5); the method and frequency of testing come from the risk assessment.
Card payments: at least every 12 months and after significant change under PCI DSS 11.4.
Federal insurers in Canada: at a frequency the insurer defines and can defend under B-13; once per three-year supervisory cycle for the four IAIGs under I-CRT.
Insurtechs and service providers: whatever the carrier contract and the SOC 2 control description say, timed so the report reaches the carrier before its next review.
A one-time annual engagement timed ahead of the 15 April certification in New York, or ahead of the domestic certification date in a model-law state (15 February in the model; Wisconsin, for example, uses 1 March), covers the calendar. Continuous testing suits insurers whose quote, portal and claims applications change every sprint, because PCI DSS ties penetration testing, and Part 500 ties scans and manual review, to change as well as to the calendar.
Scoping inputs and what it costs
Insurance tests are scoped on the same inputs as any other, with a few that are specific to the business:
Applications and roles: each quote, policyholder, agent, broker and adjuster portal, and the number of distinct roles to test in each.
APIs: rating, quote and bind, prefill, payment and claims APIs, including partner-facing ones.
Identity and internal estate: Active Directory domains, Entra ID tenants and user counts.
Cloud: AWS and Azure accounts or subscriptions that hold policy and claims data.
External footprint: internet-facing IP ranges, VPNs and remote access.
People: vishing scenarios for the help desk and contact centre, and phishing for underwriting and claims staff.
Third parties: integrations in scope, each with the vendor's written permission.
Retest: confirmation that every fix holds, which every regime above relies on.
Our penetration testing cost guide gives 2026 market bands aggregated from published vendor pricing and industry cost guides: about US$5,000 to US$30,000 for a web application, US$6,000 to US$30,000 for an API, US$5,000 to US$40,000 for an external or internal network, US$10,000 to US$50,000 for cloud, US$12,000 to US$25,000 for a PCI DSS scope and US$50,000 to US$150,000 or more for an annual enterprise program. A mid-size carrier testing several portals, its cloud, Active Directory and its contact centre will land well above a single-application price.
Stingrai publishes prices for two packages, each covering exactly one web application and its APIs, such as a policyholder portal or a quote and bind flow. An Autonomous Pentest, in which Snipe, Stingrai's AI agent for web applications and their APIs, tests alone, is at US$3,000 per one-time assessment or US$650 per month on a 12-month continuous plan. A Hybrid Pentest, in which Stingrai's penetration testers and Snipe test together throughout, is at US$6,800 per one-time assessment or US$1,275 per month on a 12-month continuous plan, and includes an attestation letter. The "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier only. Everything else in an insurance scope, including more applications, networks, Active Directory, cloud, social engineering and red teaming, is quoted through get a quote; current figures are on the pricing page.
What the report must show a regulator or a carrier
A test that cannot be followed from scope to fix will not help at a DFS or state examination, an OSFI supervisory review or a carrier's vendor assessment. Build the report and the file around what each reader checks.
What to include | Why | Who reads it |
|---|---|---|
Scope tied to the risk assessment, with systems listed | 500.5 runs "in accordance with its risk assessment"; NAIC 4C; GEICO's narrow 2018 test | Examiner, auditor |
Inside and outside coverage, stated plainly | 500.5(a)(1) "from both inside and outside the information systems' boundaries" | DFS examiner |
Tester identity and qualifications | "a qualified internal or external party"; PCI DSS "qualified" and independent | Examiner, QSA, carrier |
Method, dates and rules of engagement | Shows what was and was not tested | All readers |
Findings with severity, evidence and remediation advice | Feeds 500.5(c) risk-based remediation | Remediation owners |
Retest results and a remediation record | 500.17(b)(3) "all remedial efforts undertaken"; NAIC 4I "remedial efforts planned and underway" | Examiner, auditor |
Detection notes | Whether logging and alerting saw the test; Class A 500.14(b) | CISO, independent auditor |
Board-level summary | NAIC 4E "results of testing"; 500.4 CISO report | Board |
Short attestation or summary for third parties | DFS guidance names "penetration testing summaries" | Carriers, partners |
Keep the full report in the compliance file for at least five years if you certify under Part 500 or the model law, and share the summary or attestation letter, not the full report, with carriers and partners.
Insurance penetration testing checklist
Nine steps take an insurer, MGA, agency or insurtech through one testing year.
Map your licences and regimes. List every state and province where you hold a licence, whether you are a New York covered entity, Class A, or exempt under 500.19, whether your domicile adopted Model #668 and on what terms, and whether OSFI, the AMF or FSRA supervises you.
Confirm or file exemptions. If 500.19(a) applies, file the Notice of Exemption within 30 days and record what still applies; if a state threshold applies, keep the employee, revenue and asset counts that support it.
Update the risk assessment. Record the systems that hold nonpublic information and the systems connected to them, including quote, portal, claims, cloud and third-party integrations.
Set the cadence in writing. Use the strictest applicable rule: annual for New York and PCI DSS, the insurer-defined frequency for B-13, and retesting after material change.
Scope the test from the risk assessment. Cover the external perimeter, the internal network and Active Directory, Microsoft 365 and cloud, every portal and API role, claims intake including AI processing, and the help desk and contact centre.
Contract the tester as a service provider. Apply your 500.11, 4F or B-10 process to the tester, including access, encryption and confidentiality terms, and get written permission from any third party whose systems are in scope.
Fix, retest and record. Track each finding to closure, retest it, and keep the remediation record the certification relies on.
Report to the board and certify. Put the results of testing, open risks and remediation plans into the annual board report, then file the 15 April certification in New York or your domiciliary state's certification, which the model sets at 15 February.
Answer carrier and partner reviews with a summary. Share a short summary or attestation letter with retest status, and keep the full report for examiners and auditors.
How Stingrai supports an insurance testing program
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For an insurer, that translates into a test built to the scope above. Quote and bind flows and policyholder, agent, broker and adjuster portals are tested authenticated across every role, hunting broken authorization, IDOR and business logic flaws such as a policy, claim or quote identifier that answers to the wrong session. The internal network and Active Directory are assessed for ACL abuse and Kerberos and delegation paths to domain admin, Microsoft 365 and Entra ID for consent grants and Conditional Access gaps, and AWS and Azure from the control plane to the workload. Claims intake that uses AI is tested for prompt injection and insecure output handling, and vishing and phishing aimed at the help desk, contact centre, underwriting and claims staff test the people the regulators keep writing about. Carriers with their own offensive teams can run the work as a purple team exercise with their SOC or as an assumed-breach or intelligence-led red team.
Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications staff every human-led engagement, reviewed by the team lead and an engagement partner, and the team has published 18 CVEs. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, with live chat to the testers and Jira and Slack integration. Retesting of remediated findings is included, human-led and hybrid engagements include an attestation letter, and Enterprise engagements add high-level management and post-remediation executive reports. Engagements run as a one-time annual test ahead of the certification deadline or as a continuous program across the year. Snipe covers web applications and their APIs, alone on the Autonomous tier and together with the penetration testers on a Hybrid engagement, where the testers direct where it digs. The firm-level accreditation is listed on the CREST Marketplace, and Stingrai is rated 5.0 from 20 reviews on Clutch. Stingrai's penetration testing supports your Part 500, NAIC model law, OSFI B-13, SOC 2 and PCI DSS programs with pentest evidence your examiners, auditors and carriers can follow from scope to retest. For how other providers compare on insurance work, see our ranking of insurance penetration testing companies.
Frequently Asked Questions
Does the NAIC Insurance Data Security Model Law require penetration testing?
Not by name. The model never uses the words "penetration testing." Section 4C(5) requires a licensee to assess the effectiveness of its key controls, systems and procedures no less than annually, and Section 4D(2)(h) lists "Regularly test and monitor systems and procedures to detect actual and attempted attacks on, or intrusions into, Information Systems" among the measures a licensee implements where its risk assessment finds them appropriate. A penetration test is a direct way to evidence both. None of the sixteen state enactments we read adds penetration testing by name, so check your domiciliary state's text.
Do insurance agencies and brokers in New York need a penetration test?
Yes, unless an exemption applies. Agents, brokers and agencies licensed under New York's Insurance Law are covered entities under 23 NYCRR 500.1(e), and section 500.5(a)(1) requires penetration testing from inside and outside the information systems' boundaries at least annually. An agency covered by the limited exemption in 500.19(a), or an individual agent covered by an employer's or carrier's cybersecurity program under 500.19(b), does not have to run the annual test. DFS's October 2025 settlements over auto insurance quoting tools included an insurance agency.
Are small insurance agencies exempt?
Often, but only partly. In New York, 500.19(a) exempts covered entities with fewer than 20 employees and independent contractors, less than US$7.5 million in gross annual revenue in each of the last three fiscal years, or less than US$15 million in year-end total assets from the annual test and several other sections, but not from the risk assessment, multi-factor authentication, third-party service provider policies, training or incident notice, and the agency must file a Notice of Exemption within 30 days. Under the NAIC model, a licensee with fewer than ten employees is exempt from Section 4, and states changed that line: 15 employees in Delaware, 20 in Vermont, 50 in Illinois, with revenue and asset tests in Iowa and Wisconsin.
Does the FTC Safeguards Rule apply to insurance companies?
Generally not to licensed insurers, agents or brokers. Under 15 U.S.C. 6805(a)(6), the Gramm-Leach-Bliley Act's safeguards standards are enforced for any person engaged in providing insurance by the state insurance authority of the state where the person is domiciled, and the FTC rule at 16 CFR 314.1(b) covers only financial institutions not subject to another regulator under section 505. State insurance regulators set the standard instead, through the NAIC models and New York's Part 500. A company in the insurance chain that does not provide insurance may still be covered by the FTC rule, which is a question for counsel.
Do Canadian insurers need penetration testing under OSFI B-13?
OSFI expects it, without setting a frequency. Section 3.1.2 of Guideline B-13, effective 1 January 2024 for all federally regulated insurers, says institutions should regularly perform tests and exercises, giving penetration testing and red teaming as examples, using an intelligence-led approach. It is a guideline, so the wording is should rather than must, and the defined triggers and minimum frequencies attach to intelligence-led threat assessments. The four Canadian insurance groups OSFI identifies as internationally active also fall within the I-CRT framework, which recommends an intelligence-led red team exercise once per three-year supervisory cycle.
Does an MGA or TPA need a penetration test for carrier due diligence?
Often, because the carrier's own rules require it to assess its vendors, and a penetration test summary is one of the documents those assessments draw on. New York's 500.11 requires covered carriers to assess third-party service providers periodically, and DFS's October 2025 guidance says those assessments may consider SOC 2 or ISO 27001 attestations and penetration testing summaries. The NAIC model requires due diligence in selecting service providers, and OSFI's Guideline B-10 asks federal insurers to assess a third party's capacity to manage technology and cyber risks under B-13. A licensed MGA or TPA may also be a licensee or covered entity in its own right.
How often should an insurer run a penetration test?
At least annually where New York's Part 500 or PCI DSS applies, and again after significant change where PCI DSS applies. New York requires annual testing for covered entities, PCI DSS requires internal and external tests at least every 12 months and after significant change, and the NAIC model requires key controls to be assessed no less than annually. OSFI B-13 leaves the frequency to the insurer, and the four internationally active insurance groups follow a three-year cycle for I-CRT. Insurers whose portals and quote applications change often can test continuously instead of once a year.
What should a penetration test report include for regulators?
A scope tied to the risk assessment and listing the systems tested, a statement that testing covered both inside and outside the boundaries, the testers' identities and qualifications, the method, dates and rules of engagement, findings with severity, evidence and remediation advice, retest results, and notes on whether monitoring detected the test. New York requires five years of records supporting the annual certification, including remedial efforts and remediation plans, and the NAIC model requires insurers to document areas needing material improvement. Carriers and partners can be given a summary or attestation letter instead of the full report.
How much does an insurance penetration test cost?
It depends on scope. Stingrai's 2026 cost guide puts a single web application at about US$5,000 to US$30,000, an API at US$6,000 to US$30,000, an external or internal network at US$5,000 to US$40,000, cloud at US$10,000 to US$50,000 and an annual enterprise program at US$50,000 to US$150,000 or more. Stingrai's published prices for one web application and its APIs are US$3,000 per one-time assessment for an Autonomous Pentest and US$6,800 for a Hybrid Pentest, or US$650 and US$1,275 per month on 12-month continuous plans. Wider insurance scopes are quoted.
Related reading
OSFI B-13 and I-CRT: Who Needs Intelligence-Led Red Teaming in Canada
PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)
References
New York State Department of Financial Services. Second Amendment to 23 NYCRR 500, adopted text. Effective 1 November 2023. https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf. Sections 500.1, 500.2(c), 500.5, 500.7(c), 500.9(a), 500.11, 500.12, 500.14, 500.17, 500.19 and 500.22.
New York State Department of Financial Services. DFS Secures More than $19 Million from Auto Insurance Companies over Data Breaches. 14 October 2025. https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20251014.
New York State Department of Financial Services. Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches. 25 November 2024. https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20241125.
New York State Department of Financial Services. In the Matter of Government Employees Insurance Company, Consent Order. November 2024. https://www.dfs.ny.gov/system/files/documents/2024/11/ea20241125-geico.pdf.
New York State Department of Financial Services. Cyber Fraud Alert on Nonpublic Information (NPI), industry letter. 16 February 2021. https://www.dfs.ny.gov/industry_guidance/industry_letters/il20210216_cyber_fraud_alert.
New York State Department of Financial Services. Guidance on Managing Risks Related to Third-Party Service Providers, industry letter. 21 October 2025. https://www.dfs.ny.gov/industry-guidance/industry-letters/il20251021-guidance-managing-risks-third-party.
New York State Department of Financial Services. Cybersecurity Advisory: Targeted Vishing Attacks, industry letter. 6 February 2026. https://www.dfs.ny.gov/industry-guidance/industry-letters/20260206-cybersecurity-advisory-targeted-vishing-attacks.
National Association of Insurance Commissioners. Insurance Data Security Model Law (#668). Adopted 4th quarter 2017, technical edit 2025. https://content.naic.org/sites/default/files/model-law-668.pdf.
National Association of Insurance Commissioners. Insurance Data Security Model Law, state page, NAIC Model Laws, Regulations, Guidelines and Other Resources, Summer 2026. https://content.naic.org/sites/default/files/model-law-state-page-668.pdf.
National Association of Insurance Commissioners. The NAIC Insurance Data Security Model Law, legislative brief. August 2025, map status as of 8 August 2025. https://content.naic.org/sites/default/files/government-affairs-brief-data-security-model-law.pdf.
National Association of Insurance Commissioners. Insurance Data Security Model Law #668, Compliance and Enforcement Guide. https://content.naic.org/sites/default/files/inline-files/IDSM%20Compliance%20Guide%20Final.pdf.
National Association of Insurance Commissioners. Standards for Safeguarding Customer Information Model Regulation (#673). Adopted 2002. https://content.naic.org/sites/default/files/model-law-673.pdf. State page, Fall 2024: https://content.naic.org/sites/default/files/model-law-state-page-673.pdf.
State insurance data security statutes read for this guide: S.C. Code 38-99; 18 Del. C. 8601 to 8611; Iowa Code 507F; 215 ILCS 215; Mich. Comp. Laws 500.555; Minn. Stat. 60A.9851; N.D. Cent. Code 26.1-02.2; N.H. RSA 420-P:4; Conn. Gen. Stat. 38a-38; Va. Code 38.2-621 to 38.2-629; Wis. Stat. 601.952; 24-A M.R.S. 2264; Md. Code, Ins. 33-103; R.I. Gen. Laws 27-1-46; 8 V.S.A. 4728; Mo. Rev. Stat. 375.1405. Each read on the state legislature's official site.
United States Code. 15 U.S.C. 6801 and 6805. 2024 edition, govinfo. https://www.govinfo.gov/content/pkg/USCODE-2024-title15/html/USCODE-2024-title15-chap94-subchapI-sec6805.htm.
Electronic Code of Federal Regulations. 16 CFR 314.1 and 314.4. Title 16 up to date as of 30 September 2026. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314.
US Department of Health and Human Services. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, proposed rule. 90 FR 898, 6 January 2025. https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information. Status: 2026 Unified Agenda, RIN 0945-AA22, https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22.
Office of the Superintendent of Financial Institutions. Guideline B-13, Technology and Cyber Risk Management. Effective 1 January 2024. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/technology-cyber-risk-management.
Office of the Superintendent of Financial Institutions. Technology and Cyber Security Incident Reporting, advisory. 13 August 2021. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/technology-cyber-security-incident-reporting.
Office of the Superintendent of Financial Institutions. Guideline B-10, Third-Party Risk Management. April 2023. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/third-party-risk-management-guideline.
Office of the Superintendent of Financial Institutions. OSFI's Intelligence-led Cyber Resilience Testing (I-CRT) Framework, advisory. 1 April 2023. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework.
Office of the Superintendent of Financial Institutions. Register of OSFI-Regulated Internationally Active Insurance Groups. 2 February 2022. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/register-osfi-regulated-internationally-active-insurance-groups.
International Association of Insurance Supervisors. Register of Internationally Active Insurance Groups. As of 3 June 2026. https://www.iais.org/register-of-iaigs/.
Autorité des marchés financiers. Guideline on Information and Communications Technology Risk Management. February 2020. https://lautorite.qc.ca/en/professionals/insurers/guidelines/operational-risk/guideline-on-information-and-communications-technology-risk-management.
Financial Services Regulatory Authority of Ontario. Information Technology (IT) risk management, GR0016INT. Effective 1 April 2024. https://www.fsrao.ca/regulation/guidance/information-technology-it-risk-management.
Justice Laws Website. Personal Information Protection and Electronic Documents Act, Schedule 1, Principle 4.7. https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html.
LegisQuébec. Act respecting the protection of personal information in the private sector, CQLR c P-39.1, sections 3.5 and 10. https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1.
AICPA. 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus, 2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022.
PCI Security Standards Council. Just Published: PCI DSS v4.0.1. 11 June 2024. https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1. Requirement text from PCI DSS v4.0 Self-Assessment Questionnaire D for Merchants, https://listings.pcisecuritystandards.org/documents/PCI-DSS-v4-0-SAQ-D-Merchant.pdf.
Verizon. 2026 Data Breach Investigations Report. May 2026. https://www.verizon.com/dbir. Financial and Insurance industry summary.
Stingrai. Pricing. https://www.stingrai.io/pricing. Published one-time and continuous prices for one web application and its APIs.
Ready to scope an insurance penetration test?
New York names the test, the annual clock and the inside-and-outside scope; the NAIC model and OSFI B-13 leave the method to your risk assessment; carriers and card brands fill in the rest by contract. Stingrai's penetration testing supports your insurance compliance program with two named penetration testers on every human-led engagement, retesting, and an attestation letter on human-led and hybrid engagements, as a one-time annual engagement or as continuous coverage across the year. Book a free scoping call, get a quote for a portal, cloud, Active Directory and social engineering scope, or read the published package prices on the pricing page.



