Insurance agencies and title
The Safeguards Rule, Part 500, carrier appointments, and the lender's vendor questionnaire. We know the paper each one arrives on.
What arrives
- The Safeguards Rule
- FTC Standards for Safeguarding Customer Information, 16 CFR Part 314. Nine elements, a designated qualified individual, and a written program.
- Part 500
- NYDFS 23 NYCRR Part 500. The annual Certification of Material Compliance, or an Acknowledgement of Noncompliance, due April 15.
- Pillar 3
- ALTA Best Practices Framework, Pillar 3. A written information security plan and a written privacy plan, asked for by the lender rather than by a regulator.
- The lender questionnaire
- Third-party oversight under CFPB Bulletin 2012-03, arriving as the lender's own onboarding checklist.
- The renewal
- The cyber-insurance renewal application. Multi-factor authentication, endpoint detection, backups and an incident plan, each attested with evidence.
What the Institute has found here
The Vigil LibraryInstitute
Email Spoofability Across Insurance Agencies
Field finding · June 2026
Read itInstitute
The Safeguards Rule at Scale: FTC Enforcement Patterns and Agency Management System Risk in Independent Insurance Agencies
Policy · June 2026
Read itInstitute
The Vendor as the Vector: Third-Party Risk Management Across Veterinary and Insurance Networks
Field notes · June 2026
Read itStart the conversation
A short, plain conversation about the outside view, with an advisor who knows the paper.

