ARTICLE
16 December 2025

NAIC Fall Meeting Update: Cybersecurity (H) Working Group Receives Comments On Cyber Event Notification Portal

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
On December 10, 2025, the Cybersecurity (H) Working Group met to discuss, and receive comments regarding, its proposed Cybersecurity Event Notification Portal, which is contemplated to be a centralized national portal...
United States Technology
J.J. Silverstein’s articles from Foley & Lardner are most popular:
  • with readers working within the Retail & Leisure industries
Foley & Lardner are most popular:
  • within Coronavirus (COVID-19), Government and Public Sector topic(s)

On December 10, 2025, the Cybersecurity (H) Working Group met to discuss, and receive comments regarding, its proposed Cybersecurity Event Notification Portal, which is contemplated to be a centralized national portal for reporting cybersecurity events. The Working Group first noted that its work to date had been focused on achieving convergence in the implementation and operation of the Insurance Data Security Model Law (the "IDSM"), but that it had advanced to a goal of supporting state regulators with additional tools. One such tool would be a cost-reducing, centralizing, portal for implementation of Sections 6 and 7 of the IDSM. Section 6 describes insurer's obligations to notify regarding a cybersecurity event and the information that must be included. Section 7 sets forth the authority to investigate the conduct of licensed entities potentially in violation of cybersecurity laws.

At the 2024 NAIC Fall National Meeting in Denver, the Working Group passed a motion instructing the NAIC to explore the creation of a cybersecurity event notification portal, with a plan to create a simple portal to test. The project plan for the portal was posted for a public comment period from October 29 through December 1, 2025 (comments received were included in the meeting materials found here). At this meeting, interested regulators added some notes to these comments, including:

  1. That states that have not yet adopted the IDSM, but do have related reporting laws, should still have access to the reporting portal.
  2. Efficiency of the portal and submission process should be maximized.
  3. Confidentiality of the information submitted through the portal should be maximized.
  4. Fee structures for the portal should be considered.
  5. The portal should be rigorously tested by applicable regulators.

The Working Group then discussed adoption of the draft portal intake form, with various version options compared in relation to the level of detail in the information to be submitted therewith. Before adjourning, the Working Group received a presentation on the status of the Cybersecurity Insurance Market, noting an overall contraction in the admitted market, with a 12% increase the prior year in surplus lines (now approximately 57% of the Cyber market).

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More