NAIC SEP 3, 2026 · InsureAI Wire

NAIC Puts a Security Review Between Its Breach Portal and the Executive Committee

Since August 14 a security review has stood between the NAIC’s cybersecurity event notification portal and the Executive (EX) Committee, the project’s next step in the association’s own record. Michael Yaworsky, the Florida commissioner who chairs the Innovation, Cybersecurity, and Technology (H) Committee, asked NAIC committee support that day to work with Texas Commissioner Amanda Crawford on the review, citing her background in technology. He called it a novel situation with no predefined scope, suggested one component could be “a clear, easy-to-read listing of the security commitments the NAIC provides to its membership and regulated entities,” and said he hoped the review would be brief.

Yaworsky noted that the association had experienced a cybersecurity event several weeks earlier. The purpose of the discussion, he said, was not to review that event but “to acknowledge and address concerns raised afterward about the NAIC creating a portal and the data that would be housed within it.” The minutes name no incident. Our report on the NAIC’s PeopleSoft disclosure dates it June 17, 2026, roughly eight weeks before this meeting. No record connects the two.

That exchange sits in the committee’s Summer National Meeting minutes packet, dated August 31 by the NAIC, which also carries the April 30 virtual meeting where the project cleared the committee. Both sets of minutes are drafted August 27 and stamped Draft Pending Adoption. On April 30, Commissioner Marie Grant of Maryland moved and Carter Lawrence of Tennessee seconded adoption of the Cybersecurity Event Notification Portal Project Proposal. The motion passed unanimously, and the chair said the proposal would be forwarded to the NAIC Executive Committee for consideration. When we reported the project in July, that record was not public, and the brief said so.

Michael Peterson of Virginia traced the project that day, back to the Insurance Data Security Model Law (#668) and the Cybersecurity Event Response Plan, which tells state regulators how to handle a notice once one arrives. A 2024 Fall National Meeting motion directed NAIC committee support to explore creating the portal. Project documentation followed in 2025, drew multiple rounds of public comment from regulators and industry, and was adopted by the Cybersecurity (H) Working Group at its March 13, 2026, interim meeting.

The committee took up the project proposal on April 30, carried in the packet as Attachment One-A. One inconsistency survives in the draft minutes. The August 14 record has Yaworsky recalling that the portal project was adopted at the Spring National Meeting. The same packet twice puts the vote on April 30, and dates the Spring National Meeting minutes March 25.

What the security review is holding has been on the record for months. Peterson told the committee on April 30 that the NAIC had agreed to provide a SOC 3 report to industry as an assurance mechanism on its security.

Attachment One-A sets out the rest: “Data access will be highly limited to only those departments with an adopted version of MDL #668, and the responsibility for selecting those departments will be upon the licensee.” The SOC 3 would be published annually, the public version of the SOC 2 Type II the NAIC already runs each year against the Security Trust Services Criteria. A pilot rollout would cover five to ten states. The adoption target reads as a draft suggestion. Under user adoption rate the document says “Maybe consider quantifying the metric by saying something like” adoption by at least five states in Year 1.

Reporting on August 14, Peterson said the working group met June 2 in regulator-to-regulator session, where Kim Myers of the NAIC demonstrated a nonfunctional prototype. The minutes record that the proposal “has been reviewed and approved at the Working Group, Committee, and Enterprise Project Management Office (EPMO) levels, and the next step is for the Executive (EX) Committee to review and approve it.” The security review goes into that gap. Yaworsky invited questions and comments. None were raised.

The proposal prices the work three ways, all traced to an EPMO quote dated February 11, 2026. A dedicated NAIC team that already knows Appian would cost nothing beyond internal labor and take 7.5 to 8 months, an option the document flags as possibly infeasible. Training three engineers first costs $16,500 and pushes the schedule to 9.5 to 10 months. Outsourcing costs $2.1 million and comes back to 7.5 to 8. The proposal records no hard deadline, and says it is “not predicated upon the recovery of costs from licensees.” On the record’s own sequence, none of those clocks starts before the Executive (EX) Committee approves the project, and the review now standing in front of that vote has no scope written for it and no date attached. Until one starts, a licensee that determines it has had a cybersecurity event still notifies each adopting state separately, across the 28 jurisdictions Peterson counted under Section 6(B).

Share

InsureAI Wire seal IAW Source

Official document

content.naic.org →

The instrument itself, issued by a government, court, legislature, or standard-setting body.

Information aggregation and analysis, not legal advice. See our disclaimer.