Network Security Checklist
Access Control and Authentication
NYDFS Part 500.12(b) requires MFA for any individual accessing internal networks from an external network — including TPAs, claims vendors, and contractors with VPN access. Pull the IdP report (Okta, Entra ID, Duo) and confirm 100% coverage on remote access, privileged accounts, and any system holding NPI. Treating MFA as employee-only is the single most common Part 500 finding.
Pull the access list from PolicyCenter / ClaimCenter / Applied Epic and have each business owner attest. Common gotchas: terminated producers still appointed in the AMS, claims examiners with cross-LOB access, and shared service accounts for batch jobs.
Underwriters should not see claim notes; claims examiners should not see actuarial pricing files; producers should only see their book. Verify RBAC in the AMS, document management system (ImageRight, ePolicy), and any SharePoint or shared drive holding loss runs or claim packets.
Confirm minimum 8 characters, breached-password screening, no forced periodic rotation absent compromise. NYDFS expects documented password controls; GLBA Safeguards rule expects screening against known-breached credentials.
Network Monitoring and Intrusion Detection
Confirm IDS/IPS sensors cover all ingress/egress points and the segments holding policy and claims data. Validate rules are current and that alerts route to the on-call SOC queue, not a shared mailbox.
Review the past quarter of authentication, file-access, and admin-action logs in Splunk / Sentinel / Elastic. Flag bulk exports of claim files, after-hours producer logins, and any access from outside expected geographies.
NYDFS Part 500.5 requires annual pen testing or continuous monitoring equivalent. Scope must include the AMS, any portal exposing insured or claimant data, and the VPN. Capture the report and remediation tracker for the exam file.
Pull firmware versions on perimeter firewalls, core switches, and VPN concentrators. Apply vendor-current versions or document a compensating control. Outdated edge firmware is a common finding in market-conduct cyber reviews.
Data Protection and Encryption
Part 500.15 requires encryption of NPI in transit over external networks and at rest, or a CISO-approved compensating control. Check policy and claim databases, document repositories, backup volumes, and any SFTP exchange with carriers, reinsurers, or TPAs.
Confirm DLP fingerprints match real fields: claim numbers, SSNs on ACORD 130 workers comp apps, claimant medical records under HIPAA. Review the past quarter's DLP alerts — false positive rate above ~30% means the rules need retuning.
Restore a known recent backup of PolicyCenter / ClaimCenter / AMS to an isolated environment and validate data integrity. Backups that have never been test-restored are a common gap discovered during a real ransomware event.
Most states require 5–7 years of policy and claim file retention; workers comp often requires 10+ years given lifetime medical exposure. Confirm the destruction calendar honors the longest applicable retention and that the disposal vendor (often a Part 500 §500.11 covered third party) returns certificates of destruction.
Incident Response and Recovery
Confirm the IRP includes the 72-hour DOI notification window required under the NAIC Insurance Data Security Model Law and NYDFS Part 500.17. Many IRPs default to GLBA's looser timing or HIPAA's 60-day window and miss the much shorter state-DOI clock.
Walk through a realistic scenario: ransomware on the AMS during renewal season, or a producer phishing compromise exposing a book of NPI. Include legal, compliance, claims leadership, and the carrier appointments contact. Document the after-action.
For any material gap from the tabletop, document owner, due date, and compensating control. Track in the CISO's risk register so it appears in the next biennial risk assessment under Part 500.9.
Confirm current contact info for each state DOI cyber-event reporting portal, the cyber liability carrier's breach hotline, outside breach counsel, and the forensics retainer. Numbers go stale fast — verify, don't assume.
Compliance and Vendor Risk
Update the control mapping for each state where the entity is licensed: NYDFS Part 500, the NAIC Insurance Data Security Model Law as adopted in SC, OH, MS, CT, VA, and others, plus GLBA Safeguards. Identify any state-specific deltas and assign owners.
Part 500.11 vendor scope includes TPAs, claims vendors, document destruction firms, and any printer handling claim packets — not just IT vendors. Confirm a current SOC 2 Type II for each, review CUECs, and document compensating controls for any gaps.
Phishing-resistance training tailored to insurance operations: fake FNOL emails, fraudulent loss-run requests, claimant impersonation, wire-fraud schemes targeting closing payments. Track completion against the producer and adjuster rosters; lapsed training is an audit finding.
CISO sign-off plus any open findings feed into the annual compliance certification under Part 500.17(b). Capture the signature, the summary disposition, and any documented exceptions for the audit binder.
Use this template in Manifestly
- Annual Insurance Review Checklist
- Risk Management Checklist
- Commercial Policy Renewal Checklist
- Customer Inquiry Checklist
- Insurance Compliance Checklist
- Cyber Security Checklist
- Claims Investigation Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Customer Service Request Handling Checklist
- Disaster Recovery Checklist
- Policy Renewal Checklist
- Customer Retention Checklist
- Policy Issuance Checklist
- Sales Proposal Checklist
- Claims Auditing Checklist
- Policy Cancellation Checklist
- Customer Onboarding Checklist
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Insurance Producer Performance Review
- Cybersecurity Incident Response Checklist
- Office Opening Checklist
- Training Needs Assessment Checklist
- Insurance Committee Meeting Planning Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Premium Billing and Collection Checklist
- IT Asset Inventory Management Checklist
- Annual Budgeting Checklist
- Financial Reporting Checklist
- Insurance Agency Lead Generation Checklist
- Compliance Audit Checklist
- Commercial Underwriting Checklist
- Policyholder Feedback Cycle
- Insurance Project Planning Checklist
- Tax Compliance Checklist
- Insurance Agency Office Closing Checklist
- Client Engagement Checklist
- Data Protection Checklist
- Insurance Agency Employee Onboarding
- Enterprise Risk Assessment Checklist
- Training Materials Checklist
- Anti-Fraud Checklist
- Policy Endorsement Checklist
- Quarterly Risk Monitoring Checklist
- Expense Management Checklist
- Insurance IT Security Review Checklist
- Insurance Account Cross-Sell Checklist
- Insurance Project Closure Checklist
- Insurance Marketing Campaign Checklist
- Statutory Financial Reporting Checklist
- Claim Processing Checklist
- Policy Administration Checklist
- Cybersecurity Protocol Checklist
- Cybersecurity Checklist for Real Estate
- Manufacturing Cybersecurity Checklist
- Cyber Security Checklist
- Data Security Checklist
- Disaster Recovery Checklist
- Cybersecurity Incident Response Checklist
- IT Asset Inventory Management Checklist
- Insurance IT Security Review Checklist
- Data Security Review Checklist
- Cybersecurity Risk Assessment Checklist
- Financial Services IT Security Audit Checklist
- Cybersecurity Incident Response Checklist
- Motor Carrier Cybersecurity Protocol Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
