
Key takeaways
- An insurance agency's duties to protect client data come from several directions at once: state privacy and breach-notification rules, insurance regulators, carrier contracts and the conditions of its own cyber policy.
- Cyber-insurance questionnaires are the most practical checklist an agency has; the answers they want are multi-factor authentication, endpoint protection, tested backups, email security and a way to remove access when people leave.
- Phishing and payment-redirection scams are how small agencies actually get hit, so email security and staff awareness come before anything exotic.
- I put the technical safeguards in place and document them; your attorney or compliance consultant handles legal interpretation and filings. Together that helps you meet the requirements without pretending IT alone is compliance.
- Most of this is a one-time setup and a modest monthly cost, and it is far cheaper than the week an agency loses to a ransomware event.
Who handles cybersecurity and compliance IT for Dallas insurance agencies?
I do, for the technical side. I am Anthony Omini, the owner of Cross River Tech, a small managed IT company in Dallas. I plan and put in place the safeguards an independent insurance agency needs, and my team keeps them monitored behind me: multi-factor authentication, email security, endpoint protection, encrypted and tested backups, secure remote access, and the documentation that shows all of it is in place. That is the part of compliance that lives in your computers, your Microsoft 365 account and your network, and it is the part most agencies are missing when they get the questionnaire from their carrier or their cyber underwriter.
What I am not is a lawyer or a compliance consultant. Which rules apply to your agency, what a notification must say and who must receive it, and how to answer a regulator are questions for your attorney or a compliance professional. My job is to make sure that when they ask "is this in place," the answer is yes and I can prove it. That combination helps you meet the requirements; no IT setup on its own makes an agency compliant, and anyone who tells you otherwise is selling something.
This article covers what an agency actually has to protect, what cyber-insurance questionnaires ask for and why, and the specific safeguards I put in place, in the order I put them in. It applies to agencies in Dallas, where I work onsite, and to agencies anywhere in Texas that I support remotely. The general picture of how I work with agencies is on the insurance agency IT support page.
What does a Texas insurance agency actually have to protect?
More than most agency owners realize, and the list is the reason the rules exist. A typical independent agency holds, for every client and often for every household member and employee of a commercial client:
- Social Security numbers and dates of birth on applications.
- Driver's license numbers on every auto policy.
- Bank account and card details for premium payments.
- Medical information on life, health and disability applications.
- Business financials, payroll figures and loss runs for commercial accounts.
- Home addresses, vehicle details and alarm information, which together describe exactly when a house is empty.
The duty to protect that data does not come from one rule. It comes from several directions at the same time, and an agency has to satisfy all of them:
- State law. Texas, like other states, requires businesses that hold personal information to take reasonable steps to protect it and to notify affected people and the state when it is exposed. The details and deadlines are for your attorney; the point for IT is that you need to be able to tell what was taken, which is only possible with logging and monitoring in place.
- Insurance regulators. Regulators at the state level expect agencies to have a written information security program appropriate to their size, and to be able to describe it.
- Carrier contracts. Your appointment agreements usually require you to protect the carrier's policyholder data and to tell the carrier about incidents.
- Your own cyber policy. The application you signed made statements about your controls. If they were not true, the claim can be contested.
Every one of those points at the same short list of technical safeguards, which is good news: doing the work once satisfies all of them.
What do cyber-insurance questionnaires ask, and what do the answers mean?
If you want a practical checklist for an agency's security, use the questionnaire your own cyber carrier sends at renewal. Underwriters have watched thousands of claims, and the questions reflect what actually prevents losses. Here are the ones that appear on nearly every form, in plain language, with what I put in place to answer yes:
| Questionnaire item | What it means | What I set up |
|---|---|---|
| MFA on email | A second step beyond the password to open a mailbox | Multi-factor authentication required for every Microsoft 365 or Google Workspace user, no exceptions |
| MFA on remote access | Nobody reaches the office network or a server from outside with a password alone | Secure remote access with MFA; old open remote-desktop ports closed |
| MFA on privileged accounts | Admin accounts are protected and separate from daily accounts | Separate admin logins, MFA enforced, daily accounts with no admin rights |
| Endpoint detection and response | Security software that watches behavior, not just known viruses | Managed EDR on every workstation and server, monitored |
| Offline or immutable backups | A copy ransomware cannot encrypt or delete | Offsite backups with versions that cannot be altered, restore tested on a schedule |
| Email filtering and anti-phishing | Bad mail is stopped before an agent sees it | Advanced filtering, link scanning, external-sender tagging, sender authentication |
| Security awareness training | Staff know what a phishing email and a fake payment request look like | Short recurring training and simulated phishing, with results kept |
| Patch management | Updates applied promptly | Automated updates for Windows, browsers and common software, reported monthly |
| Access removal on departure | Former employees cannot log in | Offboarding checklist covering email, agency system, carrier portals and phones |
| Incident response plan | A written page saying who does what when something happens | Plan drafted with you, kept where you can find it without a working computer |
Answer these honestly. A "yes" that turns out to be untrue on the day of a claim is worse than a "no" that raised your premium, and I would rather help you make each one true than tell you what to write.
Multi-factor authentication everywhere that matters
If an agency does one thing after reading this, it should be this one. Stolen passwords are the way into nearly every small-business compromise, and multi-factor authentication makes a stolen password nearly useless on its own. Every underwriter asks about it first for that reason.
Where I switch it on, in order:
- Email. Microsoft 365 or Google Workspace, every user, using an authenticator app rather than text messages where possible.
- The agency management system. Applied Epic, AMS360, HawkSoft, EZLynx and the rest all support it, and where they tie into Microsoft sign-in, one setup covers both.
- Carrier portals. Most now require it. I make sure the second factor goes to a device the right person controls, not to a phone number that belonged to someone who left.
- Remote access. Anything that reaches the office from outside.
- Admin accounts. Mine included.
- The password manager, banking and payroll. Anything with money or master passwords behind it.
The pushback I hear is that producers find it annoying. It costs a few seconds a day, and I set it up so trusted office computers are not prompted constantly. Compared with explaining to a client why their Social Security number is for sale, it is a small price. The Microsoft side of this is covered in more depth in Microsoft 365 security for a small business.
Email security: the attack that actually hits agencies
Agencies are not usually attacked with clever technical exploits. They are attacked with email. Two patterns account for most of what I see:
- Phishing for a mailbox. An agent gets a convincing message, enters a password on a fake page, and the attacker now reads the mailbox quietly, learns how the agency talks to clients and carriers, and waits.
- Payment redirection. With that access, or simply by spoofing the agency's address, the attacker sends a client or a carrier new payment instructions, or sends the bookkeeper an urgent request from "the owner." Money moves, and it does not come back.
The defenses are layered, and I put all of them in:
- Sender authentication for your own domain. Three settings, known as SPF, DKIM and DMARC, that tell the world's mail servers which systems are allowed to send mail as your agency. Set correctly, they make it much harder for someone to send a message that looks like it came from you.
- Advanced filtering. Attachment sandboxing, link rewriting so a malicious page is blocked when clicked, and impersonation detection that flags a message claiming to be the owner from an outside address.
- External-sender tags. A visible label on any mail from outside the agency, so "the owner" writing from a Gmail address stands out.
- Rules that catch the aftermath. Alerts when a mailbox suddenly forwards everything outside the agency, which is what attackers set up first.
- A payment-change procedure. Not a technical control at all: any change to payment details from a client, a carrier or a vendor gets confirmed by phone on a known number. I help you write it down and get everyone to follow it.
- Training. Short, regular, with simulated phishing so people practice on messages that do not cost anything.
Email is also where most of your evidence lives, which is why it needs to be backed up and retained. That is the next section.
Backups that survive ransomware
Ransomware works by encrypting everything it can reach, including any backup that is connected to the network at the time. A backup drive plugged into the server is not a backup; it is another victim. What an agency needs is a copy the attacker cannot touch, and proof that it can actually be restored.
What I set up:
- Microsoft 365 or Google Workspace backup. Mailboxes, calendars, OneDrive or Drive files and Teams or Chat, backed up to a separate service, because the platform's own retention is not designed as a recovery tool.
- Server and shared-folder backup for any onsite system, with versions kept for months so a file encrypted quietly three weeks ago can still be recovered.
- Offsite, immutable copies. Stored away from the office, in a form that cannot be altered or deleted for a set period even by an administrator account.
- Scheduled restore tests. I restore a mailbox or a folder on a schedule and record the result. A backup that has never been restored is a hope, not a plan.
- A recovery order. A written list of what comes back first: email and the agency system connection, then shared files, then everything else.
If your agency system is hosted by the vendor, remember that the vendor protects the platform, not your email, your downloaded policy documents or your spreadsheets. The details are in better backups for insurance agencies, and the broader service is on the cybersecurity, backup and disaster recovery page.
Workstations, home laptops and people who leave
The rest of the technical safeguards are less dramatic but show up on every questionnaire and every incident:
- Full-disk encryption on every workstation and laptop, so a laptop left in a car in a Dallas parking lot is a hardware loss and not a notification event.
- Managed endpoint protection on every machine, monitored, with alerts that reach my team and me rather than a console nobody opens.
- Automated patching for Windows, browsers, Office and the components your agency system needs, scheduled outside business hours.
- Standard accounts for daily work. Nobody browses carrier portals with administrator rights. A compromised standard account does far less damage.
- Screen locks and clean desks. Automatic locking after a few minutes, and no client files left open in a shared front office.
- Home and mobile work done properly. Agency-owned, encrypted laptops with the same protection as the office, secure remote access with MFA, and a rule against agency email on unmanaged personal devices without at least a passcode and the ability to wipe the mailbox remotely.
- Offboarding the same day. When someone leaves, every account is disabled, shared passwords are rotated, carrier portal access is removed, and the laptop comes back and is wiped. I run it as a checklist so nothing is missed. The onboarding and offboarding process for agency systems is described in IT support for Applied Epic, AMS360 and agency management systems.
None of this is expensive. Most of it is configuration on hardware and licenses you already own, done once and kept in place.
Policies, training and documentation: what I provide and what I do not
Regulators and underwriters want to see a written program, not just working software. I help with the parts of that I am qualified to help with, and I am clear about the parts I am not.
What I provide:
- An inventory of every device, account and system that holds client data, kept current.
- A plain-language description of the safeguards in place, updated when they change, which is most of what a written information security program describes.
- Evidence: MFA enforcement reports, patch reports, backup and restore logs, training completion records. This is what you attach to the questionnaire.
- An incident response plan drafted with you: who calls whom, what gets disconnected, where the backups are, how staff communicate if email is compromised.
- Staff training and simulated phishing, with results.
- Help answering the technical questions on questionnaires and carrier security forms accurately.
What I do not provide:
- Legal advice on which laws and regulations apply to your agency, or on notification obligations after an incident.
- Regulatory filings or representations to a regulator on your behalf.
- A statement that your agency is "compliant." I can say the safeguards are in place and show the evidence; the judgement about compliance belongs to you and your advisers.
The useful arrangement is that your attorney or compliance consultant tells you what must be true, and I make it true and document it. That helps you meet the requirements honestly. If your agency has never had a written program, the fastest route is to start from the questionnaire, make every item true, and write down how. That document is most of the program.
Where to start and what it costs
If your agency has none of this in place, the order that reduces risk fastest is: multi-factor authentication on email and the agency system this week, email filtering and sender authentication next, then backups with a tested restore, then endpoint protection and encryption on every machine, then the written plan and the training. Each step closes the door that the previous step left open.
Most of it is a one-time project followed by a modest monthly cost for the licenses and the monitoring. For agencies on a month-to-month managed IT plan, the ongoing part is included in the per-user fee, which I quote after a short conversation about how many people and devices you have. If you only want the security work done as a project, with no contract, that is available hourly as well. Either way the first step is the same: send me your last cyber-insurance questionnaire, or tell me you have never seen one, and I will tell you where the gaps are.
Reach me through the contact page or call (214) 612-7080. I support agencies onsite across Dallas–Fort Worth and remotely anywhere in Texas.
Questions people ask
Is an insurance agency in Texas required to have cybersecurity measures?
In practical terms, yes. State privacy and breach-notification rules apply to any business holding personal information, insurance regulators expect a written security program, carrier appointment agreements require protection of policyholder data, and your own cyber policy was issued on the strength of the controls you described. Which specific rules apply to your agency is a question for your attorney; the safeguards they all expect are the ones I put in place.
Can you help fill out a cyber-insurance questionnaire?
Yes, and more usefully, I can make the answers true first. I go through each technical item, such as MFA, endpoint protection, backups, email filtering and patching, confirm what is actually in place, close the gaps, and give you the evidence to attach. I will not tell you to answer yes to something that is not true, because a false answer can cost you the claim.
What is the single most important thing to do first?
Turn on multi-factor authentication for every email account and for the agency management system. Stolen passwords are how most small agencies get compromised, and a second factor makes a stolen password nearly worthless on its own. It takes an afternoon to set up for a typical agency and is the first question every underwriter asks.
Do producers working from home create a compliance problem?
Only if it is done casually. A producer on an agency-owned, encrypted laptop with endpoint protection, secure remote access and MFA is as well protected as someone in the office. A producer reading client email on a personal phone with no passcode, or working from a family computer, is a real gap. I set up home and mobile work so it meets the same standard as the office.
What happens if the agency is breached anyway?
You follow the incident response plan: disconnect what is affected, call me, and call your attorney and your cyber carrier, because both need to be involved early. I contain the problem, preserve the evidence that shows what was accessed, and restore from the backups that were kept out of reach. The logging and monitoring I set up beforehand are what make it possible to say what was taken and to whom the notification duties apply.
Sources and further reading
Market price ranges in this article are my own observation of quotes in the Dallas market, not a published survey. Where I state a rule or a standard, the source is linked above.



