<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Harvard Law School Forum on Corporate Governance</title>
	<atom:link href="https://corpgov.law.harvard.edu/2015/09/26/cybersecurity-enter-insurance-regulators/feed/" rel="self" type="application/rss+xml" />
	<link>https://corpgov.law.harvard.edu</link>
	<description>The leading online blog in the fields of corporate governance and financial regulation.</description>
	<lastBuildDate>Wed, 06 May 2026 11:32:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.8</generator>

<image>
	<url>https://corpgov.law.harvard.edu/wp-content/uploads/2024/02/cropped-photography-4-e1706898544564-1-32x32.png</url>
	<title>Cybersecurity: Enter Insurance Regulators &#8211; The Harvard Law School Forum on Corporate Governance</title>
	<link>https://corpgov.law.harvard.edu</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cybersecurity: Enter Insurance Regulators</title>
		<link>https://corpgov.law.harvard.edu/2015/09/26/cybersecurity-enter-insurance-regulators/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cybersecurity-enter-insurance-regulators</link>
		<comments>https://corpgov.law.harvard.edu/2015/09/26/cybersecurity-enter-insurance-regulators/#comments</comments>
		<pubDate>Sat, 26 Sep 2015 13:50:19 +0000</pubDate>
<!-- 		<dc:creator><![CDATA[]]></dc:creator> -->
				<category><![CDATA[Accounting & Disclosure]]></category>
		<category><![CDATA[Boards of Directors]]></category>
		<category><![CDATA[Practitioner Publications]]></category>
		<category><![CDATA[Compliance and disclosure interpretation]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Insurance]]></category>
		<category><![CDATA[Insurance regulation]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Risk assessment]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Risk oversight]]></category>
		<category><![CDATA[State law]]></category>

		<guid isPermaLink="false">https://corpgov.law.harvard.edu/?p=71672?d=20150926095121EDT</guid>
		<description><![CDATA[Since issuing its Principles of Effective Cybersecurity last July, [1] the National Association of Insurance Commissioners (“NAIC”) has been making progress in the development of cybersecurity examination manuals. NAIC’s regulatory guidance is intended to help state insurance regulators identify cybersecurity risks and communicate a uniform set of control requirements to insurers, insurance producers, and related [&#8230;]]]></description>
				<content:encoded><![CDATA[<hgroup><em>Posted by Dan Ryan, PricewaterhouseCoopers LLP, on Saturday, September 26, 2015 </em><div class='e_n' style='background:#F8F8F8;padding:10px;margin-top:5px;margin-bottom:10px;text-indent:2.5em;'><strong style='margin-left:-2.5em;'>Editor's Note: </strong> <p style="margin:0; display:inline;">Dan Ryan is Leader of the Financial Services Advisory Practice at PricewaterhouseCoopers LLP. This post is based on a PwC publication by Mr. Ryan, Sean Joyce, Chris Joline, Adam Gilbert, Joseph Nocera, and Armen Meyer.</p>
</div></hgroup><p>Since issuing its <em>Principles of Effective Cybersecurity</em> last July, <a href="https://corpgov.law.harvard.edu/2015/09/26/cybersecurity-enter-insurance-regulators/#1">[1]</a><a name="1b"></a> the National Association of Insurance Commissioners (“NAIC”) has been making progress in the development of cybersecurity examination manuals. NAIC’s regulatory guidance is intended to help state insurance regulators identify cybersecurity risks and communicate a uniform set of control requirements to insurers, insurance producers, and related regulated entities (collectively, “Insurance Companies”).</p>
<p>Given the priority regulators are placing on cybersecurity (including NAIC’s Cybersecurity Task Force) and the continued occurrence of high profile data breaches, we expect that cybersecurity examinations will commence as early as 2016 and will be performed by insurance regulators as part of their standard three-year exam cycle. While NAIC’s examination manuals will act as guidelines for state regulators, actual regulation will vary by state. Thus, Insurance Companies should be tracking state regulatory developments to ensure that their cybersecurity programs are rigorous and all-encompassing.</p>
<p> <a href="https://corpgov.law.harvard.edu/2015/09/26/cybersecurity-enter-insurance-regulators/#more-71672" class="more-link"><span aria-label="Continue reading Cybersecurity: Enter Insurance Regulators">(more&hellip;)</span></a></p>
]]></content:encoded>
			<wfw:commentRss>https://corpgov.law.harvard.edu/2015/09/26/cybersecurity-enter-insurance-regulators/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
