Insurance

The 72-hour clock starts at determination.

Schedule a meeting

Carriers and agencies under NYDFS Part 500, NAIC Model 668 and DORA

Security built for insurers and their data

Answer the regulator from a signed audit trail the examiner can check.

Regulators

RuleWhat it asksARRTECH record
NAIC Model 668 §4D(2)(h)Test and monitor systems to detect attacks.Correlation rules and a silent-source alert. →
NAIC Model 668 §4D(2)(i)Audit trails that reconstruct material transactions.Database collection, signed and chained. →
NYDFS 500.14(a)Monitor the activity of authorized users.A risk score per user on a timeline. →
NYDFS 500.14(b)Centralized logging and security event alerting.One SIEM for every source, with alerts. →
NYDFS 500.17Notice within 72 hours.A case timeline from the first alert. →
NAIC AI Model BulletinDocumentation of model validation and drift.Detector promotion and rollback, recorded. →
DORADetection for insurers and intermediaries.Log source alerts and behavioral detection. →

NYDFS enforcement

Trace data taken through agent portals

In October 2025, NYDFS fined eight auto insurers more than $19 million after driver’s license numbers were taken through online quote tools and agent portals. ARRTECH SIEM links portal and database events, so a bulk download shows up as one case.

NYDFS 500.6

Keep five years of audit trail

NYDFS Part 500.6 requires audit trails that can reconstruct material financial transactions, kept for at least five years. ARRTECH signs every log, so the examiner can check the record has not changed.

NAIC Model 668

Report within 72 hours with evidence

The NAIC Insurance Data Security Model Law, adopted in many states, requires notice to the commissioner within 72 hours of a cybersecurity event. Each ARRTECH SIEM case keeps the full timeline from the first alert.

NAIC AI Model Bulletin

Document model testing for regulators

The NAIC AI Model Bulletin asks insurers to govern the AI systems they use, including systems from vendors. Cyberdroid AI Detection records how each detector was tested and promoted, which gives you a record for that governance. It does not validate your underwriting models.

By rule

DORA

Detection for insurers and intermediaries. ARRTECH: Log source alerts and behavioral detection.

Questions

Did the data leave through a portal?

ARRTECH SIEM connects web, application and database events, so a quote lookup followed by a bulk download shows up as one case. It records what your application logs; it does not protect the application itself.

Can claims data leave by email?

ARRTECH DLP checks email before it is sent, uploads from any application and prompts to AI tools. It recognizes excerpts of protected documents and database records.

Is our detection testing documented?

Yes. Cyberdroid AI Detection tests each detector on your own data before it can raise an alert, and records every change. That gives the examiner a record; it does not validate your underwriting models.

Who approves an action?

A person. ARRTECH SOAR emails the approver up to five options and waits. The history shows who chose what and when.

What stays with you?

Filing the notice, your web application firewall, and the systems your administrators and vendors run. Cyberdroid AI Detection reports about once an hour and never blocks.

Sources

Guide

What is NAIC Model 668?

The NAIC Insurance Data Security Model Law requires insurers to monitor systems, keep audit trails and notify regulators within 72 hours.

What does NYDFS Part 500 require of insurers?

Audit trails kept five years, monitoring of authorized users, and notice within 72 hours of a cybersecurity event.

How do insurers protect agent portals?

Correlate portal, application and database logs so bulk data theft shows up as one alert.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.