South Carolina Insurance Entities – Take Cyber Action Now

Businessman holding an umbrella insurance policy representation.
Businessman holding an umbrella insurance policy representation.

On May 3, 2018, South Carolina Governor McMaster signed into law the South Carolina Department of Insurance Data Security Act. The Act intends to protect personal information managed by insurance agencies, brokers, and carriers in South Carolina from cybersecurity threats. South Carolina is the first state to implement a comprehensive cybersecurity law covering the insurance industry following 2017’s NAIC Insurance Data Security Model Law.

The Insurance Data Security Act goes into effect on January 1, 2019, and requires all insurers, agents, and other licensed entities to develop a comprehensive written information security program within six months of the compliance date, July 1, 2019. The law implements rules for South Carolina insurance agencies, brokers, and carriers on how they manage and secure personal information. This law also applies to ANY insurance-related company writing business in South Carolina, even if they are no not physically located in South Carolina. Georgia and North Carolina businesses should take special notice.

The Act is highly detailed and requires for insurance-related entities to prepare for any cybersecurity threats in the future. Just a few examples of the requirements stated in the Insurance Data Security Act include:

  • Maintain an information security program based on ongoing risk assessment;
  • Perform risk assessment based on threats combined with likelihood and magnitude of harm;
  • Implement an information security program to mitigate risks identified;
  • Develop, implement and maintain a secure information security program;
  • Investigate any cybersecurity activities and notify the Department of Insurance of those activities within 72 hours;
  • Conduct annual testing of effectiveness and safeguards and report findings annually;
  • Develop a written Incident Response Plan; and
  • Provide adequate staff training and awareness on cybersecurity and how to mitigate risks.

Corsica Technologies recommends that all South Carolina insurers, agents, and other licensed entities impacted by the Insurance Data Security Act begin reviewing their existing information security programs to see how it aligns with the new law. If your organization does not have an information security program, now is the perfect time to develop one. Aside from complying with the new law, implementing best practices now will protect an organization from the increasing threat of cybercrime.

Corsica Technologies has analyzed the South Carolina Department of Insurance’s Insurance Data Security Act with our certified, and qualified professionals who are prepared to assist in any way necessary. We provide the components to help you manage and build the required security program or simply audit the program you currently have in place and provide next steps to complete the state requirements in-house.

Corsica Technologies
Corsica Technologies is a strategic technology partner specializing in consulting and managed services. With an integrated team of experts in cybersecurity, IT services, AI solutions, digital transformation, EDI, and data integration, Corsica offers comprehensive coverage and unlimited service consumption for one predictable monthly price—whether fully managed or co-managed.

Related Cybersecurity and IT Reads

Microsoft Copilot vs. ChatGPT - 2026 update
AI
Brian Harmison

Copilot vs. ChatGPT for Business: UPDATED 2026

💡 Compare Copilot vs. ChatGPT  Get Your FREE Chart Originally published November 1, 2023. Completely refreshed March 31, 2026. Short answers: ChatGPT is better for general-purpose tasks and non-Microsoft users. Copilot is the clear winner for Microsoft 365 environments. Both

Read more
AI as a force multiplier for business growth
AI
Garrett Wiesenberg

AI as a Force Multiplier: How Business Leaders Can Scale Without Chaos

💡 Ready to grow with AI? Let’s talk about your transformation. Book a Consultation Technology isn’t the finish line. It’s the force multiplier—and that’s especially true of AI solutions. For modern business leaders, the goal isn’t simply to accumulate more tools. Rather, it’s to create more impact, drive faster decisions, and generate outcomes that actually

Read more
Stryker cyber attack takeaways - Corsica Technologies
Cybersecurity
Ross Filipek

The Stryker Cyberattack: Takeaways for Businesses

💡 Ready to improve your security?  Talk to us about your challenges. Book a Consultation The recent cyberattack on Stryker, a leading manufacturer of medical equipment, offers a sobering window into the vulnerabilities that companies tolerate every day. As I

Read more

Sign Up For Our Newsletter

Stay up-to-date on the Managed Services and Cybersecurity landscape, and be the first to find out about events and special offers.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.