South Carolina Insurance Entities – Take Cyber Action Now

Businessman holding an umbrella insurance policy representation.
Businessman holding an umbrella insurance policy representation.

On May 3, 2018, South Carolina Governor McMaster signed into law the South Carolina Department of Insurance Data Security Act. The Act intends to protect personal information managed by insurance agencies, brokers, and carriers in South Carolina from cybersecurity threats. South Carolina is the first state to implement a comprehensive cybersecurity law covering the insurance industry following 2017’s NAIC Insurance Data Security Model Law.

The Insurance Data Security Act goes into effect on January 1, 2019, and requires all insurers, agents, and other licensed entities to develop a comprehensive written information security program within six months of the compliance date, July 1, 2019. The law implements rules for South Carolina insurance agencies, brokers, and carriers on how they manage and secure personal information. This law also applies to ANY insurance-related company writing business in South Carolina, even if they are no not physically located in South Carolina. Georgia and North Carolina businesses should take special notice.

The Act is highly detailed and requires for insurance-related entities to prepare for any cybersecurity threats in the future. Just a few examples of the requirements stated in the Insurance Data Security Act include:

  • Maintain an information security program based on ongoing risk assessment;
  • Perform risk assessment based on threats combined with likelihood and magnitude of harm;
  • Implement an information security program to mitigate risks identified;
  • Develop, implement and maintain a secure information security program;
  • Investigate any cybersecurity activities and notify the Department of Insurance of those activities within 72 hours;
  • Conduct annual testing of effectiveness and safeguards and report findings annually;
  • Develop a written Incident Response Plan; and
  • Provide adequate staff training and awareness on cybersecurity and how to mitigate risks.

Corsica Technologies recommends that all South Carolina insurers, agents, and other licensed entities impacted by the Insurance Data Security Act begin reviewing their existing information security programs to see how it aligns with the new law. If your organization does not have an information security program, now is the perfect time to develop one. Aside from complying with the new law, implementing best practices now will protect an organization from the increasing threat of cybercrime.

Corsica Technologies has analyzed the South Carolina Department of Insurance’s Insurance Data Security Act with our certified, and qualified professionals who are prepared to assist in any way necessary. We provide the components to help you manage and build the required security program or simply audit the program you currently have in place and provide next steps to complete the state requirements in-house.

Corsica Technologies
Corsica Technologies is a strategic technology partner specializing in consulting and managed services. With an integrated team of experts in cybersecurity, IT services, AI solutions, digital transformation, EDI, and data integration, Corsica offers comprehensive coverage and unlimited service consumption for one predictable monthly price—whether fully managed or co-managed.

Related Cybersecurity and IT Reads

How did CMMC change on Sept 10 2025?
Consulting
Garrett Wiesenberg

Business and IT Alignment: What It Is and How to Achieve It

Originally published July 23, 2025. Significantly overhauled July 29, 2026. In today’s technology-first economy, organizations that achieve true business and IT alignment hold a competitive edge. This synergy ensures that every digital initiative directly supports core business objectives—whether that’s driving

Read more
Microsoft 365 Copilot ROI
AI
Wes Dekoninck

Calculating ROI for Microsoft 365 Copilot

Microsoft 365 Copilot is a powerful productivity tool. With the right Copilot consulting and training, the solution can revolutionize your business. But you can’t just turn on Copilot licenses and expect to see ROI. How do you set up your

Read more
AI Governance Made Simple
AI
Brian Harmison

AI Governance Made Simple 

Originally published April 22, 2025. Significantly refreshed July 24, 2026. What guardrails should you put in place with your AI strategy? How do you empower your team to leverage AI while also mitigating any risks?   AI governance consulting is the

Read more

Sign Up For Our Newsletter

Stay up-to-date on the Managed Services and Cybersecurity landscape, and be the first to find out about events and special offers.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.