Skip to main content
milly logo
Tactical · prose B09 For Buyers · Legal & Regulatory Due Diligence

Data privacy and GLBA — the cyber-compliance stack.

An agency holds exactly the data regulators most want protected, and the rules stack four layers deep. A buyer inherits whatever the seller skipped — and the worst inheritance is the breach the seller experienced but never reported. The audit reads the stack, budgets the remediation, and treats cyber insurance as a day-one gate.

An insurance agency is a data-privacy target by definition — it holds Social Security numbers, financial details, and medical information for thousands of clients. Four layers of regulation govern that data, and a buyer acquiring the agency inherits its full compliance posture, gaps and all. The diligence isn't about achieving perfect compliance; it's about knowing exactly what's missing, what it costs to fix, and whether any latent exposure (an unreported incident, an uninsurable posture) makes the deal more expensive than the price suggests.

§ 01 · The four regulatory layersWhat stacks on every agency.

LayerWhat it governs
GLBA + Safeguards RuleThe federal baseline — privacy disclosure and an information-security program
NAIC model lawA state-adopted data-security standard — about half the states
State cybersecurity regimesState-specific rules, New York's being the strictest
State consumer-privacy lawsCalifornia and a growing list of state privacy statutes

Four layers stack on every agency, and a buyer reads all four. GLBA and its Safeguards Rule is the federal baseline — and for agencies, enforcement runs through the state insurance departments via the examination process, not the FTC, which surprises buyers who expect a federal enforcer. GLBA itself rests on three pillars: a Privacy Rule (disclosing info-sharing practices to consumers), the Safeguards Rule (a written information-security program), and pretexting provisions (restrictions on obtaining customer info under false pretenses). The NAIC data-security model law adds a state layer adopted by about half the states, with customization, phase-ins, and exemptions varying state by state. State cybersecurity regimes add another, New York's being the strictest. And state consumer-privacy laws — California's and a growing list of others — add the fourth. The stack's depth depends on the agency's footprint, so a multi-state or New York presence means more layers and more remediation.

§ 02 · The seven Safeguards deliverablesThe federal floor.

Journal axiom · 1 of 2

The Safeguards Rule requires seven concrete deliverables, and their absence is the most common finding: a written information-security program, a designated qualified individual, a documented risk assessment, employee training, vendor risk management, incident-response procedures, and regular testing and monitoring. The four common gaps — no program at all, a template-only "compliance theater" program, no training, and no vendor due-diligence files — are exactly what a buyer budgets to fix in the first 90 days.

The seven deliverables are the federal floor, and a buyer reads the agency's posture against them. The four common Safeguards findings recur: no written program at all; a program that exists but is template-only "compliance theater"; no employee training program (cured with any of the standard training platforms); and no vendor due-diligence files. None of these end a deal — they set the remediation budget, which for a small agency runs $15K–$40K in the first 90 days and a timeline of 60–120 days for a program rewrite, a training launch, retroactive vendor diligence, and a multi-factor-authentication deployment. A larger or multi-state agency with a New York footprint costs more, because the strictest state regime layers a formal board-approved program, a designated security officer, annual certification, and explicit MFA, encryption, penetration-testing, and vulnerability-assessment mandates on top of the federal floor — with a 72-hour event-notification window. The NAIC layer adds its own 72-hour notification for material events in most adopting states, with small-agency exemptions (often fewer than ten employees) that vary by state and must be documented to rely on.

§ 03 · Cyber insurance is a Day 1 gateNot a post-close project.

The most important reframe in this diligence is that cyber insurance isn't a post-close cleanup item — it's a day-one gating condition. A weak seller posture (no MFA, no written security program, no endpoint detection, no training) leads a cyber carrier to either price the premium sharply higher or decline to insure the agency at all until the gaps are remediated. So a buyer treats cyber-insurance availability as a condition to confirm before close, not a project to start after, because discovering at close that the acquired agency can't get coverage is a problem with no good post-close answer. The cyber policy also carries the same claims-made tail issue as professional-liability coverage: claims reported after the policy expires for incidents that occurred before expiration require an extended reporting period, which has to be budgeted at the LOI stage. That parallel to professional-liability tail coverage is detailed in E&O tail coverage.

§ 04 · The unreported-breach trapThe latent exposure on the balance sheet.

The highest-risk finding in the whole privacy audit is the one with no current paper trail: an incident the agency experienced but never reported. A credential-phishing event, a stolen unencrypted laptop, a paid-but-unreported ransomware demand — each sits on the balance sheet as a latent regulatory exposure that the buyer inherits at close, and none of them shows up in a routine document review because the whole problem is that they were never documented. The defense is a five-year breach-history schedule from the seller, listing every incident's date of occurrence and detection, the data and individuals affected, the regulatory and customer notifications made, the costs, and the current status — with the knowledge qualifier negotiated tightly, because a "to the best of seller's knowledge" carve-out is exactly where an unreported incident hides. Reading the four-layer stack, budgeting the seven-deliverable remediation, gating on cyber insurance, and hunting the unreported breach is how a buyer keeps a privacy gap from becoming a post-close regulatory liability. The IP-and-data inventory that pairs with this read is in IP and trade names.

Terminology on this shelf

Four regulatory layers
GLBA/Safeguards, the NAIC model law, state cybersecurity regimes, and state consumer-privacy laws.
Safeguards Rule
The federal requirement for seven deliverables — a written security program among them — enforced via state insurance departments.
Seven deliverables
Security program, qualified individual, risk assessment, training, vendor management, incident response, testing.
Remediation budget
$15K–$40K over 60–120 days for a small agency; more with a multi-state or New York footprint.
Cyber-insurance gate
A Day 1 gating condition — a weak posture can make the agency uninsurable until remediated.
Unreported-breach trap
An incident the agency experienced but never reported — a latent exposure the buyer inherits.

From the buyer theme

One piece every other Tuesday.

The next long-form piece in your inbox the morning it goes live. No marketing. Unsubscribe in one click.

Anonymous by default · One click to unsubscribe