PassSprint
State RegulationsNY specificDifficulty 2/5

A New York insurance agency stores clients' personal data on its own information systems. Under the Department of Financial Services' cyber security regulation (Reg 23), the agency is expected to

Select an option to reveal the answer and the full 3-part explanation — free, no signup.

Answer & full 3-part explanation (select an option above, or peek)

Why B is correct

Under Reg 23, the Department of Financial Services' cyber security regulation, covered entities — including licensees under the Insurance Law — must maintain a cyber security program with controls reasonably designed to protect their information systems and the nonpublic client data those systems hold, and they must notify the Department of Financial Services of cybersecurity events. Outsourcing services does not erase the licensee's own obligations.

Why the other options are wrong

  • A) Reg 23 is precisely the regulation governing data security at DFS-licensed entities; informal good practices do not satisfy it.
  • C) A vendor may perform services, but the licensee remains accountable for maintaining its own cyber security program.
  • D) An agency's own systems holding client data are covered; cyber responsibility cannot be shifted wholesale to the insurers it represents.

Memory hook

Reg 23: your data, your cyber program — vendors don't absorb the duty.

Related Practice Questions