Oklahoma changed the rules for agencies in 2024.
The Oklahoma Insurance Data Security Act applies to producers and licensees, not just carriers. If you have a cybersecurity event, you have three business days to notify the Commissioner. Most agencies we speak to have never heard of it.
Three business days is not long enough to start figuring it out.
Oklahoma enacted the Insurance Data Security Act in 2024 (36 O.S. §§ 670–679). It reaches insurers, producers and other licensees under the Insurance Commissioner's jurisdiction — which includes independent agencies. Non-exempt licensees have to build and maintain an information security program, investigate cybersecurity events, and notify the Commissioner without unreasonable delay and no later than three business days after determining an event occurred.
Three business days is a forensic timeline, not an IT timeline. To make that window you need to already know what happened, what was touched, and whether personal information was involved. That determination is not something you can begin on day one of an incident.
If you are under $5 million in revenue, read this part carefully
Licensees with less than $5 million in gross annual revenue are exempt from the program requirements, as are entities already complying with HIPAA or Gramm-Leach-Bliley. A lot of Oklahoma agencies fall under that line, and we are not going to pretend otherwise to sell you something.
But the exemption is from the paperwork, not from the breach. Your agency holds Social Security numbers, dates of birth, driver's license numbers and often medical information collected for underwriting. That file is worth the same to an attacker whether or not you had to file an attestation, and your carriers and your E&O policy will still ask what controls you had in place.
Built around the data agencies actually hold.
Written information security program
The document the Act asks for, built from your actual environment rather than a template with your name in the header.
Incident response you can run in 3 days
A tested plan, logging that survives the event, and a team who has done the forensic work before.
Email and wire-transfer defense
Agencies move money and get impersonated. Email security, spoofing controls and staff training aimed at the fraud you actually see.
Managed EDR and 24/7 monitoring
Detection on every endpoint, watched around the clock, so an intrusion is caught before it becomes a notification event.
Backup with tested restores
Verified restores on a schedule. A backup nobody has tested is a plan you have not made.
Agency management system support
Your AMS, carrier portals, and the integrations between them — kept patched, monitored and available.
The agency counted 21 sends. The message trace said 763.
This is from an incident response engagement we ran at an insurance agency. Details are withheld, the numbers are not.
It started with a lure from a genuinely compromised trusted sender — a real contact at a partner agency whose own account had been taken over. The email security allowlist did not stop it, precisely because the sender was legitimate and already trusted. The staff member tried to verify by replying to ask if the message was real. The attacker, sitting in that mailbox, replied and confirmed it was. She then entered her credentials.
Working from the mailbox, the agency counted 21 malicious messages sent from the account. The reconciled message trace found 763 distinct recipients, 762 of them external — carriers, brokerages and named agents — all inside a single 24-minute window. The count was low by a factor of thirty-six.
Two things suppressed it. The attacker ran 165 deletion operations, 45 of them hard deletes, and created a concealment inbox rule named "..." that routed replies and bounces straight to Deleted Items marked as read. And the dashboard count had been filtered on a single subject line, which varied between sends. Separately, the audit log showed 836 distinct messages read by the attacker — across Inbox, Sent Items, Drafts, and Recoverable Items.
The consequence is the whole point. A notification scoped to 21 would have left roughly 740 external recipients — other insurance professionals — never told they had received a credential-harvesting lure from a trusted partner. The mailbox was not the authoritative source. The message trace was, and it has a ten-day retention window.
Your own mailbox will lie to you
Attackers delete and conceal. The count you can see is the count they left you. Authoritative sources sit outside the mailbox.
The evidence is on a clock
Message trace retains ten days; Entra sign-in logs thirty. Miss the window and a later collection returns clean — which reads as 'no malicious activity'.
Allowlists fail on trusted senders
This campaign moves agency to agency through real relationships. Being on someone's trusted list is exactly what makes it work.
Find out where you actually stand.
We will assess your agency against the Act's requirements and tell you plainly whether you are exempt, what your real exposure is, and what is worth fixing first. If you are already in good shape, that is what we will tell you.