May 16, 2024

NAIC President Mais Named Vice Chair of IAIS Executive Committee

Connecticut Commissioner and NAIC President Andy Mais has been named the new Vice Chair of the International Association of Insurance Supervisors (IAIS) Executive Committee. Mais, who replaces former Massachusetts Commissioner Gary Anderson (the NAIC’s new CEO), will speak at NOLHGA’s 2024 Legal Seminar.

  Staff Contact - Sean McKenna

Cybersecurity Policy Updates

The NAIC IT Examination Working Group has established a drafting group to consider whether existing guidance should be updated to better prioritize cybersecurity and, if so, what resources should be used to update that guidance. The drafting group, which was formed in response to a referral from the Cybersecurity Working Group, has decided that the guidance should be updated using the National Institute of Standards and Technology (NIST) 2.0 framework to enhance the existing guidance. The drafting group continues to work through challenges related to how examiners make certain conclusions on cyber issues and when in the examination process those conclusions should be made (as many cyber risks are prospective). The drafting group may bifurcate analysis of cyber issues on one hand and general IT controls on the other.

In other cybersecurity news, on May 6, 2024, the State Department released the United States International Cyberspace & Digital Policy Strategy, outlining its position on engaging with international partners, building coalitions, and developing new capabilities focused on cyberspace protections. The strategy deals with:

  • Building an open, inclusive, secure, and resilient digital ecosystem
  • Aligning approaches to digital and data governance with international partners
  • Advancing responsible behaviors in cyberspace
  • Strengthening and building international partner digital policy and cyber capacity
The Senate Committee on Commerce, Science and Transportation’s Subcommittee on Consumer Protection, Product Safety and Data Security held a hearing on May 8 on consumer data security, with a focus on protecting the integrity and accessibility of consumer data. Finally, the NIST's published guidance on vertically portioned privacy-preserving federated learning systems is intended to balance the risk of information leakage against the cost of preventing data leaks.   Staff Contact - Sean McKenna

© 2001-2025 All Rights Reserved | Terms Of Use | Site Help