Cybersecurity myth icons over the Salt Lake City skyline for insurance agencies

October 2026 | Insurance Agency Cybersecurity Salt Lake City | Cybersecurity Awareness Month | Security Myths

October is Cybersecurity Awareness Month — a good time for your Salt Lake City insurance agency to take stock of what you actually know versus what you think you know about protecting policyholder data. You assess risk for a living. You would never let a client build their coverage around assumptions that sound right but were never verified — yet plenty of agencies do exactly that with their own cybersecurity.

When bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals look for. Knowledge gaps and comfortable assumptions are what make agencies easy targets — not their location or their line of business.

The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from agency principals regularly, along with the truth behind each one.

Myth 1: "Hackers Don't Target Insurance Agencies"

You would push back immediately if a client said, "nothing bad will happen to us." The same logic applies to your agency. Your systems hold policyholder PII — Social Security numbers, dates of birth, driver's license numbers, bank and premium payment details — plus credentials for every carrier portal your producers log into. That combination is your entire book of business, sitting behind whatever protections you happen to have.

It doesn't matter what lines you write or how your agency is structured. If you have exposed accounts or vulnerable systems, bad actors will take advantage of them. An attacker with access to your Applied Epic or AMS360 database, or a handful of carrier portal logins, has everything needed for identity theft, premium payment fraud and impersonating your agency to your own clients.

Fact: Hackers choose targets based on opportunity, not profile — and an agency full of policyholder data is a rich opportunity.

Myth 2: "Our CSRs Will Recognize a Phishing Email"

The days of obvious phishing emails full of typos from suspicious senders are gone. Today's emails are polished and personalized — a fake carrier renewal notice, a spoofed "portal password reset" from a carrier your agency actually represents, or a DocuSign request that looks exactly like the dozens your CSRs handle every week.

Thanks to AI, it's become harder to catch a scam email from the text alone. Instead, your agents and staff need to think about sender behavior. Ask whether the supposed sender would:

  • Make an unusual request
  • Change premium payment or commission deposit instructions
  • Request policyholder information outside your normal workflow
  • Send a new or unusual carrier portal login link

If anything seems off, double-check before clicking or responding — the same way you'd tell a client to verify before wiring money.

Fact: A convincing email can still be a scam.

Myth 3: "MFA Fully Protects Applied Epic and Our Carrier Portals"

Multi-factor authentication (MFA) is important, but it's not invulnerable. Hackers use MFA fatigue to their advantage, counting on busy CSRs approving requests out of habit or annoyance. "Prompt bombing," for example, floods a phone with requests in hopes someone will approve access just to make them stop — and suddenly an attacker is inside your agency management system or a carrier portal.

MFA is a tool, not a shield. Attackers are finding ways around weaker authentication methods, which is why MFA on Applied Epic, EZLynx, HawkSoft or any carrier portal needs support from the security controls around it.

Fact: MFA should be part of a broader cybersecurity strategy, not the whole strategy.

Myth 4: "Our Backups Have Us Covered"

Ask yourself: if your agency was hit with a ransomware attack tomorrow, could you actually restore your policyholder data? How long would quoting, servicing and renewals be down? Could you look up a client's coverage while they're standing at the scene of a loss?

A backup is great when you know it's going to work. An untested backup isn't something you can rely on during an incident. Knowing how long your agency would realistically be unable to quote, endorse or service policies can save you significant time, money and client relationships.

Fact: Having backups is not the same as being able to recover.

Myth 5: "Cybersecurity Is Only IT's Responsibility"

Your IT provider does a lot to keep your agency safe, but they can't control every click your agents and staff make. Cybersecurity decisions happen at every desk, and it takes only one bad click on a fake renewal notice to open your systems to threats.

There's also a regulatory reason this myth is dangerous: under the NAIC Insurance Data Security Model Law, adopted in Utah and across much of the country, data security is the licensee's obligation — the agency's — not something you can quietly delegate to a help desk. Employee security awareness training matters. When everyone knows what to look for and when to ask for help, they become part of your defenses instead of the gap in them.

Fact: Training your agents and staff to make good decisions strengthens your security posture — and supports your compliance obligations.

Myth 6: "We'd Know What to Do If Something Happens"

It's Tuesday morning during renewal season. Several CSRs suddenly can't access Applied Epic. Many agencies discover in that exact moment that nobody has answered the basic questions:

  • Should staff shut down their computers?
  • Who calls IT?
  • What do you do if email and phones are down while clients are calling about claims?
  • When do you notify carriers, your E&O carrier and the state insurance department?
  • Who communicates with policyholders — and how?

Don't rely on memory in the moment. State insurance data security requirements expect a documented, written incident response plan — the same discipline you'd expect from any well-run risk management program.

Fact: Your recovery plan shouldn't debut during an incident.

Frequently Asked Questions

Do you offer IT support and cybersecurity for insurance agencies in Salt Lake City?

Yes. Qual IT provides IT support for insurance agencies in Salt Lake City, including cybersecurity, threat detection and response, email security, phishing protection, employee security awareness training, MFA implementation and incident response planning built around agency management systems like Applied Epic, AMS360, HawkSoft and EZLynx.

What data security rules apply to insurance agencies?

Most states, including Utah, have adopted versions of the NAIC Insurance Data Security Model Law, which requires licensees to maintain a written information security program, oversee third-party providers, keep a documented incident response plan and report cybersecurity events to the state insurance department on tight timelines. Qual IT helps agencies put the technical safeguards behind those requirements.

How do I know if my agency's cybersecurity is actually working?

Through testing and review: verified restores of your policyholder data, simulated phishing exercises using realistic carrier-themed lures, and a periodic assessment of your tools, policies and response plans by a qualified IT security partner.

Cybersecurity Awareness Starts With the Facts

You'd never let a client hold comfortable myths about their own coverage — "it won't happen to me" is the first thing a good advisor challenges. Cybersecurity Awareness Month is about applying that same discipline to your own agency. Security gaps rarely come from a missing product. They come from believing you've already got it handled when you don't.

If any of these myths sound familiar, it's time to take a closer look at where your agency stands. We work with Salt Lake City insurance agencies to protect policyholder data and keep agency systems running. Schedule a free 10-minute discovery call with Qual IT and we'll help you separate what's protecting you from what's only giving you peace of mind.

Book your discovery call here: https://www.qualit.com/discoverycall/