NetVU Playbook Advocacy of Key
Industry Issues
Maintaining Privacy and Effective Data
Security Essentials for Success
In a previous
issue of NetVU Now we looked at Real
Time adoption and Commercial Lines Download as two industry issues NetVU
addresses in its Playbook
of Strategic Industry Positions.
This week we look at NetVU’s position on Identity Management and Data Security and what
progress the industry is making through the activities of groups like IIABA’s
ACT, AUGIE and ACORD.
Identity Management
NetVU
Position: NetVU
believes the key to effective identity management lies in the agency’s ability
to easily manage their carrier IDs and passwords in a central location within a
real-time environment like PL Rating or TransactNOW. Agencies, vendors, and
carriers must first implement proper user authentication and security controls
in its own systems, employee procedures, and physical perimeters. Vendors, carriers,
and agencies themselves must work together to make it easier to do business within
the real-time environment.
To that end
NetVU encourages its member agencies to manage their carrier passwords within
their Real Time environment, and vendors and carriers to make it easier for
agencies to manage them.
Check page 9
of the Playbook for specifics on steps carriers and vendors must take to ensure
no unauthorized access to personal information occurs through the information
infrastructure between agents and carriers.
Industry Activities: In 2009 IIABA’a Agents Council for Technology (ACT) approved
a business case to encourage carriers and vendors to improve password handling
in agents’ Real Time tool. The scope of this challenge is wide and includes
consideration of non-expiring passwords, synchronization, federated IDs,
advance notice of needed password changes and new Real Time transaction to
delete users.
The issue of
improved password handling and identity management is one that goes back a long
ways. Now, it is an issue we can all agree on but back in February 2009 ACT
felt the need to write “The
Business Case for Improved Password Workflows within the Real-Time Environment.”
Since then, agency adoption of best practices has grown but not all agencies
are focusing on round trip transaction processing.
In order for
carriers to implement these solutions or vendors to develop them, there needs
to be greater adoption by agencies. As the recent Status Report on current ACT
recommendations states, “Carriers have need of an instruction guide on proper
implementation of password synchronization. The industry needs to raise
awareness among carrier security officers about recommended solutions that
would make agency password handling both more efficient and more secure.”
Additionally,
several industry participants are collaborating to develop a Trust Framework to
enable the use of federated IDs with multiple business partners. NetVU’s
Chairman of the Board, Gray Nester, has been directly involved in a proof of
concept through his agency, BB&T Insurance Services Inc., together with The
Hartford. Look for more information about this approach to password management
as more testing results are completed.
Data Security
NetVU
Position: NetVU
believes the privacy of customer data gathered during the sales and service
process is of paramount importance. Agents are custodians for tremendous
amounts of non-public data, which are gathered from customers and third parties,
and shared among numerous trading partners.
While there
are many secure methods for transporting this data among the various
constituents, for a variety of reasons, a great deal of data tends to be
distributed through non-secure standard email. Sending non-public data over the
public Internet via non-encrypted email is considered a violation of many state
and federal regulations. To that end, NetVU encourages our member agencies,
carrier partners, and vendor community to embrace secure email.
Specifically:
- Stop
sending private customer data over unsecured email.
- Member
agencies, carrier partners, and vendor community must embrace securing email
via TLS (Transport Layer Security) or other third party solution.
- Where
possible, turn on TLS (Transport Layer Security), the industry standard email
encryption method.
- Encourage
your carrier partners, vendors, and other trading partners to implement TLS
encrypted email.
Email is
entrenched within business workflows; a significant amount of business is
transacted between agents, carriers, and other business partners. The data
shared between the parties is often confidential — although critical to the
business relationship — and contains information of a sensitive nature that, if
lost or stolen, could be harmful to either party.
Industry
Activities: As many
more devices are engaged by our industry to communicate and serve the
customers, the issue of data security becomes greater. The use of mobile
devices and the demand for 24/7 service, has required agents and carriers to be
doubly certain of the security of the private information in which we are
entrusted.
Many industry
groups advocate the adoption by agencies of a written information security plan,
and the proactive implementation of it. ACT has developed a “Prototype Agency
Information Security Plan,” as well as a recorded webinar on “Implementing an
Effective Information Security Program in Your Agency.” You can find all this
information on the “Security
& Privacy” page of the ACT website.
As
a result of industry advocacy efforts, agency E&O carriers now look for a
written security plan, secure email, and other security measures when extending
some data breach related coverages to agencies.
Still,
awareness among agents to the importance of this issue is not high enough,
especially as it pertains to agencies categorized as “business associates” with
regard to HIPPA compliance.
Finally, ACT
advocates agencies implement Transport Layer Security (TLS) as part of an
overall email protocol when transmitting private personal information. The
current environment has shown, however, that agencies often need proprietary
solutions, as well for client communications.
In future
issues of NetVU Now, we will look at
other industry issues, and track progress as they pertain to the NetVU
Playbook. The positions NetVU advocates in the Playbook on your behalf are just
a small part of the group’s overall advocacy campaign. The NetVU Industry
Relations Committee visits to carrier partners, and participation in industry
events and meetings to promote these positions to convey members’ concerns go a
long way to making change happen for greater efficiencies and profitability
within your businesses.
The
effectiveness of our advocacy plan, however, is only as great as your involvement. So, keep abreast of the NetVU Playbook, convey those
positions to your carrier and vendor partners, and be sure to communicate back
your own thoughts and feedback from your discussions. Remember NCOM
is a great place to share your thoughts.
NetVU Account Manager
Certification for AMS360
Are you an Account Manager using AMS360?
Do you want to work smarter, not harder?
If you answered, “Yes,” then the NetVU Account Manager
Certification Program is for you.
Are you the principal of an AMS360 agency?
Do you want to maximize your investment in your people and
technology?
If you answered, “Yes,” then the NetVU Account Manager
Certification is for your account managers.
As part of NetVU’s commitment to offering our members World
Class Education, we are happy to announce our new Certification Program for
AMS360 users. Last year we launched a
highly acclaimed Certification Program for Sagitta users. Based on the success of that certification,
we are expanding our certification program to include AMS360.
Account Managers using AMS360 will not want to miss out on
this training and the prestigious distinction of this certification. This is your opportunity to become an expert
in your field, including the latest technology of version 6.0. You will also be able to use AMS360 to its
full potential and teach others to do the same.
Certified Account Managers will be recognized at NetVU Conference,
be part of a private community available to certified members and will be given
special consideration when contacting Vertafore Support.
Principals, having Certified Account Managers in AMS360 will allow
your agency to maximize your investment in Vertafore with 20% greater
utilization of your agency management system.
The Certification immersion course will be March 5-7, 2012 at the
NetVU National Headquarters in Irving, TX.
Beginning December 1, 2011, NetVU will launch a series of webinars, six of
which must be successfully completed in order to attend the four-day course. Please see the website for more information
on the specific coursework and requirements. View Certification information.
What others are saying…
I felt that this was
one of the best programs that I have participated in and it was extremely
valuable to me and to its applicability in our agency. It was a great week and
I would highly recommend it to anyone. I think it is a great concept and
hope that it continues to develop in the future. Thanks again. It
was top notch!
Ms. Patricia C. Robinson, SSA
American Insurance Administrators Inc.
Mechanicsburg, PA
Property/Casualty Insurance Rates Largely Unchanged: CIAB Analysis
Average commercial property/casualty insurance rates remained largely unchanged during the third quarter of this year, according to a survey conducted by the Council of Insurance Agents & Brokers released. Read full story.
Vertafore Users Get “Real” about Disaster Recovery
In case you missed the recent webinar on Disaster Preparedness featuring Johnmichael Monteith and Roy Riley, you're in luck! Agility Recovery is providing a recorded version of this webinar FREE to Vertafore users.
Additionally, in light of the recent snow storms that hit the Northeast, Agility is offering a FREE Winter Weather Preparedness Checklist to all of our subscribers. Visit the links below to take advantage of these tools.
Agility Recovery is a NetVU Gold Corporate Partner. If you need advice or have any questions about their services please visit www.agilityrecovery.com or call them at 866-364-9696
Click here to watch Roy Riley discuss his experience recovering from the 2009 KY ice storm.
Using
Social Media to Enhance Disaster Communications
by Rick Morgan, Chairman - ACT’s Social Web Work Group
It is not unusual to hear agents who are not yet actively participating
in social networking question its value and/or its return on investment (ROI). Despite
clear evidence to the contrary, they consider social networking a fad and/or a
waste of time. When I speak of clear evidence, I think of the way our industry
used social networking in response to the earthquake, hurricane Irene, tropical
storm Lee, and severe flooding that plagued much of the East coast this past
summer. During these events, agents, carriers, and associations effectively
used social networking to connect with their followers and communicate valuable
information.
Agencies used everything from e-newsletters and blogs to Twitter and
YouTube to post information on how to contact carriers, storm updates,
emergency shelters locations, road closings, office hours, FEMA info, tips on
cleaning, preparing a disaster supply kit, storm surge maps, “thank you’s” to
emergency responders, photos of local flooding, and insurance policy coverage
information. In short, they provided valuable information and kept their
customers informed prior to, during and after the disasters.
Read
complete article
NetVU's Own Brett Burchett is Finalist in Social Media Contest
By: Stephen Moriyama, 2nd Vice Chairman of the Board
NetVU in its day to day operation uses a comprehensive database association system called iMIS. This brings together your registrations, NCOM, and all of the vital communication pieces that bring our NetVU members together. Just like our own Vertafore Systems, iMIS has their own conferences to update and advocate the necessary changes to keep progress moving. Brett recently was engaged in discussions and support for the growing use of social media. Join me in helping NetVU trump the other associations by voting for him as 1 of 6 finalists in a promotion on Social Media.
Click here and "Like" Brett's video to cast your vote. Voting ends Friday, Nov. 4!