Written Information Security Programs for Florida Insurance Agencies
Here is a friendly thought experiment for any Florida insurance agency owner: if someone asked to see your written information security program tomorrow, could you hand it over? Not a folder of vendor brochures or a vague memory of "we do that," but a current document that describes how your agency protects customer information, along with a few pieces of proof that it is followed. For many small agencies in Wesley Chapel and across Tampa Bay, the honest answer is "sort of." That is a very normal place to start, and it is fixable. This guide explains what the rule asks for and how to build something practical.
What Rule 69O-128.032 asks for
Florida Administrative Code Rule 69O-128.032 is titled Information Security Program. In plain terms, it says each licensee shall implement a comprehensive written information security program that includes administrative, technical, and physical safeguards for the protection of customer information. It also says those safeguards should be appropriate to the size and complexity of the licensee and the nature and scope of its activities.
Two ideas stand out. The program is written, which means it can be shown and reviewed. And it is scaled to your agency, so a small agency is not expected to look like a large carrier. It is expected to be thoughtful and real.
The three kinds of safeguards
• Administrative: the people and process side, such as policies, training, named responsibilities, vendor oversight, and an incident plan.
• Technical: the settings and tools, such as multi-factor authentication, encryption, updates, backups, and email protections.
• Physical: the real-world side, such as locked offices and file storage, screen positioning, secure disposal of paper and old devices, and protection for equipment.
What a practical program includes
• Scope and responsibility. What information you hold, where it lives, and who is accountable for the program.
• Risk assessment. A short review of what could go wrong and what you already do about it.
• Policies. Acceptable use, access control, remote work and mobile devices, data retention and disposal, and appropriate use of AI tools.
• Technical controls. A plain-language list of the protections in place, such as MFA, encryption, backups, and updates.
• Physical safeguards. How paper, offices, and equipment are protected.
• Vendor oversight. Who else touches your customer information, and what you know about how they protect it.
• Training. When staff learned what, and how new hires get started.
• Incident response. Who does what if something goes wrong, and who is contacted.
• Review. A date, at least annually, when the program is read and updated.
The whole thing does not need to be long. For a small agency, a clear, readable document supported by a simple appendix is often enough.
Common gaps we see
• The program lives in one person's head rather than on paper
• A downloaded policy template that does not match how the agency really works
• No record of when staff were last trained
• No list of vendors who touch customer information
• No date for the next review
Each of these is quick to fix, and fixing them tends to make daily operations smoother as well. A simple habit that helps: keep one shared folder for the program and its evidence, with clear subfolders for policies, training, backups, and vendors, so that pulling everything together takes minutes instead of days.
The "hand it over" test
A useful way to check your readiness is to imagine assembling everything in an hour. Could you produce the written program itself? A list of who has access to key systems? Evidence that multi-factor authentication is on? Training records? Your most recent backup test? Your vendor list? Your incident contact sheet? If a few of those are missing, you now have a to-do list rather than a problem.
Evidence does not need to be fancy. Screenshots of settings, a dated training sign-in sheet, and short meeting notes all count for a lot.
Getting started this month
• Week one: list the systems and places where customer information lives, and name a program owner.
• Week two: write down what you already do. Most agencies are further along than they think.
• Week three: identify the gaps and choose the two or three most valuable to address first.
• Week four: gather the first round of evidence, hold a short team briefing, and put a review date on the calendar.
Then keep it alive with a small update each quarter.
Not scary, just steady
A written program is not about fear of an audit. It is about knowing your own agency well enough to describe how you protect the people who trust you with their information. Agencies that do this often find it improves daily operations too, because the questions it raises (who has access, where is the data, what happens if something goes wrong) are the same ones that make a business more resilient.
This article is general information and not legal advice. Your compliance advisor or counsel can confirm the details that apply to your agency.
Main Event Managed Services works with Florida insurance agencies in Wesley Chapel and across Tampa Bay to build and maintain written information security programs that reflect what they actually do. To start the conversation, visit maineventmsp.com.

