Insurance agencies

Managed IT and cybersecurity for Maryland insurance agencies.

EDG.tech runs IT and security for independent insurance agencies across Gaithersburg, Rockville, Bethesda, Germantown, Washington, DC, and Frederick: multi-factor authentication on every carrier portal and the agency management system, application data encrypted and retention-limited, premium-payment fraud protection, and the documentation carriers require of appointed agencies. Complete is $100 per user per month; Essentials is $45 per device per month.

Who this is for

For independent property-and-casualty, life and health, and benefits agencies and brokerages of roughly 3 to 60 people, including agencies in a network or cluster that still run their own office. Captive agencies on a carrier-provided system are a fit for what the carrier leaves to the agency, which is usually the local office, devices, and email.

What is at stake for an insurance agency?

Carriers must report cyber events to the state in three business days, and they pass that pressure down

Under Maryland's Insurance Data Security Act, effective October 1, 2022, carriers must maintain a written information security program and notify the Maryland Insurance Administration of a cybersecurity event within three business days. Carriers are increasingly meeting those duties by requiring the agencies they appoint to attest to security controls, and an agency that cannot attest is an agency a carrier can decline.

Source: Maryland Insurance Administration Bulletin 22-13 (Sep 30, 2022): reporting cybersecurity events

Premium payments are a wire-fraud target with your name on them

The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints and $3.05 billion in losses in 2025. In an agency the pattern is a client paying a premium or a down payment to an account named in an email that looks like it came from your office, or an account manager's mailbox taken over and used to redirect a carrier payment.

Source: FBI IC3 2025 Internet Crime Report (PDF)

An application is a breach waiting to be reported

A single personal lines or benefits application can carry a Social Security number, a driver's license number, a date of birth, and health information. Maryland's Personal Information Protection Act requires reasonable security for that data and notice to affected individuals within 45 days of discovering a breach, and the applications accumulate in email and shared drives for years unless something removes them.

Source: Maryland Attorney General: PIPA guidelines for businesses

What do carriers and Maryland law ask of an insurance agency?

Three sets of rules reach an agency. Maryland's Insurance Data Security Act binds carriers directly, and carriers are increasingly pushing its requirements down to appointed agencies through contracts, attestations, and portal security rules. The Gramm-Leach-Bliley Act's privacy and safeguarding duties apply to insurance producers through Maryland's insurance privacy regulations, with the Maryland Insurance Administration as regulator. Maryland's Personal Information Protection Act covers the personal information in applications and client files, with a 45-day breach notice. Benefits agencies that handle health plan information may also be business associates under HIPAA. Your errors-and-omissions and cyber-insurance carriers ask for multi-factor authentication, encryption, backups, and training before renewal. EDG.tech builds the controls into the plan, writes the security policy carriers ask you to attest to, and keeps the evidence ready.

How does EDG.tech serve insurance agencies?

Carrier portals and the agency management system behind one strong login

Every carrier portal, the comparative rater, and the agency management system get multi-factor authentication and individual accounts instead of a shared password on a sticky note, with a password manager for the dozens of portals staff use daily, and access removed the same hour a producer or CSR leaves.

Applications encrypted and then removed

Application files and the email they arrive in are encrypted on every device, moved into the management system where they belong, and purged from mailboxes and downloads on a retention schedule, so a Social Security number from 2019 is not sitting in a departed CSR's inbox waiting to be found.

Premium and payment fraud protection

Email authentication so no one can send mail as your agency, lookalike-domain monitoring, impersonation detection on messages about premiums, down payments, or carrier remittances, and a verbal confirmation rule for any payment-detail change, written with you and trained with staff.

Attestations and E&O questionnaires answered from evidence

A written security policy, device inventory, training records, and incident response plan kept current in the form carriers, networks, and E&O underwriters ask for, so when the annual attestation or the renewal questionnaire arrives, the agency answers from documents rather than memory.

Which plan fits an insurance agency?

Recommended for insurance agencies
EDG.tech Complete
$100PER USER / MO

Enterprise-grade managed IT & cybersecurity, fully managed, 24/7.

See EDG.tech Complete

Agencies belong on Complete. The risk sits in each producer's and CSR's mailbox and portal logins, which per-user pricing covers together with their devices, and the 24/7 security operations center is what notices a mailbox takeover before a carrier payment is redirected. Essentials fits a one- or two-person agency with a small book and a carrier-provided system.

EDG.tech Essentials is $45 per device per month. Compare both plans 

"Twelve carrier portals, one password on a sticky note. That is the agency we usually meet. A password manager and multi-factor authentication fix it in a week," says Duane Epperly, founder of EDG.tech.

Insurance agency IT questions, answered

Does Maryland's Insurance Data Security Act apply to our agency?

The Act binds carriers directly: a written information security program, a risk assessment, and notice to the Maryland Insurance Administration within three business days of a cybersecurity event. Agencies feel it through the carriers, which increasingly require appointed agencies to attest to controls and report incidents promptly. We help you meet those attestations and keep the evidence behind them.

What does managed IT cost for an independent insurance agency?

EDG.tech Complete is $100 per user per month and includes helpdesk, patching, encryption, multi-factor authentication, a password manager, backup, email and identity protection, and 24/7 monitoring. A six-person agency pays $600 per month. Essentials is $45 per device per month for very small agencies. A written security policy is included at onboarding.

Can you set up multi-factor authentication on all our carrier portals?

Yes. We enable multi-factor authentication on every carrier portal, rater, and agency management system that supports it, give each staff member their own login, and deploy a password manager so the dozens of credentials staff use each day are strong, unique, and removable the hour someone leaves. Shared passwords are the first thing we retire.

How do you keep applications with Social Security numbers from piling up in email?

Email and devices are encrypted, applications are moved into the agency management system where access is controlled, and a retention schedule purges them from mailboxes and download folders automatically. We document the schedule in your security policy so a carrier attestation can say exactly how long client data lives outside the system.

Ready for IT you never have to worry about?

Book a free 30-minute consultation, or start with a free security assessment. You get a fixed price within two business days. No pressure, no jargon.