Put Your Agency on the Right Side of South Carolina’s Data Security Law

Managed IT and SC Insurance Data Security Act compliance for independent agencies with 1 to 50 employees — built around the Written Information Security Program the state already requires you to have.

South Carolina was the first state in the country to adopt the NAIC Insurance Data Security Model Law. Every licensed agency is required to have a Written Information Security Program, conduct risk assessments, and report cybersecurity events to the Department of Insurance within 72 hours of determining an event occurred.

Dealing with a problem right now? Call (803) 881-3771 — you’ll get a straight answer on whether we can help and what it would take. Not a sales pitch.

Locally owned in Irmo, SCFlat rate, locked 24 monthsFree on-site IT walkthroughBuilt for 1–50 employees

The daily cost

Your Producers Should Be Writing Policies — Not Resetting Passwords

The office manager is on hold with HawkSoft because a quoting issue is holding up a renewal. A CSR who happens to know her way around a computer is trying to get the network printer working before a client comes in to sign. The agency owner is staying late because Applied Epic froze during a policy change and nobody else knows what to do.

Every one of those hours is time not spent writing policies, servicing accounts, or following up on quotes. And the compliance problem running underneath it is bigger than the daily frustration. The WISP deadline passed on July 1, 2019.

Most agencies in this market know the law exists. Almost none have the documentation it requires.

The program

Six Controls. Nothing You Don’t Need.

The same six controls go into every managed agreement, mapped to what your framework requires and configured around the software your team already uses.

CONTROL 01

Multi-Factor Authentication

On every account that holds sensitive data — email, banking, accounting, practice management, cloud storage. Paired with a password manager so your team isn’t drowning in credentials.

CONTROL 02

Automatic Security Updates

Unpatched software is now the single most common way attackers get in. Patches applied when they’re released, not queued for a testing cycle that never happens.

CONTROL 03

Email Security & Training

Technical filtering in Microsoft 365 or Google Workspace, plus staff training built on education and positive reinforcement — not fake phishing tests designed to catch your employees failing.

CONTROL 04

Backup & Recovery, Tested Quarterly

Critical data backed up in two locations, tested every quarter, documented, and reported to you. A backup that’s never been tested isn’t a backup. It’s a hope.

CONTROL 05

Restricted Admin Access

Your employees don’t need the ability to install software or change system settings. Restricting admin access eliminates an entire category of problems before they start.

CONTROL 06

Your Three Core Documents

An incident response plan, a password policy, and an offboarding checklist. Who to call when something goes wrong, how your team handles credentials, and how to kill access the day someone leaves.

Count your contractors before you decide you’re exempt

The Act exempts licensees with fewer than ten employees — but the statute says “including any independent contractors.” A seven-person agency with four contracted producers is at eleven, not seven, and owes the full Written Information Security Program. This is the single most common way agencies in this market conclude they’re exempt when they aren’t. And the exemption is narrower than most people assume even when it does apply: it exempts you from the WISP requirement, not from investigating a cybersecurity event or notifying the Department when one occurs.

Compliance

What the SC Insurance Data Security Act Actually Requires

A comprehensive Written Information Security Program. Annual risk assessments. A designated person responsible for the security program. Specific technical safeguards. Certification to the Department by February 15 each year, with five-year record retention.

And when something happens: notification to the Director of the Department of Insurance within 72 hours of determining that a cybersecurity event has occurred. Not 72 business days. Seventy-two hours — which is not enough time to build an incident response plan from scratch.

What we build, inside your managed agreement: the complete WISP and its supporting documentation — risk assessment, incident response plan, password policy, offboarding checklist. Six security controls that map directly to what the law requires, implemented on day one. Annual certification documentation ready when the state asks for it.

What you actually get

Compliance Documentation That Exists on Paper, Not in a Sales Pitch

Most IT companies mention compliance and never deliver the documents. Every managed agreement produces real artifacts — the risk assessment, the written security plan, the incident response plan, the quarterly restore report. When a carrier audit or a regulatory inquiry arrives, the answer is already written.

Your stack

Software We Support Around

Applied Epic · HawkSoft · AMS360 · comparative raters · and the carrier portal integrations your agency depends on for quoting and renewals.

Geoffrey Giles, founder of Soda City Systems

Geoffrey Giles
Founder · former Virtual CIO

Why us

Built by Someone Who Managed $24 Million in Annual IT Spend — and Saw What Wasn’t Working

Soda City Systems was founded by a former Virtual CIO at a national managed IT provider, where he managed $24 million in annual IT spend across South Carolina. That role made one thing clear: as IT firms grow and get acquired, businesses with 10 to 50 employees stop getting the attention they need.

Your problems stop repeating.

Every issue we resolve gets a second look — what caused it, and what would prevent it. The businesses that have worked with us longest call us the least.

You never start over with a stranger.

You have an accountant who already knows your books. You have an attorney who already knows your contracts. Now you have an IT team that already knows your technology.

Your IT company doesn’t outgrow you.

We’re not an enterprise firm that occasionally takes a small client, and not a solo consultant who disappears for a week. Founder-operated and locally owned, built for businesses your size and only your size.

Our guarantees

Three Commitments, in Writing

Guarantee 01

The 60-Day Out

If the relationship isn’t working, give us 60 days’ notice and walk. No penalties, no buyout fees. We hand off your documentation, credentials, and configuration to whoever comes next.

Guarantee 02

The Rate Lock

Your per-user rate is fixed for 24 months from signing. If our prices go up, yours doesn’t change until month 25.

Guarantee 03

The Quarterly Restore Test

Every quarter we restore your data from backup, document the result, and send you the report. If a restore fails, we fix the cause and re-test before the quarter closes, at no charge.

Questions

Common Questions

Does the SC Insurance Data Security Act apply to my agency?

If you’re a licensed insurance agency in South Carolina, yes. The WISP requirement exempts licensees with fewer than ten employees — but the statute counts independent contractors toward that total, which catches a lot of agencies off guard. Even exempt licensees still owe investigation and notification obligations.

What is a WISP, exactly?

A Written Information Security Program: a documented plan covering how your agency protects nonpublic information, who is responsible for it, what safeguards are in place, how risks are assessed, and what happens when there’s an incident. It has to exist on paper, be maintained, and be produced on request.

How fast do we really have to report a cybersecurity event?

Within 72 hours of determining that an event has occurred. The clock runs from determination, not from discovery, but either way it’s short enough that the plan needs to already exist.

How much does managed IT cost for an agency our size?

Starting at $100 per user, per month, locked for 24 months. Agencies with compliance documentation needs typically sit above the floor because the WISP and annual certification work is ongoing, not one-time.

We already have an IT company. Can you just do the compliance piece?

Usually the two aren’t separable — the WISP has to describe controls that actually exist, and the annual certification says they’re in place. If your current provider has the six controls handled, we’ll say so during the walkthrough rather than sell you something you don’t need.

Free IT walkthrough

Find Out Where Your Agency Stands

The right IT plan for a 12-person insurance agency looks nothing like the right plan for a 30-person dental practice. We’ll come to your office, look at your current setup, talk through what’s working and what isn’t, and give you a clear recommendation.

It takes about an hour. No pressure, no contracts, no 47-slide presentation.

Prefer to just call?
(803) 881-3771

Monday–Friday, 8am–5pm Eastern

Book your walkthrough

We’ll call you back within one business hour.

We’ll call you back within one business hour.

We don’t share your information with anyone, and we won’t add you to a mailing list you didn’t ask for.