Pirlo Cloud Security

Morgantown, West Virginia · Serving agencies remotely

Security and compliance for independent insurance agencies.

A security assessment for agencies and small financial firms, built around the FTC Safeguards Rule and your carrier's cyber requirements. Every finding explained in English, with a specific fix.

AWS Certified Security Specialty, CompTIA Security+, CompTIA Secure Infrastructure Specialist Securing regulated insurance data
Assessment report Sample finding
High F-001

Administrator accounts do not require multi-factor authentication

What it means

Anyone who guesses or steals an admin password gets full access to every client record.

The fix

Turn on MFA for every admin account. Estimated effort is under one hour.

Every finding in your report reads like this: a severity rating, the plain-English impact, and the fix.

The requirement

The rules already apply to you.

Federal

FTC Safeguards Rule

Insurance agencies and other financial institutions must maintain a written information security program with specific required safeguards under 16 CFR Part 314, including a designated qualified individual, risk assessments, and access controls.

State

Insurance data security laws

West Virginia and a growing list of states have adopted insurance data security acts modeled on the NAIC standard, requiring documented risk assessments, oversight of vendors, and breach notification.

Carrier

Cyber insurance conditions

Carriers now condition coverage and renewal on controls like multi-factor authentication, tested backups, and email protection. The renewal questionnaire is effectively an audit, and answering it wrong risks a denied claim.

An assessment tells you exactly where you stand, before a regulator, a carrier, or an attacker does.

The service

Fixed scope. Fixed price. In writing.

Start here

Security and Compliance Assessment

A complete review of your agency's security posture, measured against the Safeguards Rule and your state's requirements.

Two to three weeks. Deliverable is a written report with severity-rated findings and a prioritized fix plan you can hand to any IT provider.

Remediation projects

Fixed-scope fixes for what the assessment finds, from MFA rollout and email protection to cloud configuration.

Each project quoted individually in writing, before any work begins.

Compliance retainer

Ongoing monthly oversight: monitoring, vendor reviews, policy upkeep, and support when your carrier or a regulator asks questions.

Includes a monthly written status report your agency can keep on file as compliance evidence.

Every engagement is quoted in a written proposal with a fixed price, scope, and timeline. No hourly surprises, no pressure calls.

The scope

What the assessment covers.

Identity and access

Who can log in, who holds admin rights, and whether MFA actually protects the accounts that matter.

Email security

Phishing resistance and the protections that stop criminals from spoofing your agency's domain.

Endpoints and devices

The laptops and desktops your team works from: updates, encryption, and protection.

Cloud and system configuration

Your CRM, file storage, and the other systems that hold client data, checked for the misconfigurations attackers look for.

Backups and recovery

Whether you could actually recover from ransomware, and how long it would take.

Vendor management

Who else touches your client data, and whether the paperwork holds them to a real standard.

Written policies

The documented information security program the Safeguards Rule requires you to have and maintain.

What you receive: a written report covering every area above, with each finding rated by severity, explained in plain English, and paired with a fix. A technical appendix gives your IT provider exactly what they need to act.

What's deliberately excluded: penetration testing, and remediation work, which is always quoted separately. The assessment stays independent, so the findings are never shaped by what I might be hired to fix.

The process

Everything in writing, start to finish.

01

Email me

Describe your agency in a sentence or two. No call required, and no one will phone you unprompted.

02

Scoping in writing

A short set of written questions about your size, systems, and the states you operate in.

03

Written proposal within two business days

Fixed price, defined scope, and a timeline. You decide on your own schedule.

04

The assessment

Two to three weeks, with minimal disruption to your team. Read-only access wherever possible.

05

Report and walkthrough

You get the full written report, plus a walkthrough of the findings in plain business terms and what to do first.

The consultant

Addison Pirlo, Principal Consultant.

I have hands on experience securing a production insurance CRM handling HIPAA and GLBA regulated client data, including a full security assessment that documented 76~ findings across the platform and verified every critical fix before launch.

That work is the model for every engagement, findings mapped to the actual regulations that apply to you, explained in terms an agency principal can act on, and verified rather than assumed fixed.

I hold a B.S. in Cloud and Network Engineering - Amazon Web Services from Western Governors University, and Pirlo Cloud Security LLC is registered in West Virginia.

Selected certifications

  • AWS Certified Security, Specialty
  • AWS Certified Solutions Architect, Professional
  • AWS Certified DevOps Engineer, Professional
  • Azure Solutions Architect Expert
  • Azure DevOps Engineer Expert
  • Azure Security Engineer Associate
  • CompTIA Security+

Every assessment is performed directly by an AWS and Azure certified cloud security consultant with experience securing regulated insurance systems.

Start with an email.

Tell me about your agency. You'll get a written reply, and if it's a fit, a fixed-price proposal within two business days of scoping.

Email addison@pirlocloudsecurity.com

Pirlo Cloud Security LLC · Morgantown, West Virginia · Working with agencies remotely