The licensee shall provide the information in electronic form as directed by the Director. The licensee shall have a continuing obligation to update and supplement initial and subsequent notifications to the Director regarding material changes to previously provided information relating to the cybersecurity event.
In the case of a cybersecurity event involving nonpublic information that is in the possession, custody, or control of a third-party service provider of a licensee that is an assuming insurer, the assuming insurer shall notify its affected ceding insurers and the Director of its state of domicile within 3 business days after receiving notice from its third-party service provider that a cybersecurity event has occurred.
The ceding insurers that have a direct contractual relationship with affected consumers shall fulfill the consumer notification requirements imposed under the Personal Information Protection Act and any other notification requirements relating to a cybersecurity event imposed under this Section.
215 ILCS 215/20