New · Sept 10DFS issued guidance on cybersecurity risk assessments today. If your team started using AI this year, it says your last assessment may already be out of date.Walter explains in 4 minutes →
For New York insurance agencies

Your IT company has never sat on a DFS audit. We have.

Twenty-five years of them, in fact. Here's what we keep finding.

Walter conducts these personally and takes on a limited number each month.
Garden City, New York · independent agencies only, for 25 years.

Silver DFS instructor
credential badge
(SVG — to add)
Walter Contreras is approved by the Superintendent of Insurance as an instructor in the New York DFS continuing-education program, teaching forBig I New York.
Big I New York memberPIA memberSOC 2
Type II
Google 5.0★ +500 ReviewsNYDFS approved instructor
What we keep finding

What we keep finding inside agencies that thought they were fine.

Redacted real evidence — the dark-web password list with carrier portals visible and logins masked, or the assessment's cyber-risk gauge
01
The hacker had been in the mailbox for 31 days before anyone noticed.
Nothing flagged it. The owner found out when clients started calling about phishing coming from the agency's own address.
02
Friday, 5 p.m. A carrier email with the week's binding list — and a new routing number.
Same format, same sender to the eye. The wire went out for $90,000. Hackers don't send viruses anymore. They sit in the inbox and pick a Friday.
03
The owner had no idea what AI the staff was using.
Copilot was already in Microsoft 365. Someone used it to draft a renewal, and it never came up. Almost every agency, every time.
04
3,517 passwords on six computers. 970 already for sale.
Carrier portal logins saved in a browser, one reused across 27 sites. Nothing was set up to tell anyone.
05
Client files sitting unencrypted, right where a producer would paste them.
Applications, tax documents, claim files on shared drives and desktops. The distance to a stolen laptop is about four seconds.
06
And when it goes wrong, you are the one answering for it.
Not your IT company. The regulator's questions come to the owner, and the first one is what your logs show. Most owners find out that day the answer is nothing.

None of it is exotic. That is the point — ordinary gaps, in ordinary agencies, and every one was stoppable with ordinary controls a general IT company is not built to look for.
See how we close each one →

Twenty-five years in the room

Anyone can say they work with insurance agencies. We've done it for 25 years.

The start
We started with agencies

Not dentists, not law firms. Independent agencies on Long Island — and we never widened it.

Early on
The first event we put our name on

A room full of people who had no idea who we were. Most of them know now.

The credential
Approved to teach for Big I New York

Walter became a New York State approved cybersecurity instructor for the Independent Insurance Agents & Brokers of New York.

Today
In the CISO seat

Part 500 asks every agency for a designated CISO. Most independents never filled it. Walter fills it for the agencies we protect.


One industry, for twenty-five years.

We didn't add insurance to a list of industries — itisthe list. Twenty-five years of AMS migrations, carrier portal logins, renewal seasons and April certifications, inside agencies, with the people who run them.

And we hold ourselves to the standard we ask of you. Motiva is SOC 2 Type II examined — an independent auditor tests our own controls every year. The report is available to any client who asks.

AMS360Applied EpicEZLynxVertaforeHawkSoftCarrier portalsACORD formsCertificates of insuranceE&O renewalsProducer onboardingBook rollsPart 500 certificationThird-party vendor oversightAMS360Applied EpicEZLynxVertaforeHawkSoftCarrier portalsACORD formsCertificates of insuranceE&O renewalsProducer onboardingBook rollsPart 500 certificationThird-party vendor oversight

If you have to explain any of these to your IT company, they are not an insurance IT company.

What we understand

We know what running an agency actually looks like.

§500.12 · Multi-factor authentication

Your agency management system is the heart of the business.

So it sits behind MFA or single sign-on, and nobody reaches it with a password saved in a browser.

§500.15 · Encryption

W-2s, applications and claim files end up on desktops. Always.

Drive encryption on every machine and PII moved into a vault, so a lost laptop is a lost laptop — not a breach notification.

§500.07 · Access privileges

A producer leaves. Your agency's information should not leave with them.

Every hire and departure runs a Motiva onboarding and offboarding checklist — AMS, carrier portals, email, the shared drive, the phone. Access granted on day one, removed on the last, and the record of both kept.

§500.03 · Policy  ·  §500.17 · Certification

Every April 15th, we sign the certification with you.

As your designated CISO, Walter's name goes on the Part 500 certification next to yours — so the policies, training records and evidence behind it are things he built and will stand behind.

Walter Contreras
headshot
Who you talk to

You talk to Walter. Every time.

Every consultation, every assessment, every strategic conversation is with our CEO — not a rep, not an account manager who loops him in later. He teaches the continuing-education classes agency staff sit through, and he serves as designated CISO for the agencies we protect — the seat Part 500 asks for and most independents never filled.

  • New York State approved cybersecurity instructor
  • Instructor for Big I New York
  • Acting CISO for the agencies we protect
  • Graduate of Columbia Business School
  • Host of the Breaking Protocol podcast
  • Garden City — local to the agencies he serves
Request a conversation with Walter
Agencies stay with us

What owners say after a few years, not a few weeks.

“Cavallino Risk would not have survived the economic turmoil of the great recession or the disruptive technology in the retail insurance marketplace without the support of Motiva.”

Frank Caponi
President, Cavallino Risk Management

“The thing that sets Motiva apart is that they shine through and are there for you when needed.”

William Libardi
President, Libardi Service Agency

“They follow up to make sure the issues were handled to our satisfaction; I have never had a tech company do that.”

Robert Stone
Managing Director, Stone Insurance
25
Years working only with independent agencies
100+
Independent agencies protected
98%
Issues resolved on first contact
SOC 2
Type II examined — the controls we ask of you
Resources

Written for agency owners, not for IT people.

Free guide

The Agency AI Playbook

Four steps to find out what AI your staff is already using, and a one-page use policy you can hand out. About twenty minutes.

Get the guide →
Podcast

Breaking Protocol

Walter talks to agency owners and the people who regulate them. Plain English, no IT jargon.

Coming Soon
Checklist

What DFS actually asks for

The documents an agency your size gets asked to produce, and the order to build them in.

Get the checklist →

Let's talk about your agency.

A conversation with Walter, not a rep — whether you have an exam coming, a question about what your staff is doing with AI, or you just want a second opinion on your current setup.