The Illinois Department of Insurance Issues Cybersecurity Guidance Regarding Microsoft Exchange Server Installations
Privacy, Cyber & AI Decoded Alert | 2 min read
Jun 4, 2021
The Illinois Department of Insurance (the "Department") recently released guidance to all regulated entities concerning vulnerabilities in Microsoft's Exchange Server installations. Issued on the heels of other state and federal agency warnings and directives, the guidance outlines pertinent details of the vulnerabilities and what successful exploitation of these vulnerabilities could mean—namely "persistent system access and control of an enterprise network." Recognizing that servers may still be compromised even after March and April fixes have been applied, the Department urges regulated entities to:
- Immediately assess the risk to their systems and consumers and take steps to address them;
- Identify internal use of vulnerable Microsoft Exchange products and any use of these products by critical third parties;
- Immediately patch or disconnect vulnerable servers and use tools provided by Microsoft to identify and remediate; and
- Continue to track developments and respond quickly to new information.
Although failure to follow the Department's guidance cannot result in an enforcement action at this juncture, it could potentially support claims in a civil or criminal action given the overwhelming amount of public notice.
Also significant is that the guidance is yet another example of a government agency seeking to monitor and advise on cybersecurity events. This further demonstrates increased governmental interest and foreshadows potential legislation in Illinois and at the federal level. Businesses that already have risk assessment tools and cybersecurity policies in place will be in an excellent position to meet and comply with any future requirements. In addition, it is noteworthy that the average cost of a data breach in 2020—according to the Ponemon Institute—was 3.86 million dollars, which in the short term can significantly impact an organization's operations. Given the possible risks of such a serious and large scale event, we strongly advise businesses to follow the Department's guidance.
Related Content
Related People
Related Capabilities
Featured Insights

Employment Law Observer
Aug 10, 2026
As Leaves Fall, Leave Requests Rise: Are You Compliant With Chicago’s Expanded Rules?

Press Release
Aug 7, 2026
Daniel McGrath Re-Elected Senior Director of the Federation of Defense & Corporate Counsel

Insights for Insurers Alert
Aug 7, 2026
California Supreme Court Clarifies Pleading Standards for Excess Policy Claims

Press Release
Aug 6, 2026
Charles Townsend Named a Best Mentor Finalist in the 2026 ALM Texas Legal Awards

Webinar
Aug 5, 2026
April Toy Moderates HNBA Webinar on AI in the Practice of Law

Privacy, Cyber & AI Decoded Alert
Aug 5, 2026
2026 AI Compliance: Upcoming Laws Every Organization Needs to Know

Press Release
July 21, 2026 | Updated on August 4, 2026
Three Hinshaw Attorneys Named to the 2026 National Black Lawyers’ Top 40 Under 40 List

Healthcare Alert
Aug 3, 2026
Fixing the Emergency Refill Trap: What California’s AB 1587 Means for Pharmacies

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies


