The Illinois Department of Insurance Issues Cybersecurity Guidance Regarding Microsoft Exchange Server Installations
Privacy, Cyber & AI Decoded Alert | 2 min read
Jun 4, 2021
The Illinois Department of Insurance (the "Department") recently released guidance to all regulated entities concerning vulnerabilities in Microsoft's Exchange Server installations. Issued on the heels of other state and federal agency warnings and directives, the guidance outlines pertinent details of the vulnerabilities and what successful exploitation of these vulnerabilities could mean—namely "persistent system access and control of an enterprise network." Recognizing that servers may still be compromised even after March and April fixes have been applied, the Department urges regulated entities to:
- Immediately assess the risk to their systems and consumers and take steps to address them;
- Identify internal use of vulnerable Microsoft Exchange products and any use of these products by critical third parties;
- Immediately patch or disconnect vulnerable servers and use tools provided by Microsoft to identify and remediate; and
- Continue to track developments and respond quickly to new information.
Although failure to follow the Department's guidance cannot result in an enforcement action at this juncture, it could potentially support claims in a civil or criminal action given the overwhelming amount of public notice.
Also significant is that the guidance is yet another example of a government agency seeking to monitor and advise on cybersecurity events. This further demonstrates increased governmental interest and foreshadows potential legislation in Illinois and at the federal level. Businesses that already have risk assessment tools and cybersecurity policies in place will be in an excellent position to meet and comply with any future requirements. In addition, it is noteworthy that the average cost of a data breach in 2020—according to the Ponemon Institute—was 3.86 million dollars, which in the short term can significantly impact an organization's operations. Given the possible risks of such a serious and large scale event, we strongly advise businesses to follow the Department's guidance.
Related Content
Related People
Related Capabilities
Featured Insights

Press Release
Sep 18, 2026
Paris Glazer Named to Chicago Daily Law Bulletin’s 2026 40 Attorneys Under Forty

Consumer Crossroads: Where Financial Services and Litigation Intersect
Sep 17, 2026
Federal and State Regulators Continue Crackdown on Junk Fees

Press Release
Sep 17, 2026
Defense Verdict Reduces $134 Million Demand to $2 Million in Catastrophic Motorcycle Injury Case

Insights for Insurers Alert
Sep 16, 2026
America 250: The Nation’s Unique Contributions to Insurance Coverage Law and Litigation

In The News
Sep 15, 2026
Lucy Wang Discusses the California Insurance Commissioner’s Role in Protecting Consumers

Press Release
Sep 10, 2026
Hinshaw Attorneys Recognized as 2027 Lexology Index Thought Leaders: USA

In The News
Sep 10, 2026
Nicholas Ajello and Gregory Emry Analyze FAA’s Proposed BVLOS Drone Regulations

Consumer Crossroads: Where Financial Services and Litigation Intersect
Sep 9, 2026
“Play Now, Arbitrate Later”—“Not So Fast,” Ninth Circuit Says

In The News
Sep 9, 2026
Jennifer Driscoll Discusses “Patchwork” of Laws Targeting Personalized Pricing

Employment Law Observer
Sep 8, 2026
Five Workplace Issues Every Employer Should Address Before They Become a Costly Lawsuit

Press Release
Sep 8, 2026
Jim Sandy Appointed Chair of ABA Debt Collection and Bankruptcy Subcommittee


