IL Company Bulletin 2021-15
All Regulated Entities : Company Bulletin 2021-15 Log4j Vulnerability
Springfield Office
320 W. Washington Street
Springfield, Illinois 62767
(217) 782-4515
Chicago Office
122 S. Michigan Ave., 19th Floor
Chicago, Illinois 60603
(312) 814-2420
Illinois Department of Insurance
JB PRITZKER
Governor
DANA POPISH SEVERINGHAUS
Acting Director
TO:
All Regulated Entities
FROM:
Dana Popish Severinghaus, Acting Director
DATE:
December 20, 2021
RE:
CB 2021-15
Log4j Vulnerability
The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency
(“CISA”) and its partners in the Joint Cyber Defense Collaborative have issued urgent guidance about a
critical remote code execution (“RCE”) vulnerability in many versions of Apache’s Log4j software.
CISA has warned that the vulnerability is serious and expected to be used by hackers to infiltrate
organization’s computer networks.
The Department urges all regulated entities to review and monitor the CISA resource page and take
immediate steps to identify and mitigate any risks posed by the Log4j vulnerabilities. Regulated entities
are reminded to report cybersecurity events that fall under the Illinois Personal Information Protection
Act (815 ILCS 530/1 et seq.) to the consumer and/or the Illinois Attorney General as required by the
Act.
Questions regarding this Bulletin should be directed to DOI.InfoDesk@illinois.gov.