Posts

Showing posts with the label IT service

Why The Shield Act In New York Is A Big Deal

Image
The SHIELD Act in New York is a bill that was introduced in 2019 by Andrew Cuomo, Governor of New York City. Its purpose is to provide protection for companies that share information about cyberthreats with each other so that they can work together to prevent data breaches and protect their customers’ information. The new SHIELD Act protects businesses from cyberattacks by requiring that they report any security breaches to both the New York Attorney General and their customers. This is a big deal because it covers a wider spectrum of businesses in New York. It applies to all businesses that have customers in New York and those that do business there, regardless of where they are located. It also applies to any breach involving New York residents’ personal information, regardless of where the company is located or where the hack occurred. That means if you’re an out-of-state business with employees or customers in New York, you still have to comply with th...

What The NY DFS Cybersecurity Regulations Mandate?

Image
The NYS DFS (New York State Department of Financial Services), declared 23 New York Code Rules and Regulations 500 (23 NYCRR 500), a cybersecurity regulation for financial service organizations doing business in New York state. All banks, financial organizations and identical businesses must comprehend their accountabilities under 23 NYCRR 500, especially for strong authentication & securing data. Listed below are the requirements 23 NYCRR 500 places on financial institution operating in the state of NY. Prepare policies & procedures for safeguarding information systems: There should be a standard written guideline with procedures in place to safeguard information system, consumer data, and other nonpublic minutiae. The guideline must be based on a comprehensive & stout risk evaluation. Hire a CISO: All financial institutions must appoint a Chief Information Security Officer who is accountable for supervising & executing a cybersecurity program that safeguards system...

Four Phases of the 23 NYCRR 500 Regulations – A Brief Overview

Image
The threat of cyberattacks has been growing tremendously, because of which businesses operating in the financial and insurance industries in New York have been mandated to establish stronger cybersecurity programs. The New York State Department of Financial Services i.e., NYDFS, has hence passed a set of rules and regulations called the 23 NYCRR 500 for supervising the banks, insurance organizations, and other financial organizations/institutions to create and keep up robust cybersecurity programs.  The first phase of the  23 NYCRR 500  regulations was finalized on March 1, 2017, needing the covered entities to comply with the regulation before August 28, 2017. Want to get your organization compliant to the regulations within the set 23 NYCRR 500 timeline?  Four Phases of NYDFS Cybersecurity Regulation (23 NYCRR 500) The compliance requirements for 23 NYCRR 500 cybersecurity regulations were rolled out in four phases in a two ...