Remove Authentication Remove Business Services Remove Compliance Remove Exercises
article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

Covered entities also must conduct an “impact assessment whenever a change in the business or technology causes a material change in the covered entity’s cyber risk.” A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content.

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

New annual certification of non-compliance : The draft amendments now provide for a certification of non-compliance that describes the nature and extent of such noncompliance and identifies all areas, systems, and processes that require material improvement, updating or redesign. Notifications to DFS. Penalties for Single Failures.