article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

Covered entities also must conduct an “impact assessment whenever a change in the business or technology causes a material change in the covered entity’s cyber risk.” A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content.

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

To the extent passwords are employed as a method of authentication, the proposed changes would require the covered entity to ensure strong, unique passwords are used. Notifications to DFS. Cybersecurity Event Notification Would Expand.