Remove Business Services Remove Communications Remove Compliance Remove Exercises
article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content. The risk assessments required by Section 500.9

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

Annual certification signed by CEO and CISO : The covered entity’s annual certification of compliance would need to be signed by the CEO and CISO (or by the senior officer responsible for the cybersecurity program if the entity does not have an internal CISO). Penalties for Single Failures. 500.20).

article thumbnail

California Consumer Privacy Act: The Challenge Ahead — Key Terms in the CCPA

HL Chronicle of Data Protection

The CCPA applies to businesses, service providers, and other third parties. The CCPA does not cover every business. We hope that the discussion of key terms in this installment of our blog series on the CCPA will assist businesses as they make compliance plans. Who must comply with the CCPA? Sale and Disclosure.

Privacy 40