article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content. The risk assessments required by Section 500.9

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

New annual certification of non-compliance : The draft amendments now provide for a certification of non-compliance that describes the nature and extent of such noncompliance and identifies all areas, systems, and processes that require material improvement, updating or redesign. Penalties for Single Failures. 500.20).

article thumbnail

California Consumer Privacy Act: The Challenge Ahead — Key Terms in the CCPA

HL Chronicle of Data Protection

The CCPA applies to businesses, service providers, and other third parties. The CCPA does not cover every business. We hope that the discussion of key terms in this installment of our blog series on the CCPA will assist businesses as they make compliance plans. Who must comply with the CCPA? No Discrimination.

Privacy 40