Remove Business Services Remove Compliance Remove Exercises Remove Ransomware
article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content. of the Proposed Amendments, must contain proactive measures to mitigate disruptive events ( e.g. , ransomware events) and ensure operational resilience.

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

Annual certification signed by CEO and CISO : The covered entity’s annual certification of compliance would need to be signed by the CEO and CISO (or by the senior officer responsible for the cybersecurity program if the entity does not have an internal CISO). Extortion Payments. Penalties for Single Failures. 500.20).