article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content. The risk assessments required by Section 500.9

article thumbnail

California Consumer Privacy Act: The Challenge Ahead — Key Terms in the CCPA

HL Chronicle of Data Protection

The CCPA applies to businesses, service providers, and other third parties. The CCPA does not cover every business. Unless addressed in future legislative activity in 2019, these differences will have significant implications for what covered organizations must do to comply with the CCPA. Who must comply with the CCPA?

Privacy 40
article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

Board Cyber Expertise : The company’s board (or appropriate committee of the board) is required to have sufficient expertise and knowledge, or be advised by persons with sufficient expertise and knowledge, to exercise effective oversight of cyber risk and a committee or subcommittee assigned responsibility for cybersecurity (the SEC has imposed a similar (..)