article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

A covered entity’s cyber program must include phishing training and exercises, as well as monitoring and filtering of emails to block malicious content. of the Proposed Amendments, must contain proactive measures to mitigate disruptive events ( e.g. , ransomware events) and ensure operational resilience.

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

Covered entities must also periodically test their incident response plans (including “disruptive events such as ransomware,” which NYDFS specifically would require) and their ability to restore systems from backups. Companies would need to maintain backups that are isolated from network connections. Extortion Payments.