article thumbnail

NYDFS Amends Cybersecurity Rules for Financial Services Companies

Hunton Privacy

The proposed amendments provides three new cybersecurity events that Covered Entities must report to NYDFS via the NYDFS online cybersecurity portal within 72 hours: Unauthorized access to privileged accounts; Deployment of ransomware within a material part of the Covered Entity’s systems; and. Revised Definition of Class A Companies.

article thumbnail

NYDFS releases major update to Part 500 cybersecurity requirements for financial services companies

Data Protection Report

Requirements The Amendment includes a new requirement to report to the superintendent of NYDFS when a ransomware event has been deployed in a material part of the covered entity’s information system (500.1(g)(3)). The Amendment also includes new governance requirements and responsibilities applicable to the CISO of all covered entities.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

World Backup Day 2023: Five Essential Cyber Hygiene Tips

Thales Cloud Protection & Licensing

Exercising the principle of least privilege is always recommended: every user, app, program, and device should be able to access only the areas and data that are necessary for their function. All of these can be considered best practices to secure your private data, and comply with various compliance mandates.

article thumbnail

Saudi Arabia’s New Data Protection Law – What you need to know

DLA Piper Privacy Matters

Ongoing compliance with existing laws and NDMO Personal Data Protection Interim Regulations. The PDPL does not appear to repeal the existing NDMO Personal Data Protection Interim Regulations, and so Data Controllers would appear to still need to comply with those regulations, while developing their compliance with the new PDPL.

article thumbnail

2022 Cyber Security Review of the Year

IT Governance

Although Vladimir Putin and his sympathisers assured the world that they were simply conducting military exercises, the inevitable occurred on 24 February, when troops mobilised and war was declared. By comparison, a report published last year found that US firms pay $6 million on average in ransomware demands.

Security 132
article thumbnail

CyberheistNews Vol 13 #14 [Eyes on the Prize] How Crafty Cons Attempted a 36 Million Vendor Email Heist

KnowBe4

Grimes Teaches Ransomware Mitigation Cyber-criminals have become thoughtful about ransomware attacks; taking time to maximize your organization's potential damage and their payoff. Join Roger for this thought-provoking webinar to learn what you can do to prevent, detect, and mitigate ransomware. Also appreciate the book." - W.K.,

article thumbnail

MY TAKE: COVID-19’s silver lining could turn out to be more rapid, wide adoption of cyber hygiene

The Last Watchdog

federal data handling rules for contractors, for which compliance was by-and-large voluntary. Ransomware hacking groups extorted at least $144.35 Beyond that, use social media judiciously and exercise extreme caution clicking on any email attachments or any webpage link sent your way. million from U.S.