ARTICLE
24 January 2017

What Do You Need To Know About New York And Cybersecurity

FR
Fox Rothschild LLP

Contributor

Who We Are

With bold growth, Fox Rothschild brings together 1,000 attorneys coast to coast. We offer the reach and resources of a national law firm combined with the personal touch and connections of a boutique firm.

Our Mission

Solving problems is our top priority. We invest the time to get to know you and understand your needs. We work hard to win every client’s loyalty. We do that by providing creative solutions and excellent client service.

At its core, the rules require these entities to have cybersecurity programs directed to consumer protection.
United States Finance and Banking
Fox Rothschild LLP are most popular:
  • within Privacy topic(s)
  • in European Union

On March 1, New York will go live with cybersecurity rules for financial service providers such as banks, insurance companies and others subject to the Department of Financial Services' jurisdiction. At its core, the rules require these entities to have cybersecurity programs directed to consumer protection.

New York firms must now have written policies and procedures, as well as a designated chief information security officer to oversee, train, enforce the program and report hacking to the state. Any report of hacking must take place within 72 hours of the hack, where the hack has a reasonable likelihood to impact firm operations.

This program will necessarily create new costs for these companies. Specifically, there is a cost in finding an adequately trained and certified individual to serve in the role of chief information security officer. Additional costs will arise from the mandate that firms monitor all data leaving it and to have email systems that block certain forms of information like Social Security numbers.

With this cost, however, will come added protection for consumers and, in turn consumer confidence in their financial institutions. This one of a kind program is likely not to be the only one in the coming years.

More and more states will implement such data security protocols for the purpose of consumer protection.   Are you doing enough now in the absence of regulation to protect consumer information?

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More