On November 25, 2024, the New York State Department of Financial Services (“NYDFS”) announced it settled with two large insurance companies over allegations of inadequate data security practices in violation of New York’s cybersecurity regulation (23 NYCRR Part 500) (the “Cybersecurity Regulation”) that led to the compromise of more than 120,000 New Yorkers’ personal information.
Latest Post
More Posts
Department of Defense proposes requirements for assessing contractor cybersecurity
CISA issues proposed rules for cyber incident reporting in critical infrastructure
NYDFS issues significant guidance on insurers using AI or external data
FCC adopts updated data breach notification rules to protect consumers
FTC amendment to Safeguards Rule
Subscribe: Subscribe via RSS
Blogs
Firm/Org