Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

New York's Cyber Regulation Two Years Later: We've Only Just Begun

By Craig A. Newman and Kade N. Olsen
May 01, 2019

Financial institutions regulated by New York's Department of Financial Services (DFS) can breathe a sigh of relief, at least temporarily. Two years after DFS's Cybersecurity Requirements for Financial Institutions took effect, and more than three years after the cybersecurity regulation was announced, the final provision of the law became effective on March 1 of this year.

But the celebrations must be short. DFS got it right when describing its then-new regulation as the “first in the nation.” Like the federal Sarbanes-Oxley Act of 2002, financial institutions will have to certify annually that their internal controls and cybersecurity practices remain up to snuff. And now that the transitional periods for implementing the cyber regulation have passed, covered institutions will need to certify that they have complied with each provision.

Some of those requirements are one-off. For example, §500.04 required each covered entity to “designate” a Chief Information Security Officer (CISO). And §500.16 required companies to establish an incident response plan. Absent changes at the company or a need to update compliance, covered entities will not have much to do on a day-to-day basis when it comes to these two requirements.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Major Differences In UK, U.S. Copyright Laws Image

This article highlights how copyright law in the United Kingdom differs from U.S. copyright law, and points out differences that may be crucial to entertainment and media businesses familiar with U.S law that are interested in operating in the United Kingdom or under UK law. The article also briefly addresses contrasts in UK and U.S. trademark law.

Strategy vs. Tactics: Two Sides of a Difficult Coin Image

With each successive large-scale cyber attack, it is slowly becoming clear that ransomware attacks are targeting the critical infrastructure of the most powerful country on the planet. Understanding the strategy, and tactics of our opponents, as well as the strategy and the tactics we implement as a response are vital to victory.

The Article 8 Opt In Image

The Article 8 opt-in election adds an additional layer of complexity to the already labyrinthine rules governing perfection of security interests under the UCC. A lender that is unaware of the nuances created by the opt in (may find its security interest vulnerable to being primed by another party that has taken steps to perfect in a superior manner under the circumstances.

Removing Restrictive Covenants In New York Image

In Rockwell v. Despart, the New York Supreme Court, Third Department, recently revisited a recurring question: When may a landowner seek judicial removal of a covenant restricting use of her land?

Fresh Filings Image

Notable recent court filings in entertainment law.