Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.
By Katherine Lemire and Laura Ferguson
On November 1, significant revisions to the regulations enforced by the New York Department of Financial Services (DFS) — the state’s financial services regulator — went into effect. The DFS revisions create a long-arm provision in that the changes affect not only New York State companies, but also their affiliates, and therefore the revisions could have an impact far beyond New York State borders.
DFS amended its cybersecurity regulations in November 2023, directly affecting New York State-regulated financial services companies, including insurers, crypto exchanges, mortgage servicers, foreign bank branches, money transmitters, student lenders, and fintech companies. The amended regulation, 23 NYCRR 500, often referred to as “Part 500,” has been touted by DFS as a first-of-its-kind regulation that aimed at improving institutional cybersecurity preparedness, response, and governance in New York’s financial services sector. Part 500 established various cybersecurity requirements for the so-defined “Covered Entity,” including maintenance of a cybersecurity program and designation of a qualified Chief Information Security Officer (CISO) overseeing the program; implementation of a written cybersecurity policy; regularly conducted vulnerability assessments; multi-factor authentication for external access to the company’s server; mandatory reporting of serious data breaches; and employee training.
Highlights of the changes to the DFS cybersecurity regulations include:
*****
ENJOY UNLIMITED ACCESS TO THE SINGLE SOURCE OF OBJECTIVE LEGAL ANALYSIS, PRACTICAL INSIGHTS, AND NEWS IN ENTERTAINMENT LAW.
Already a have an account? Sign In Now Log In Now
For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473
The business-law issue of whether and when a corporate defendant is considered distinct from its affiliated entities emerged on December 11 at the U.S. Supreme Court, with the justices confronting whether a non-defendant’s affiliate’s revenue can be part of a judge’s calculation of the monetary remedy for the corporate defendant’s infringement of a trademark.
The most forward-thinking companies embrace AI with complete confidence because they have created governance programs that serve as guardrails for this incredible new technology. Effective governance ensures AI consistently aligns with an organization’s best interests, safeguarding against potential risks while unlocking its full potential.
It’s time for our annual poll of experts on what they expect 2025 to bring in legal tech, including generative AI (of course), e-discovery, and more.
AI’s rapid market proliferation and regulatory expansion mirrors privacy’s, and businesses should model their contractual AI compliance on the successes of privacy law’s DPA and BAA.
Traditional keyword strategies and ranking tactics are losing ground to a more dynamic approach in which optimizing for search now means optimizing for every platform and user interaction. This evolution is appropriately being called “Search Everywhere Optimization.” The redefined SEO reflects how AI is not just changing how people find information but also how businesses need to think about visibility in an increasingly connected digital ecosystem.