BSN Blog 12.11.19

Getting Ahead of the Curve

BSN Blog 12.11.19

Plan, people, policies

Under the guidance of Maria Vullo, the New York Department of Financial Services (NYDFS) created and finalized cybersecurity regulations for the banks, insurance companies, money transmitters, credit unions, brokers, and mortgage bankers that they oversee.  These companies and institutions run the gamut in size and sophistication of their systems. So, they looked at it individually but reviewed the risk level and factors of each one.

This was done AHEAD of any federal or local laws that were put into place.  A forward way of thinking that will likely save many businesses from losing it all should they be afflicted by a breach.

What is interesting about their approach, aside from being done proactively and not reactively, is that the rules are risk-based.  This means that they don’t have a straight prescription but made it so that companies weren’t limited to adhering to a strict list of guidelines. They gave some flexibility to how standards were met, and how the businesses were certified.

It Takes a Team

Additionally, the accountability is spread out among any individuals at the C-level, not just a person in the CISO role.  Taking it one step further, the CISO title wasn’t required, but the responsibility of the role was there.  It was dependent on the size and nature of the institution, but it should be noted that there had to be a person identified to oversee and enforce the policies.  This person also had to report to the board.

Training was also put at the forefront, making sure that the regulations were known and understood.  They realized that internal employees were the highest risk factor to a breach, and ultimately the most preventable by creating awareness and enforcing education.  Additional training also has to be done for the cybersecurity personnel.  Vullo said that while the content is was different, it is also ongoing and critical.

SHIELDing Your Business

In July 2019 New York Governor Cuomo signed legislation that aims to put New Yorker’s private data in more protective and safer business environments.  The Stop Hacks and Improve Electronic Data Security, or SHIELD law, imposes strong obligations on businesses that handle private data to provide proper notification to the consumers who are affected by a security breach.  Additionally, credit reporting agencies must offer identity theft prevention and mitigation services to those who have been affected by a security breach of the agency’s system.

To meet the NYDFS regulations and to be prepared, we recommend that all companies acknowledge the risk factor and upgrade their security measures by aligning themselves with those put in place by a credible agency, like NYDFS.  Ideally, you would get ahead of the game as they did.

Do you have a plan to prevent, detect, and respond?  Prevention and detection are great first steps, but the likelihood of a breach or attack happening increases daily.  An incident response plan is a critical component – you need to know how you’ll respond and recover for your own safety and security, as well as for the survival of your own business.

Following the lead of this progressive thinking, organization is highly recommended.  Save time and money by being ahead of the hackers.

badge w light burst white (1)
Exclusively for Our MSP Partners

Now Available: Gen AI Certification From BSN

Lead Strategic AI Conversations with Confidence

Breach Secure Now’s Generative AI Certification helps MSPs simplify the AI conversation, enabling clients to unlock the value of gen AI for their business, build trust, and drive growth – positioning you as a leader in the AI space.

More on blogs

From Risk to Adoption: Why AI Success Starts with Leadership

AI adoption is accelerating across every industry, but many organizations still lack the training, governance, and leadership needed to use it effectively. Learn why AI

Breach Secure Now Brings Security Training Data into ScalePad Lifecycle Manager

Breach Secure Now’s integration with ScalePad Lifecycle Manager gives MSPs greater visibility into client security training data, phishing performance, and employee risk trends. By connecting

AI-Assisted Phishing Is Changing the Game, and Traditional Awareness Training Isn’t Enough

Generative AI is reshaping the phishing landscape, making attacks more polished, personalized, and difficult to detect. As AI-assisted phishing campaigns achieve dramatically higher click rates,
Take the First Step

Experience Training That Makes a Difference

during the demo you’ll:

Take the First Step

Experience Training That Makes a Difference

During the demo you’ll:
situs toto toto toto togel sesetoto toto desa wisata pujon kidul 13 situs toto toto slot toto slot toto slot toto slot toto slot akuntoto slot gacor slot gacor toto togel toto slot toto slot toto slot toto togel situs toto situs toto https://www.timexplywoodanddoors.com/clients/ situs toto toto slot toto slot toto togel toto slot slot hoki99 toto slot gacor slot gacor bwo303 bwo99 toto slot bwo99 toto slot situs togel toto slot toto slot toto situs togel slot online pewe4d MANCINGDUIT slot 4d bwo99 AMANAHTOTO AMANAHTOTO toto togel slot toto https://saint-mathieu.com/spcaroussillon/ slot 4d toto slot slot 4d toto slot toto slot togel slot situs indobet akuntoto slot toto slot 4d babeh188 situs toto toto slot agb99 PEWE4D PASCOL4D Toto https://www.teamajans.com/kurumsal/ toto toto slot toto slot 4d slot depo 10k situs toto situs toto toto togel situs toto toto slot toto togel toto slot toto slot toto toto situs toto toto slot 8kuda4d toto slot judi bola toto situs toto link slot situs toto situs toto situs toto toto toto slot situs toto slot toto toto togel situs toto eropa99 login logototo RTP toto slot leon188 situs toto toto slot 8kuda4d situs slot gacor slot situs toto situs toto situs toto situs toto situs toto lingkartoto ilmutoto panen100 mix parlay sumbartoto toto slot toto slot situs toto situs toto situs toto situs toto situs toto toto slot situs toto agen toto togel mawar800 situs toto situs toto titi4d titi4d mataramtoto rtp slot slot gacor slot gacor slot gacor toto slot gacor