| 1 minute read

NYDFS Amendment to Cybersecurity Regulation

nys dfs seal

Avalon previously reported on proposed changes that may have a significant impact on the current 23 NYCRR Part 500 – Cybersecurity Requirements for Financial Services Companies (the Cybersecurity Regulation or Part 500) released by the New York State Department of Financial Services (NYSDFS). 

Part 500, a regulation establishing cybersecurity requirements for financial services companies, was declared by the Superintendent of Financial Services, and has been in place since March 2017.

Since adoption, the cybersecurity landscape has changed, and attacks have become more sophisticated and more expensive. There are many additional controls to help mitigate these threats that should be implemented by organizations to help protect themselves and, as such, on November 1, 2023, Part 500 was amended to help align with these changes and push for better security for financial services companies.

Please go to https://www.dfs.ny.gov/industry_guidance/cybersecurity for more information on the updates and related resources including available training sessions and implementation timelines for small businesses, Class A businesses, and covered entities.

Avalon can assist your organization with staying or becoming compliant through many of our services, including vCISO, vendor management, policy creation, and risk assessment.

Blog Articles

7 Common Missteps in Preserving Digital Evidence

Digital evidence is fragile. It changes, syncs, expires, gets overwritten, and often disappears before anyone realizes it matters. For law firms and corporate legal departments, the goal is not just to save data. The goal is to preserve the right data, in the right way, with the right documentation. That’s why our experts created this quick data preservation guide for legal teams, corporate counsel, and litigation support professionals.

What to Expect During a Relativity Server to RelativityOne Migration

In a recent blog, “Why Your Move from Relativity Server to RelativityOne Should Start Now," we discussed the need for organizations to move from Relativity Server to RelativityOne.

The Next Generation of AI in Law*

The legal industry is steadily moving beyond early experimentation with generative AI and into a more complex phase defined by agentic systems. These systems do not simply generate text or assist with discrete tasks. They are designed to take action, to carry out multi-step processes, and to operate with a level of autonomy that begins to resemble participation rather than assistance.