| 1 minute read

NYDFS Amendment to Cybersecurity Regulation

nys dfs seal

Avalon previously reported on proposed changes that may have a significant impact on the current 23 NYCRR Part 500 – Cybersecurity Requirements for Financial Services Companies (the Cybersecurity Regulation or Part 500) released by the New York State Department of Financial Services (NYSDFS). 

Part 500, a regulation establishing cybersecurity requirements for financial services companies, was declared by the Superintendent of Financial Services, and has been in place since March 2017.

Since adoption, the cybersecurity landscape has changed, and attacks have become more sophisticated and more expensive. There are many additional controls to help mitigate these threats that should be implemented by organizations to help protect themselves and, as such, on November 1, 2023, Part 500 was amended to help align with these changes and push for better security for financial services companies.

Please go to https://www.dfs.ny.gov/industry_guidance/cybersecurity for more information on the updates and related resources including available training sessions and implementation timelines for small businesses, Class A businesses, and covered entities.

Avalon can assist your organization with staying or becoming compliant through many of our services, including vCISO, vendor management, policy creation, and risk assessment.

Blog Articles

Why Your Move from Relativity Server to RelativityOne Should Start Now

The clock is ticking on Relativity Server, and legal teams that delay their cloud transition risk operational disruption and missed opportunities for AI-powered efficiency gains. Relativity, the dominant platform in the industry, has drawn a clear line in the sand: beginning January 1, 2028, all new matters must be hosted in RelativityOne, the company's cloud-based platform. While existing Server matters created before December 31, 2027, will continue to be supported, the message is unmistakable. The future of eDiscovery lives in the cloud.

What Happens When We’re TOO Anxious to Rule on AI Issues?

As courts start to confront how generative AI fits into privilege and workproduct doctrine, early decisions are already pointing in different directions. United States v. Heppner is often cited as a warning signal, but it should not be read as establishing a general rule about AI and privilege. The legal community is chomping at the bit for AI-related case law, but we need to proceed carefully.

Employee Spotlight: Donald Watkins

 Every once in a while, we like to show off one of our hard-working, detail-oriented problem solvers. Take a moment to see who's in the spotlight today!