This page focuses on proactive cybersecurity compliance counseling for New York businesses, building defensible security programs, meeting SHIELD Act "reasonable safeguards" obligations, and satisfying the New York Department of Financial Services (NYDFS) Cybersecurity Regulation (23 NYCRR Part 500). If your organization is already in the middle of an incident, or facing litigation, see our related pages on data breach response and notification, claims arising from a cybersecurity failure, and disputes over lost or exposed information. This page is our compliance hub; those pages address enforcement and litigation intent.
Who Must Comply in New York: and Which Rule Applies
The two frameworks that most often govern a New York City business overlap but are not identical, and confusing them is a common and costly error.
- The SHIELD Act (N.Y. Gen. Bus. Law § 899-bb, effective March 2020) reaches any business (anywhere in the world) that owns or licenses computerized "private information" of a New York resident. It is jurisdiction-agnostic and applies to the vast majority of NYC employers, retailers, professional service firms, and nonprofits.
- NYDFS Part 500 applies only to "Covered Entities" operating under a license, charter, or registration issued under New York's Banking, Insurance, or Financial Services Laws, banks, insurers, mortgage servicers, licensed lenders, and many fintech firms concentrated in Manhattan's financial district.
A NYC-based bank or insurer is typically subject to both. A Brooklyn e-commerce company is usually subject to the SHIELD Act only. Getting this threshold analysis right determines your entire compliance obligation.
The SHIELD Act's "Reasonable Safeguards" Standard
Section 899-bb does not prescribe specific technologies. Instead it requires "reasonable" administrative, technical, and physical safeguards. In practice, we counsel clients to document each of the statutorily enumerated elements so the program is defensible if the New York Attorney General inquires:
- Administrative: designating one or more employees to coordinate the security program, identifying reasonably foreseeable internal and external risks, and training workforce members.
- Technical: assessing risks in network and software design, information processing, and detection/response capabilities.
- Physical: controls on collection, storage, and secure disposal of private information.
Small businesses (fewer than 50 employees, under $3 million in gross revenue, or less than $250,000 in year-end total assets) may scale safeguards to their size, a nuance we frequently apply for early-stage NYC startups. Enforcement is by the Attorney General under Gen. Bus. Law § 899-bb(4); there is no private right of action for the security-program requirement, and civil penalties for knowing or reckless breach-notification violations can reach up to $250,000. The SHIELD Act notably expanded the definition of a "breach" to include unauthorized access, not merely acquisition, a change that catches many out-of-state counsel by surprise.
NYDFS Part 500: Including the 2023 Amendment Deadlines
The Second Amendment to 23 NYCRR Part 500 became effective November 1, 2023, and phases in obligations on a staggered schedule that covered entities must calendar carefully:
- December 1, 2023: the 72-hour cybersecurity-event notice to the Superintendent and the new 24-hour reporting requirement following an extortion/ransom payment, plus a written explanation within 30 days of any such payment (§ 500.17).
- April 15, 2024: the revised annual certification (now signed by the highest-ranking executive and the CISO) or a written acknowledgment of non-compliance with a remediation plan.
- November 1, 2024: enhanced governance (CISO reporting to the senior governing body), MFA expansion, and encryption obligations.
- November 1, 2025: asset inventory and access-privilege review requirements.
The amendment also created a new "Class A Company" tier (large entities by revenue/employee thresholds) with heightened independent-audit and endpoint-monitoring duties. Note the frequently-misread CISO reporting nuance: the CISO must report in writing to the senior governing body at least annually, and that report must now address material cybersecurity issues, plans for remediation, and the CISO's ability to have timely notified the board of material events. We help covered entities right-size their exemptions under § 500.19 (limited exemptions for small entities) rather than assuming full applicability.
Overlapping Federal Obligations for NYC Industries
New York City's concentration of regulated industries means a single organization often layers state and federal duties:
- Healthcare and health-tech (Manhattan hospital systems, digital-health startups): HIPAA's Security Rule (45 C.F.R. Part 164) coexists with the SHIELD Act. HIPAA-covered entities are deemed compliant with the SHIELD Act's data-security requirements, but breach-notification analysis still requires a separate SHIELD assessment. We map where HIPAA's Breach Notification Rule and New York's timeline diverge.
- Financial services (Wall Street banks, broker-dealers, insurers): the Gramm-Leach-Bliley Act Safeguards Rule and SEC cybersecurity disclosure rules run alongside NYDFS Part 500. A GLBA-compliant program can satisfy the SHIELD Act's security element but does not eliminate Part 500's independent obligations.
- Consumer-facing businesses: may also face California and other state statutes when serving a national customer base, requiring a harmonized policy rather than a New York-only approach.
How We Counsel New York Businesses (Compliance Scope)
This practice is deliberately scoped to preventive and compliance work. Typical engagements include:
- SHIELD Act and Part 500 gap assessments, with a written applicability memo documenting which rules apply and why.
- Drafting written information security programs, incident response plans, and the governance documentation regulators expect to see.
- Vendor and third-party risk contracting, data processing addenda and security terms aligned to § 500.11 and SHIELD vendor-oversight expectations.
- Preparing the annual NYDFS certification and supporting the CISO's board reporting obligations.
- Tabletop exercises to rehearse the 72-hour and 24-hour reporting decisions before a live event.
- Cyber-insurance policy review coordinated with the compliance posture.
When an actual breach, extortion event, or regulatory enforcement action arises, we transition the matter to our breach-response and litigation teams (see the linked pages above) so the counseling relationship and the response engagement remain clearly delineated.
Regulatory Enforcement Context
The New York Attorney General has repeatedly used the SHIELD Act and related consumer-protection authority to resolve investigations of businesses that failed to maintain reasonable safeguards, frequently through settlements requiring specific security improvements and monetary penalties. NYDFS has likewise brought and settled Part 500 enforcement matters, with consent orders emphasizing MFA failures and deficient risk assessments. We use these public enforcement patterns, not to predict outcomes for any client, but to prioritize the controls regulators actually scrutinize.
About Our Attorneys
Our firm is led by Albert Goodwin, Esq., admitted to the New York State Bar. Mr. Goodwin advises New York businesses on regulatory compliance and commercial matters. Attorney biographies and bar admission details are available on our firm profile. We do not publish client names or guarantee results; every engagement begins with a confidential assessment of your specific facts and regulatory footprint.