Investor Presentaiton
QUESTION:
Requirement
Cyber Security Event
Reporting
Definition of Cyber
security event
Investigation of a
Cyber Security Event
Why does the Department plan to recognize an exemption
for licensees who certify they are compliant with the New
York Cybersecurity Regulation?
SC Insurance Data Security New York Cybersecurity Regulation
Act
Notice must be provided within
72 hours from determination
that a cybersecurity event has
occurred; 13 categories of
information must be included
in the notice
Cyber security event does not
include unauthorized
acquisition of encrypted
information
Licensee has an affirmative
obligation to conduct a prompt
investigation under the Act.
Records must be maintained
for five years and produced
upon demand of the Director or
his designee.
Notice must be provided within 72 hours
of the determination that a cybersecurity
event has occurred; but no detail as to
information to be included in the notice to
the Director.
The New York regulation does not include
the SC Act's language
No specific requirements regarding the
prompt investigation of a cybersecurity
event.View entire presentation