State Requirements Translated Into Proof

STATE CYBER & BREACH REQUIREMENTS / NEW YORK

New York Cybersecurity & Breach Notification Requirements

If you store or process personal information for New York residents, these notice rules can apply even outside regulated industries.

Not legal advice. Use this to scope work and keep records, then confirm specifics with counsel.

New York

What applies and what to keep ready

Breach Notification

Applies to
If you store or process personal information for New York residents, these notice rules can apply even outside regulated industries.
Trigger
A reportable breach trigger varies by state and may be based on unauthorized access, unauthorized acquisition, or other misuse-based standards. Use the jurisdiction-specific law for the exact trigger.
Covered Data
Covered data is state-specific and can include name plus Social Security number, driver’s license/state ID number, financial account or payment credential data, medical/health information, health-insurance information, biometric data, tax information, login credentials, and other categories specified by the state law. Use the jurisdiction-specific rule to determine coverage.
Consumer Notice
30 days
New York requires businesses and persons to notify affected individuals in the most expedient time possible, with a maximum deadline of 30 days after breach discovery.
Third-Party to Owner/Licensee
30 days
New York requires processors to notify data owners/licensees "immediately" following discovery, but with an outer limit of 30 days following discovery.
AG / State Agency
Yes
New York requires notification to the Attorney General, Department of State, Division of State Police, and (for covered financial entities) Department of Financial Services for any breach affecting New York residents, including timing, content, distribution, approximate number affected, and a copy of the notice template.
Response priorities to review live

Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.

  • Preserve logs and evidence (do not "clean up" yet)
  • Open an incident ticket and assign an owner
  • Start the decision log and incident timeline
  • Notify counsel and your cyber insurer

Key Obligations

Written Program
Risk Assessment
MFA and Encryption
Vendor Oversight
Incident Response

Who You Notify

Primary
  • Affected New York residents - if covered personal information was accessed, acquired, or otherwise triggers the jurisdiction-specific notice rule
Conditional
  • State regulator / Attorney General - when the jurisdiction-specific recipient, threshold, and entity-type rule applies
  • Consumer reporting agencies - if required for large-scale incidents
Coordination
  • Law enforcement - coordinate if an investigative delay is requested

What to Keep Ready

Prepare Now
  • Incident Response Plan - roles, escalation, outside counsel and insurer contacts
  • Incident Contact Matrix - IT/MSP, insurer, key vendors, regulator/AG contacts
  • Notice Templates - resident and regulator notice drafts reviewed with counsel
  • Baseline Control Evidence - MFA, access reviews, backup/restore testing, vendor oversight
During an Incident
  • Notification Decision Log - why notice is or is not required, who approved, and when
  • Incident Timeline - key events, containment steps, and decision points
  • Delivery & Submission Records - notices sent, confirmations, and regulator submissions

Review-Ready Evidence

Incident RecordDecision log, timeline, approval trail
Control EvidenceMFA config, backup test proof, access attestations
Notification RecordsNotices sent, delivery confirmations, regulator receipts

NYDFS Cybersecurity Regulation NYDFS

Applies to
Current filing scope: Covered entity.
Classification
NYDFS Cybersecurity Regulation
Authority
23 NYCRR Part 500
Regulator Notice
72 hours
New York DFS. Threshold: Cybersecurity event that has a reasonable likelihood of materially harming normal operations. Notify the Superintendent of Financial Services within 72 hours of determining a cybersecurity event has occurred that requires notification.
Response priorities to review live

Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.

  • Preserve logs and evidence (do not "clean up" yet)
  • Open an incident ticket and assign an owner
  • Start the decision log and incident timeline
  • Notify counsel and your cyber insurer

Key Obligations

Written Program
Risk Assessment
Vendor Oversight
Incident Response
Board Reporting

Annual Requirements and Filings

Certification Due
Apr 15
Who files: Covered entity. Submit annual certification to the Superintendent of Financial Services confirming compliance with 23 NYCRR Part 500.
Board Report
Annual
Who files: CISO / Covered entity. CISO must report in writing at least annually to the board on the cybersecurity program and material risks.
Pen Test
Annual
Who files: Covered entity. Conduct annual penetration testing of information systems.
Risk Review
Annual
Who files: Covered entity. Conduct periodic risk assessment to inform the cybersecurity program design.

What to Keep Ready

Prepare Now
  • Written Information Security Program - approved, dated, with a documented review cadence
  • Risk Assessment - current, with remediation tracking
  • Vendor Inventory - due diligence, contract clauses
  • Baseline Control Evidence - MFA, access reviews, backup/restore testing
During an Incident
  • Notification Decision Log - why notice is/isn't required, who approved, when
  • Incident Timeline - key events, containment steps, decision points
  • Tabletop Records - IR plan execution evidence

Review-Ready Evidence

Program RecordWISP, risk assessment, vendor records, incident-response evidence
Leadership UpdateSecurity status, risk posture, compliance attestations
Certification SupportSigned certifications and supporting evidence

Federal Overlays

Applies to
Applicability depends on whether the entity is a covered financial institution under FTC jurisdiction. Common examples can include tax return preparers, tax professional firms, accounting firms, and some financial advisors.
Authority
FTC Safeguards Rule (16 CFR 314) under the Gramm-Leach-Bliley Act.
FTC Notification
At least 500 consumers / 30 days outer limit
For a notification event involving at least 500 consumers' unencrypted customer information, covered institutions must notify the FTC as soon as possible and no later than 30 days after discovery.
IRS Stakeholder Liaison
Immediately / as soon as possible
IRS guidance says tax professionals should report client data theft immediately / as soon as possible to the local IRS stakeholder liaison.
Response priorities to review live

Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.

  • Preserve logs and evidence (do not "clean up" yet)
  • Open an incident ticket and assign an owner
  • Start the decision log and incident timeline
  • Notify counsel and your cyber insurer

Key Obligations

Written Program
Risk Assessment
MFA and Encryption
Vendor Oversight
Incident Response

What to Keep Ready

Prepare Now
  • Tax-Focused WISP - written security plan for taxpayer data, access controls, and encryption approach
  • MFA Evidence - email, portal, admin accounts configuration
  • Encryption Documentation - secure storage approach for SSNs and return data
  • Vendor Inventory - tax software, DMS, e-sign, portal, payroll providers
During an Incident
  • Notification Decision Log - why notice is/isn't required, who approved, when
  • Incident Timeline - key events, containment steps, decision points
  • Submission Records - FTC notification, IRS liaison report (if applicable)

Review-Ready Evidence

Written ProgramSigned, dated, with current security controls
Control EvidenceMFA/encryption config, access review attestations
Vendor OversightInventory, due diligence, contract clauses
Incident RecordTimeline, notification records, FTC/IRS receipts

Program Review

Compare New York to Other States

Operate in more than one state? Use the interactive hub to compare requirements side by side, or book a short program review to map deadlines, reviewer expectations, and next actions with us.