CNA cyberattack

CNA Cyberattack: Insurance Company Hit By cyberattack

CNA Financial, a Chicago-based provider of cyber insurance, confirmed a cyberattack against its systems, which has some concerned that cybercriminals may target policyholders. If the investigation of the attack proves to include policyholder data, a cyber insurance industry expert warned, it could enable devastating further incidents that hackers could use as leverage in extortion attempts.…

data breach notification

Data breach notification laws: New York

Personal information in the United States is currently protected by a patchwork of industry-specific federal laws and state legislation whose scope and jurisdiction vary. The challenge of compliance for organizations that conduct business across all 50 states is therefore considerable. Even though many countries have laws that mandate data breach notification, data breach notifications are…

cyber insurance risk framework

NYDFS: Cyber Insurance Risk Framework

The New York State Department of Financial Services has released new guidance presenting some key practices for New York-regulated insurers that write cyber insurance. Background The 2020 Internet Crime Report issued by the FBI’s Internet Crime Complaint Center includes information from 791,790 complaints of suspected internet crime—an increase of a whopping 69.4% from 2019—and reported…

microsoft breach

Microsoft Breach and The NYDFS

Hackers are exploiting vulnerabilities in Exchange email servers to drop ransomware, Microsoft has warned, a move that puts tens of thousands of email servers at risk of destructive attacks. NYDFS Letter To Regulated Entities On March 9th The NYDFS released an industry letter to all regulated entities regarding the Microsoft Reports Exploitation of Four Vulnerabilities…

Cyber fraud DFS

DFS Cyber fraud alert

A few days ago, the Department of Financial Services (DFS) looked at an unusual pattern of interaction with multiple insurance websites and concluded that cybercriminals were exploiting data obtained from those website interactions to commit fraud. Website operators of all types should take note of the DFS’ warning and consider whether their websites may also…

NYDFS applies to New yorkers

What is the NYDFS Cybersecurity regulation? (23NYCRR 500) – 2021

What is NYDFS cybersecurity regulation? The New York Department of Financial Services (NYDFS) is the department that regulates certain covered entities and licensed persons in the financial services sector doing business in New York. This department has established a set of regulations called “The NYDFS cybersecurity regulation (23NYCRR 500) that demands some cybersecurity requirements on…