Aboutwhy sjkplawyerspracticesInsightsCase StudyNewsLocations
Administrative

Cyber Compliance

A bank customer sends a security questionnaire, an insurer asks about multi-factor authentication before renewing a policy, or a regulator expects a compliance filing signed by senior leadership.

Reviewed

01 GUIDE

Cyber Compliance: what usually happens

Where cybersecurity duties come from

Cyber compliance obligations arrive from several directions at once. In New York, the Department of Financial Services has a detailed cybersecurity regulation for the banks, insurers, and other companies it licenses, and the SHIELD Act requires businesses holding New York residents' private information to maintain reasonable safeguards. Public companies face SEC disclosure rules on material cybersecurity incidents and risk management, defense contractors face federal contract requirements, and health care organizations answer to HIPAA's security standards. Customer contracts and cyber insurance policies frequently add conditions of their own, and those can be the most demanding of all.

Evidence that a program exists

Regulators and insurers tend to ask for proof, not policies. Keep a current risk assessment, an asset inventory, records of access reviews and multi-factor authentication coverage, vendor security reviews, and an incident response plan that has actually been tested. Document who approved security decisions and how management and the board were briefed. Make sure certifications and questionnaire answers match reality, because a statement that overstates controls can create liability of its own, separate from any breach. If a gap is known, record the plan for closing it and who owns that plan.

Prioritizing a review

Our first task is identifying which regimes actually apply to your business and which contractual promises you have already made. We then look at the controls most often tested after an incident, such as access management, backups, and logging, and at whether your incident response plan accounts for regulatory notice deadlines, some of which are measured in hours or days. Where a security assessment is needed, we discuss having counsel engage the assessor so that legal advice and technical findings are organized with privilege in mind, though whether privilege holds depends on how the work is structured and used. If an incident is already under way, the priorities shift to containment, preservation, and notice decisions, and the broader review waits.

02 ATTORNEYS

Who you would be working with

Attorneys at our New York and Washington, D.C. offices handle matters like this one.

03 CASE RESULTS

Matters we have handled

Prior results do not guarantee a similar outcome.

05 HOW WE WORK

Client-centered service across jurisdictions

Global Coordination & Expertise

We deliver coordinated and effective legal services to our clients, utilizing our extensive legal resources and experienced attorneys in our well-integrated global network. Through our Washington D.C. and New York offices, together with our alliance

Multilingual & Cross-Border Communication

Our attorneys are experienced in both domestic and international matters and, with fluency in various languages, provide clear and consistent communication at every stage of your legal process.

Client-Centered Approach

Client service lies at the heart of our operations. From the initial consultation, we prioritize understanding your situation, listening to your goals, and providing regular updates and strategies tailored to your individual case.

Multidisciplinary & Efficient Solutions

Our multidisciplinary approach and established processes enable us to address cross-border challenges with efficiency.

06 OFFICES

Where we meet clients

Consultations are available in person or remotely.

New York

285 Fulton Street, New York, NY 10007
(855) 529-7557

Washington, D.C.

Suite 985, 1717 K Street NW, Washington, DC 20006
(855) 529-7557

Los Angeles

1901 Avenue of the Stars, Suite 820, Los Angeles, CA 90067
(424) 561-7557

Attorney Advertising. This page is general information about cyber compliance and is not legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on the facts of each matter, and prior results do not guarantee a similar outcome. Laws differ by state and change over time.