Cyber insurance built for a state that regulates security twice over — the SHIELD Act’s reasonable-safeguards duty on every business holding New Yorkers’ data, and NYDFS Part 500’s 72-hour incident reporting and MFA mandates for financial-services licensees — with an Attorney General who has turned breach settlements into a production line.
New York polices cybersecurity from two directions. The SHIELD Act imposes a reasonable-safeguards duty and breach-notification obligations on any business, anywhere, that holds a New York resident’s private information. And if you are licensed by the Department of Financial Services — banks, insurance agencies, mortgage brokers, money transmitters — 23 NYCRR Part 500 adds a prescriptive cybersecurity program with 72-hour incident reporting, amended in November 2023 and fully phased in by November 2025. The $11.3 million GEICO/Travelers settlement shows what happens when both regimes hit at once. Here is what that means for your cyber policy.
New York’s baseline is the Stop Hacks and Improve Electronic Data Security (SHIELD) Act, codified at General Business Law §899-aa and §899-bb. It does two things. First, §899-bb requires any person or business holding a New York resident’s private information — regardless of where the business sits — to develop, implement, and maintain reasonable administrative, technical, and physical safeguards, with the statute itself listing what those look like: a designated security coordinator, risk assessments, employee training, vetted vendors under contract, and tested controls. Second, §899-aa requires notice of a breach to affected residents without unreasonable delay, notice to the Attorney General, the Department of State, and the State Police — and to the consumer reporting agencies when more than 5,000 New Yorkers are affected.
There is no private right of action under the SHIELD Act — enforcement belongs to the Attorney General, who can seek up to $5,000 per violation for safeguards failures and up to $20 per failed notification, capped at $250,000, for notice violations. And this Attorney General uses it: New York has extracted a steady stream of breach settlements from national retailers, healthcare companies, and accounting firms, frequently pairing the penalty with a mandated multi-year security program. For a cyber policy, that means the New York tail of any breach includes a near-automatic AG inquiry — a regulatory-defense exposure even when no lawsuit ever gets filed.
If you hold a license from the New York Department of Financial Services — and that includes independent insurance agents and brokers, not just banks — 23 NYCRR Part 500 applies, and its November 1, 2023 amendment sharpened every edge:
A New York cyber program has to assume that any serious incident produces parallel regulatory proceedings, so regulatory-defense coverage that responds to both an AG investigation and a DFS enforcement action — with penalties covered where insurable — is the first thing we check, not the last. For DFS licensees, Part 500 also changes the underwriting itself: applications now effectively mirror the regulation’s control set, and a misstatement about MFA or encryption on an application is the classic path to a denied claim, so we make sure what you attest matches what you run. First-party breach-response coverage should be built around the 72-hour and 24-hour clocks — panel breach counsel and forensics who file DFS notices routinely — and because SHIELD Act exposure follows New Yorkers’ data everywhere, out-of-state businesses selling into New York need this structure too, not just Manhattan firms.
Tell us about your operation and your loss history — we’ll confirm we can write New York and structure the limits to match.