Category
Advisory-services

September 23, 2024

New York Department of Financial Services (NYDFS) Amendments Effective November 2024

As covered in our previous article, the New York Department of Financial Services (NYDFS) updated its Cybersecurity Regulation in 2023. To help entities roll out the changes and new requirements, they have provided phased timelines for when these items must be implemented by.
September 4, 2024

Risks Lurking in the “Shadows”: Shadow IT and Shadow AI

You may have heard the saying: “Change is the only constant in life.” This is certainly true of the information technology industry, which in turn, has a ripple effect on the technology, services, risk, and regulatory requirements that impact your organization and its environment.
June 27, 2024

The CDK Incident and Recommended Actions from Avalon Cyber

Thousands of car dealerships’ operations slowed to a halt last Wednesday as their core dealer management system, CDK, shut down. CDK Global announced that they were investigating a cyber incident and “Out of an abundance of caution and concern for our customers, we have shut down most of our systems and are working diligently to get everything up and running as quickly as possible” according to...
April 12, 2023

Governance Considerations in the Age of AI

There has been a lot of talk recently about artificial intelligence (AI), especially around ChatGPT, a chatbot which interacts in a conversational way. As a broad category, AI is the simulation of human processes by machines and computer systems. A few business use cases may include leveraging AI to provide fast and accurate response for customer inquiries, assisting with topic research, or...
January 24, 2023

Be Cyber Ready by Implementing These Key Controls

As the number and severity of cyber threats and attacks continues to rise, it’s more important than ever to make sure your organization is cyber ready. Safeguarding your environment, including the systems and data within, will both reduce risk and promote business operation continuity and security.
October 5, 2022

Introducing Our Cybersecurity Service Plans

Developing – and maturing – a layered, effective cybersecurity program for your organization can be confusing, time-consuming, and stressful. But it doesn’t have to be.
August 3, 2022

Proposed Changes to NYDFS Cybersecurity Requirements

On July 29, 2022, the New York State Department of Financial Services (NYSDFS) released proposed changes that may have a significant impact on the current 23 NYCRR Part 500 – Cybersecurity Requirements for Financial Services Companies (the Cybersecurity Regulation or Part 500). Part 500, a regulation establishing cybersecurity requirements for financial services companies, was declared by the...
April 11, 2022

Cybersecurity Spring Cleaning

The weather is changing, and spring is upon us. Each year around this time, many people tend to do a thorough cleaning of their home and maybe tackle a few home improvement projects before summer arrives. We cannot forget to do the same maintenance and enhancements to our cybersecurity program. To assist you, we created this basic cybersecurity “to-do” list to ensure that you are being proactive...
April 6, 2022

Get Ready for the New 36-Hour Cyber Breach Notification Rule for Financial Institutions

If you’re in the financial sector, no doubt you’ve already heard, and hopefully, are prepared or preparing for, the new federal banking rule regarding cyber breach notifications. This new rule, which took effect April 1, 2022, with full compliance required by May 1, 2022, requires banking organizations and bank service providers to notify banking regulators within 36 hours after a notification...
February 16, 2022

Avalon Cyber Welcomes Jill Martucci

The Avalon Cyber team is proud to welcome Jill Martucci as our new Director of Governance Risk and Compliance (GRC) for our security advisory services. Her experience spans many service lines and industries in which she executes programs that ensure the proper functioning of client information technology and information security (IT/IS) controls, with a focus on the following areas:

Contact Our Team Now