Key Takeaways from FinCyber Femmes Meeting on Navigating AI and Cybersecurity Laws
Privacy, Cyber & AI Decoded Alert | 2 min read
Sep 30, 2025
Hinshaw partner Cathy Mulrow-Peattie recently participated in a panel discussion during the Q3 2025 FinCyber Femmes Meeting, hosted at IBM’s office in New York City. The FinCyber Femmes bring together leading professionals in cybersecurity, financial services, and technology to discuss the rapidly evolving landscape of artificial intelligence (AI) and its intersection with cybersecurity laws and regulations.
Cathy and her panel explored the latest trends, challenges, and best practices for organizations seeking to employ AI while managing their cyber risk and regulatory compliance.
Here’s a summary of key takeaways from this latest FinCyber Femmes panel:
- According to IBM’s Cost of Data Breach Report, 63 percent of organizations that experienced a data breach lacked AI governance. This absence of oversight not only increased the cost and impact of cybersecurity incidents but also emphasized the criticality of cybersecurity controls with AI.
- The panel discussed the growing sophistication of cyber threats, noting that one in six breaches involved attackers using AI tools (e.g., phishing, deepfakes), increasing the threat and attack landscape. The panelists discussed how most AI attacks were made through SAAS platforms and/or supply chain providers, highlighting the importance of maintaining strong cybersecurity for third-party applications.
- All panels at the conference emphasized that AI is here to stay and should be tested and used properly. AI can help us make more informed decisions, enhance efficiency, and provide better and more customized services only if it is built and used responsibly.
- The event discussions recommended that financial services organizations, and fintechs in particular, ensure they have AI and cybersecurity controls in place. The panel referred the audience to existing controls set out in the Department of Financial Services Cybersecurity Regulation Part 500 and AI Guidance, GLBA Safeguard Rules requirements, and existing OCC model risk management practices to mitigate cybersecurity AI risk.
- The speakers also stressed the importance of implementing AI on a use-case basis, guided by an established governance structure and an organization’s existing policies and procedures. This approach helps set expectations for employees and prevents the risk of “shadow AI,” the unauthorized or unmonitored use of AI tools within an organization.
- Lastly, the audience was also reminded of two upcoming New York State Department of Financial Services (NYSDFS) Part 500 requirements going into effect on November 1, 2025, for covered entities. These requirements include:
(1) Having Multifactor Authentication in place for remote access to systems and applications; and
(2) Implementing policies and procedures to develop and maintain documented assets and an accurate asset inventory of the covered entities' information systems. Information systems are broadly defined and cover any system that collects, processes, stores, uses, shares, or discloses electronic information.
Related People
Related Capabilities
Related Locations
Related Insights
Featured Insights

Press Release
Oct 22, 2025
Hinshaw & Culbertson LLP Launches New Website and Refreshed Brand

Press Release
Sep 26, 2025
Hinshaw Recognized as a “Leader in Litigation” in the BTI Consulting Litigation Outlook 2026 Survey

Privacy, Cyber & AI Decoded Alert
Sep 23, 2025
Fall 2025 Regulatory Roundup: Top U.S. Privacy and AI Developments for Businesses to Track

Press Release
Sep 15, 2025
Hinshaw Achieves 2024–2025 Mansfield Rule Certification Plus Status

In The News
Sep 5, 2025
Jessica Riley Reflects in a Law360 Story on Lessons She Learned as a Junior Lawyer

Press Release
Aug 25, 2025
Trial Spotlight: Hinshaw Prevails in ERISA Fiduciary Fraud Case

Press Release
Aug 21, 2025
102 Hinshaw Lawyers Recognized in 2026 Editions of The Best Lawyers in America® and Ones to Watch™





