Cybersecurity Compliance Emphasized at MBA's Legal Issues and Regulatory Compliance Conference
Privacy, Cyber & AI Decoded Alert | 2 min read
Jun 3, 2021
With cybersecurity legislation and regulation sweeping the country in response to a series of high-profile hacking and ransomware attacks, it was little surprise that cybersecurity was a topic at the recently concluded Mortgage Bankers Association's Conference on Legal Issues and Regulatory Compliance. A major takeaway at the conference was that lenders and servicers with consumer-facing platforms that collect personal information should review their cybersecurity policies immediately. Simply waiting for an agency inquiry, investigation, or a breach could result in dire financial and reputational consequences.
To illustrate this point, one speaker at the conference noted the enforcement action commenced by the New York State Department of Financial Services (DFS) in July of 2020 against a leading title insurance company, alleging violations of DFS's Cybersecurity Regulation 23 NYCRR 500 (Regulation 500). Among other things, Regulation 500 requires that most financial institutions and other regulated businesses operating in New York have a robust written cybersecurity program informed by periodic risk assessments. The program should also include a plan to respond to and recover from cybersecurity incidents and trained cybersecurity personnel. Covered entities are further required to submit a certificate of compliance to DFS. Failure to adhere to the mandates of Regulation 500 subjects violators to penalties of $1,000 per incident.
DFS alleged that the insurer failed to follow its own cybersecurity policy after a vulnerability in its system exposed millions of files containing consumers' personal information, including bank account and social security numbers. DFS further alleged that the insurer misclassified the vulnerability as "low" in severity; failed to conduct a reasonable investigation into the scope and cause of the exposure; failed to utilize cybersecurity personnel; and falsely certified its compliance with Regulation 500. A hearing is scheduled for August of this year.
All businesses that collect the personal data of consumers should take heed of this enforcement action and adopt the following best practices:
- Follow written cybersecurity programs;
- Conduct regular risk assessments to detect vulnerabilities and update cybersecurity programs accordingly;
- Do not underestimate the level of risk associated with a vulnerability;
- Train and utilize cybersecurity personnel; and
- Adhere to representations concerning cybersecurity programs.
If you are unsure if your organization is in compliance with cybersecurity laws like Regulation 500, you should contact a trained legal professional for an assessment as soon as possible. Other than DFS and the Federal Trade Commission, agencies such as the Consumer Financial Protection Bureau and the Securities & Exchange Commission have shown an increased appetite for regulating and enforcing digital practices and risks. Now is the time to ensure that your organization is in compliance.
Related People
Related Capabilities
Featured Insights

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies

In The News
Jul 29, 2026
Hinshaw Authors Contribute Two Articles in Latest Edition of the CCFL Quarterly Report

Webinar
Jul 28, 2026
Cathy Mulrow-Peattie and Sabrina Janeiro Present on Legal AI Technology

In The News
Jul 27, 2026
Scott Seaman Discusses How the Insurance Industry Contributed to the 2026 FIFA World Cup

Privacy, Cyber & AI Decoded Alert
Jul 27, 2026
Compliance Guidance for the New Vermont Data Privacy and Online Surveillance Act (VDPOSA)

Healthcare Alert
Jul 24, 2026
Q&A: Right to Electronic Monitoring Extended to Illinois Assisted and Shared Living Facilities

Press Release
Jul 23, 2026
Insurance Partner Christophe Burusco Joins Hinshaw in Los Angeles

In The News
Jul 16, 2026
Jennifer Driscoll Anticipates Epic Battle Between “Titans of the Antitrust Bar”

Press Release
Jul 15, 2026
Two Hinshaw Partners Recognized in Minnesota Monthly's 2026 Top Lawyers in Minnesota


