Legal Cyber Academy

Continuing Education Information Sheet

Pioneer: New York DFS Cybersecurity Regulations

Back to course
Provider
Legal Cyber Academy · Lexeprint Inc.
13413 Granger Ave, Orlando, FL 32827
info@lawandforensics.com · https://www.lexeprint.com
Delivery method
On-demand, self-study (online, recorded)
Instructional time
1h 3m
Assessment
Graded multiple-choice exam · pass mark 70%
Administered online, unproctored, with identity verified only to the level of a confirmed email address. Each sitting draws 10questions at random from the course’s pool, is timed, and is fixed for that sitting; correct answers are never disclosed. The pass mark is provider-set and is not supported by published reliability statistics or a standard-setting panel.

Equivalent credit hours

1.0 on a 60-minute basis (most CLE / general CE) · 1.2 on a 50-minute basis (NASBA CPE). Rounded down to the nearest tenth of an hour; your board may round differently.

Learning objectives

  • Understand the NYDFS role and its cybersecurity regulation (23 NYCRR 500)
  • Identify the six regulatory minimum standards
  • Anticipate the proposed 2022 amendments and their impact
  • Advise financial institutions on NYDFS compliance

Audience & prerequisites

Intended audience: Attorneys advising financial institutions on data privacy and cybersecurity compliance.

Level: intermediate

Prerequisites: None

Faculty

  • Daniel B. Garrie, Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard

    Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare

    Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.

  • Justin Herring, Partner, Mayer Brown

    Mayer Brown

    Justin Herring is a partner at Mayer Brown, practicing in the firm's Cybersecurity & Data Privacy, Financial Services Regulatory & Enforcement, and Global Investigations & White Collar Defense groups. He advises on global incident response, regulatory enforcement and related litigation, including for crypto and fintech clients. He was Executive Deputy Superintendent of the Cybersecurity Division at the New York State Department of Financial Services, the first leader of that division, and previously spent nine years as an Assistant U.S. Attorney, serving as inaugural chief of the Cybercrimes Unit in the District of New Jersey. He holds a J.D. from the University of Chicago Law School. At Legal Cyber Academy he teaches on the New York DFS cybersecurity regulations, blockchain and cryptocurrency, and managing cybersecurity risk.

  • K Royal, Global Chief Privacy Officer and Deputy General Counsel, Crawford & Company

    Crawford & Company

    K Royal is Global Chief Privacy Officer and Deputy General Counsel at Crawford & Company, where she is tasked with developing and implementing the company's privacy policies, designed to protect both client and company data. She has more than 25 years of experience in the legal and health-related fields. She holds a J.D. from the Sandra Day O'Connor College of Law at Arizona State University and a Ph.D., and is certified as a Fellow of Information Privacy (FIP), in Privacy Management (CIPM) and in US and EU privacy law (CIPP/US, CIPP/E), plus Certified Data Privacy Solutions Engineer (CDPSE) through ISACA. She co-hosts the Serious Privacy podcast. At Legal Cyber Academy she teaches on the New York DFS cybersecurity regulations and the GDPR.

  • George Pierce, Special Counsel, Zeichner Ellman & Krause LLP

    Zeichner Ellman & Krause LLP

    George Pierce is Special Counsel to the litigation and cyber security practices at Zeichner Ellman & Krause LLP. He has substantial experience providing legal services related to complex litigation, corporate governance, labor and employment, bankruptcy, international trade, regulatory compliance and cyber security matters. He retired from Toyota Tsusho America in December 2022, where he was employed for 29 years, established the legal department as the company's first general counsel, and served as a director, senior vice president, chief legal officer, chief compliance officer and corporate secretary, sitting on the company's board for 22 years. He was earlier associated with Mudge Rose Guthrie Alexander and Ferdon for 12 years, where his work included complex litigation for Japanese and domestic corporations. He holds a J.D. from the University of Denver and is admitted in New York and in the Southern and Eastern Districts of New York. At Legal Cyber Academy, George Pierce teaches on the New York DFS cybersecurity regulations and cybersecurity practices organisations should adopt.

Timed agenda

#TopicMinutes
1Pioneer: New York DFS Cybersecurity Regulations63
Total instructional time63

Self-submission by credit type

Legal Cyber Academy is not an accredited provider; the notes below explain how a learner may self-submitthis activity where their board permits. The pathways shown reflect this course’s subject matter. Always confirm your board’s current rules.

  • Finance/securities subject matter — may support CPE where your state board accepts non-NASBA-registered activities.
  • CLE (attorneys)up to 1.0 hr (60-min basis)

    Many U.S. jurisdictions let an attorney apply for CLE credit for a non-accredited program (often called individual attorney or self-application). Use this certificate plus the course Information Sheet as your supporting documentation. Your state bar or CLE board decides whether credit is granted, how much, and any self-study cap.

  • CE / CPD (privacy, insurance, IT)up to 1.0 hr (60-min basis)

    Where your professional body recognizes self-reported or self-directed learning (CPD) — for example many privacy (CIPP/CIPM) and security certifications — record this activity using the certificate and Information Sheet. Confirm your program's self-reporting rules and any documentation it requires.

  • CPE (accountants)up to 1.2 hr (50-min basis)

    NASBA CPE uses a 50-minute credit hour and has strict self-study standards (registered sponsors, word-count-per-credit, and qualifying review questions). This course is NOT a NASBA-registered self-study program. Some state boards accept non-registered activities at their discretion — verify with your board before claiming CPE.

Legal Cyber Academy is not an accredited continuing-education provider, and its courses are not pre-approved for CLE, CE, CME, or CPE credit. Each course provides a graded assessment, a verifiable Certificate of Completion, and a Continuing Education Information Sheet documenting instructional time, learning objectives, faculty, and a timed agenda — the records most licensing bodies require when a learner applies for self-submitted or self-study credit. Whether credit is granted, and how much, is determined solely by your licensing board. Confirm your board's rules before claiming credit. Verify certificates at https://www.legalcyberacademy.com/certificate/ <code>.