New York's product-security and cyber-resilience posture rests on one enacted state statute, the Stop Hacks and Improve Electronic Data Security (SHIELD) Act's data security program duty, General Business Law 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), signed July 25, 2019 and effective March 21, 2020), which requires any person or business that owns or licenses computerized data including the private information of a New York resident to develop, implement, and maintain reasonable administrative, technical, and physical safeguards appropriate to the information it holds, satisfied either by being a compliant regulated entity already regulated under Gramm-Leach-Bliley Act Title V, Health Insurance Portability and Accountability Act (HIPAA)/HITECH, or 23 NYCRR Part 500, or by running a scaled data security program of the kind the section itself describes.
No enacted New York statute sets security requirements a connected device or software product must meet before or after it reaches the market: a bill closely modeled on California's connected-device statute, adding General Business Law 390-d, has been introduced in every legislative session since 2017-2018 (S9179; S3973 and A2229; S1926 and A561; most recently S7269 in the 2025-2026 session) and has never advanced past committee, so this is a researched absence rather than a gap in coverage.
Outside the financial sector New York has no general private-sector duty to report an exploited vulnerability or a security incident to an authority; Chapter 177 of the Laws of 2025 (General Municipal Law Article 19-C, Executive Law 711-c, and State Technology Law 103-f and 210) requires municipal corporations, public authorities, and state agencies, government bodies, not a private business, to report a cybersecurity incident to the Division of Homeland Security and Emergency Services within 72 hours and a ransomware payment within 24 hours, so it belongs with this jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.
The Department of Financial Services separately administers 23 NYCRR Part 500, first promulgated March 1, 2017 as the first cybersecurity regulation of its kind, binding a Covered Entity operating under a license, registration, charter, certificate, permit, or accreditation issued under the Banking Law, the Insurance Law, or the Financial Services Law, and requiring a risk-informed cybersecurity program with a designated Chief Information Security Officer; its Second Amendment, promulgated by Superintendent Adrienne A. Harris with a Notice of Adoption published November 1, 2023, added an enhanced-obligation Class A company tier for the largest covered entities, defined in part by at least $20,000,000 in gross annual revenue in each of the last two fiscal years and more than 2,000 employees averaged over the same period, and 899-bb itself names Part 500 compliance as one of the three routes to being a compliant regulated entity.
Because Part 500's bound party, a financial-services licensee, is a role the LexLint activity vocabulary cannot yet express, it is deferred rather than flagged on a guess (#6740): no instrument for it is filed here, and it is recorded in this summary so a reader knows it exists.
General Business Law 899-bb is enforced only by the Attorney General, who may bring an action for injunctive relief and a civil penalty of up to $5,000 per violation under General Business Law 350-d after a violation is deemed unlawful under General Business Law 349; the section creates no private right of action, and no published enforcement record specific to the safeguards duty, as against the SHIELD Act's breach-notice half, was located.
New York's breach-notification duty, General Business Law 899-aa, the other half of the SHIELD Act, is already this jurisdiction's privacy row rather than repeated here: it requires notice to an affected New York resident and, where over 500 residents are affected, to the Attorney General, and carries its own civil penalty of up to $20 per instance of failed notification capped at $250,000. Section 500.17 of Part 500 is recorded below as its own row.
It requires a Covered Entity to notify the Superintendent within 72 hours of determining that a cybersecurity incident occurred, to notify within 24 hours of making an extortion payment and to describe in writing within 30 days why the payment was made and what alternatives were considered, and to file either a certification of material compliance or a written acknowledgement of non-compliance by April 15 each year.
A cybersecurity incident is the narrower of the regulation's two defined terms, an event that also requires notice to a government or supervisory body, has a reasonable likelihood of materially harming a material part of normal operations, or results in the deployment of ransomware within a material part of the information systems. None of the exemptions in section 500.19 relieves a Covered Entity of that notice duty, so a limited-exemption entity owes it in full.
A third-party service provider is not bound directly and is reached only through the Covered Entity's own section 500.11 duty to impose notice and security terms on it by contract.