Fractional CISO leadership for small and mid-size businesses.
You do not have to be in New York for the SHIELD Act to apply to you. Holding computerized private information on a single New York resident is enough.
A dental practice in New Jersey. A SaaS startup in Austin. An Ohio e-commerce shop shipping to Brooklyn. All in scope, and most of them do not know it.
Small businesses are scaled, not excused.
A small business under the Act is one with fewer than fifty employees, or under three million dollars in revenue, or under five million in assets. A small business is held to safeguards appropriate to its size and complexity. It is not exempt.
Attorney General only
The Attorney General is the sole enforcer. There is no private right of action, which means no class actions under this statute.
Thirty days
Notification of affected New York residents is required within thirty days of discovery.
Notification failures
Up to the greater of $5,000 or $20 per failed notification, capped at $250,000.
Security failures
Up to $5,000 per violation for failing to maintain reasonable safeguards.
Genuine, current compliance with HIPAA, GLBA or DFS Part 500 deems you compliant with the security requirement. Claiming HIPAA coverage while your Security Rule risk analysis is years out of date does not qualify you.
Someone tricked into moving money, not a sophisticated intrusion.
Fifty-two percent of cyber claims begin with an email attack. Financial fraud accounts for thirty percent of claims, and eighty-two percent of that starts in email. One carrier puts business email compromise and funds transfer fraud together at fifty-eight percent of incidents.
For businesses under twenty-five million in revenue, claim severity rose twenty-six percent to roughly $180,000, ransomware frequency rose twenty-one percent and ransomware severity rose forty percent.
It means the controls that change your insurability are unglamorous and largely affordable. Nobody needs to buy a security operations center to fix an email problem.
A governance failure, not an unsolved research problem.
Forty-three percent of breached organizations had unsanctioned AI in their environment, at an average breach cost of $5.39 million.
Sixty-eight percent had no AI governance at all. Not weak governance. None.
Ninety-two percent of AI-related breaches occurred at organizations lacking basic access controls for their AI. It was not model failure.
Governance is not a brake on AI. It is what lets you step on the gas safely.
Frequently asked questions
We are not in New York. Does the SHIELD Act apply to us?
If you hold computerized private information on even one New York resident, yes. The location of the business is not the test.
We are small. Are we exempt from the safeguards requirement?
No. Small businesses are held to safeguards appropriate to their size, complexity and the sensitivity of the information. Scaled, not excused.
We are already HIPAA compliant. Does that cover us?
It can, through the statute's safe harbor, but only if the compliance is genuine and current. A Security Rule risk analysis that is years out of date does not qualify.
Our staff use AI tools. Is that a problem?
It is a governance question rather than a prohibition. The issue is not that people use AI tools, it is that nobody has decided what data may go into them, under what terms, with what access controls, and with what record.
Large enterprises have budget. You have speed.
A 40-person company can change a process, revoke standing access, and encrypt a data store in a week. A large health system takes a year to do the same thing through committee.
