Who I Help · Small and Mid-Size Businesses

Fractional CISO leadership for small and mid-size businesses.

You do not have to be in New York for the SHIELD Act to apply to you. Holding computerized private information on a single New York resident is enough.

A dental practice in New Jersey. A SaaS startup in Austin. An Ohio e-commerce shop shipping to Brooklyn. All in scope, and most of them do not know it.

White Plains, NY
Based in Westchester, working with businesses across New York, the tri-state area and nationally.
Exhibit A · What the statute actually requires

Small businesses are scaled, not excused.

A small business under the Act is one with fewer than fifty employees, or under three million dollars in revenue, or under five million in assets. A small business is held to safeguards appropriate to its size and complexity. It is not exempt.

Enforcement

Attorney General only

The Attorney General is the sole enforcer. There is no private right of action, which means no class actions under this statute.

Notification

Thirty days

Notification of affected New York residents is required within thirty days of discovery.

Penalty

Notification failures

Up to the greater of $5,000 or $20 per failed notification, capped at $250,000.

Penalty

Security failures

Up to $5,000 per violation for failing to maintain reasonable safeguards.

The safe harbor, and its condition

Genuine, current compliance with HIPAA, GLBA or DFS Part 500 deems you compliant with the security requirement. Claiming HIPAA coverage while your Security Rule risk analysis is years out of date does not qualify you.

Exhibit B · Where the losses actually come from

Someone tricked into moving money, not a sophisticated intrusion.

Fifty-two percent of cyber claims begin with an email attack. Financial fraud accounts for thirty percent of claims, and eighty-two percent of that starts in email. One carrier puts business email compromise and funds transfer fraud together at fifty-eight percent of incidents.

For businesses under twenty-five million in revenue, claim severity rose twenty-six percent to roughly $180,000, ransomware frequency rose twenty-one percent and ransomware severity rose forty percent.

Why that is good news

It means the controls that change your insurability are unglamorous and largely affordable. Nobody needs to buy a security operations center to fix an email problem.

Exhibit C · The AI problem you already have

A governance failure, not an unsolved research problem.

43%
Had shadow AI

Forty-three percent of breached organizations had unsanctioned AI in their environment, at an average breach cost of $5.39 million.

68%
Had no AI governance

Sixty-eight percent had no AI governance at all. Not weak governance. None.

92%
Lacked basic access controls

Ninety-two percent of AI-related breaches occurred at organizations lacking basic access controls for their AI. It was not model failure.

Governance is not a brake on AI. It is what lets you step on the gas safely.

Exhibit D · Questions owners ask

Frequently asked questions

We are not in New York. Does the SHIELD Act apply to us?

If you hold computerized private information on even one New York resident, yes. The location of the business is not the test.

We are small. Are we exempt from the safeguards requirement?

No. Small businesses are held to safeguards appropriate to their size, complexity and the sensitivity of the information. Scaled, not excused.

We are already HIPAA compliant. Does that cover us?

It can, through the statute's safe harbor, but only if the compliance is genuine and current. A Security Rule risk analysis that is years out of date does not qualify.

Our staff use AI tools. Is that a problem?

It is a governance question rather than a prohibition. The issue is not that people use AI tools, it is that nobody has decided what data may go into them, under what terms, with what access controls, and with what record.

Large enterprises have budget. You have speed.

A 40-person company can change a process, revoke standing access, and encrypt a data store in a week. A large health system takes a year to do the same thing through committee.

Book a Free Security Clarity Session
Melissa Thornton, CISSP, C|CISO · Founder, Cybersecurity Advisory Group · White Plains, New YorkLast reviewed September 2026