Fifty-Three Regulators Raise Cyber Expectations With Multi-State Breach Settlement

A $20‑million settlement of charges that 53 state financial regulatory agencies brought against mortgage company Bayview Asset Management highlights enforcers’ consensus around board responsibilities and cybersecurity hygiene. The case arose from a data breach that impacted 5.8 million customers, and the consent order (Order), which addresses Bayview’s failure to cooperate, contains extensive corrective measures for it to implement. This article examines the novel requirements from the December 31, 2024, Order, discusses multi-state enforcement trends and offers key practical takeaways, with insights from experts at A&O Shearman, Clark Hill, Frankfurt Kurnit and Lowenstein Sandler. See “NYDFS Changes Its Cybersecurity Regulation Requirements Through Enforcement – Again” (Jul. 19, 2023).

To read the full article

Continue reading your article with a CSLR subscription.