State Cybersecurity Laws: Steps to Address Regulators’ Priorities
State regulators are asking more questions after cybersecurity incidents, and data protection professionals should assume that a breach notice will start a longer dialogue with state regulators. Breach reports remain the central trigger for investigations, but the increase in comprehensive privacy laws and growth of AI-related concerns have spurred more prolonged enforcement conversations.
“We’ve seen a pretty significant uptick in regulatory inquiries from state regulators,” Paul Hastings partner Michelle Reed told the Cybersecurity and AI Law Report. Beyond the AGs, state insurance and other sectoral regulators police and probe the increasing number of cyber incidents. “New York Department of Financial Services inquires on almost all the breaches that companies report to them,” Debevoise partner Erez Liebermann noted.
Regulators are probing deeper, beyond their baseline questions. They ask about data retention and minimization measures, access controls, procedures for logging and patching, and risk-based resilience planning. “One huge area that is abundantly being hit right now in breaches, and will be questioned going forward, is vendor management,” Matthew Van Hise, a BakerHostetler partner and, until 2025, the Illinois assistant AG who led privacy and data security investigations, told the Cybersecurity and AI Law Report.
This second article in a three-part series on state cybersecurity law and enforcement, written in conjunction with IAPP’s Cybersecurity Law Center, provides practical recommendations for enterprises responding to initial questions from state enforcers. With insights from Liebermann, Reed and Van Hise, as well as experts from Morrison & Foerster, Ropes & Gray, and Shook, Hardy & Bacon, it also provides steps to address more intense scrutiny of vendor management and two other hot issues that pose complicated, companywide challenges requiring attention far beyond cyber teams.
Part one examined the state law toolkit for regulators and examined key enforcement actions. The final installment will cover important steps for showing reasonable security and resilience planning, and will discuss the first impacts of AI on state cybersecurity enforcement.
See “Practical Compliance Implications From NYDFS’ Healthplex Settlement” (Sep. 17, 2025).
Build Readiness for Initial Regulator Focus on Incident Handling
AGs and other state regulators tend to react to a breach notification by asking for specifics about the company’s response to the cyber event, zeroing in on its notification timeline, the substance of its communications with consumers and its incident response plan, according to experts.
Improve Notification Processes Before the Breach
Regulators inevitably scrutinize the speed of a company’s notification to their state, Morrison & Foerster partner Miriam Wugmeister told the Cybersecurity and AI Law Report. They typically question the time needed for analysis after discovery and ask the company when it found out that state residents were impacted and why it took so long from that date to send the notices, she reported.
Notification delays often stem from the labor-intensive process of identifying affected individuals in unstructured data, requiring forensic review, validation and matching records to current contact information. “The company has to have somebody look at each document and retype the name and the Social Security number” to determine who needs notice, Wugmeister explained. “It’s very much my hope that AI will make that better and faster,” she added.
Compliance leaders should treat readiness for notification as a standing task, experts agreed. Assigning who coordinates legal analysis, forensics, data mining, regulator communications and mailings helps demonstrate diligence when notification takes longer than expected. Showing implementation of these workstreams can persuade “the regulator that the company was taking its obligations seriously and moving expeditiously,” Wugmeister observed. Engaging with outside counsel throughout this planning is important, Van Hise pointed out.
Many states still require notice in “the most expedient time possible” or “without unreasonable delay,” but regulators and lawmakers have been moving to impose numerical deadlines, Van Hise noted. In 2026, California updated its law to impose a hard 30‑day deadline to notify affected residents, and a subsequent 15‑day deadline to supply” the AG with a copy of the consumer notice.
Companies can further demonstrate their diligence by establishing clear criteria for when the notification clock begins and by documenting how they communicate as facts continue to emerge.
Practice Incident Response Plans
Among the first regulator requests that companies receive post-breach are those asking for details about the incident response plan used, to help determine whether the organization had prepared adequately before the alarm sounded, Van Hise said.
In response to the inquiry, the company should aim to provide the AG more than an outdated PDF. Its incident response leaders should be prepared to produce documents that demonstrate companywide practice of a plan. It has become important to show wide participation in such tabletop exercises, spanning compliance, IT, security, vendor management, business-unit leaders and senior executives, Reed noted.
The practiced plan should include key elements such as named roles, inclusion of the board, logs for decisions made and triggers for escalating reports. Procedures for customer support, vendor coordination and regulator communications are other good components, recommended Shook, Hardy & Bacon senior counsel Jon Wilson.
A best practice is to run exercises that force decisions despite incomplete facts, like whether to rely on vendor assurances, Liebermann suggested. The plan and tabletop exercise should also identify backup decision-makers because incidents often arrive when the right people are not available. Conducting the tabletop exercise with added topics and nuances helps build “muscle memory,” he noted.
State investigators may also focus on business continuity planning and how the company responds to operational disruptions, Reed suggested. Accordingly, “when we tabletop our plans with various companies, we’re modeling what the business disruption looks like and how to work through it,” she said. Possible outages, malfunctions or other failures with AI tools are now increasingly part of those scenarios, as well. The business needs to see “what their plan B is for when these incredible tools become problematic,” she added.
See our two-part series “Amendment to NYDFS Cyber Regulation Brings New Mandates”: Governance Provisions (Dec. 13, 2023), and First Compliance Steps (Jan. 3, 2024).
Revamp Data Governance Around Retention, Minimization and Inventories
Data governance has intensified as a potent cyber-enforcement issue as the pool of consumer data that companies hold has continued to grow. Regulators are probing more closely into how long the company held the affected data and, in some cases, questioning why the company retained the data in the first instance, Liebermann reported.
Reduce Retention Risk
Managing data retention proves difficult because business teams often see old data as useful for analytics and AI initiatives. IT teams, meanwhile, fear deleting something another unit may later need. “The default often is the data stays too long,” Liebermann said.
Legal and risk leaders can help shift the focus from the value of retaining data to the risks of keeping it by asking, “What would happen if this data was breached?” Liebermann suggested.
An incident response tabletop practice can reveal gaps in executives’ understanding about the extent of the data that the company keeps. In one exercise, Liebermann recalled, a CEO argued that the company did not have the referenced dataset. However, after about 20 tense seconds, another participant clarified the company did indeed maintain the dataset and that it was actually “a database of our old clients.”
Put Muscle Into Inventories
Regulators expect companies to know their data flows. Yet, inventories are notoriously difficult to maintain and become “obsolete given how quickly data moves,” Reed lamented. Still, they are necessary. During inquiries, regulators issue requests for details on processing and sharing of personal data, and “the only way one can answer those questions effectively for the regulator is if the company has a proper and complete inventory,” she pointed out.
Regulators now expect that large organizations conduct inventories annually, experts agreed, while high-risk systems likely need more frequent review. “Some companies have spent small fortunes trying to inventory their data in response to regulatory requirements,” Ropes & Gray partner Edward McNicholas told the Cybersecurity and AI Law Report. Now, keeping the inventory current will be even more costly because of AI-related activity, he pointed out.
To keep inventories as useful as possible, companies can focus their efforts on important systems, vendors or purposes to ensure those are being covered, Wilson advised.
Increase Minimization Scrutiny
Regulators have upgraded data minimization from a privacy principle to a policed cyber control. “A major enforcement change on data minimization is going to happen in the blink of an eye,” Van Hise said.
The AGs are drilling down in investigations, questioning businesses’ need for keeping certain datasets and expecting disposal when no business or legal purpose remains, Wilson noted. One message lawyers can deliver to business colleagues is that keeping such datasets means also keeping liability, he advised.
Organizations can promote minimization by explicitly embedding it in AI governance programs, experts suggested.
Strengthen MFA, Identity and Access Management
Because compromised credentials remain a leading path to breaches, a company’s rigor in authenticating users and shielding access to systems is a key focus of enforcers.
Switch to More Sophisticated MFA
Regulators may start by asking “about departed employees, password policies and active credentials. And that often leads to a focus on whether there’s multi-factor authentication (MFA),” McNicholas advised.
Regulators’ emphasis makes sense, Liebermann opined, as “strong MFA across an enterprise makes it more difficult for threat actors to get in. But regulators see MFA as a panacea. Unfortunately, it is not. Threat actors have learned very well how to get around even the best MFA,” he lamented.
“Regulators have a very strong opinion on the best types of MFA and those that fail, and they are looking for companies to continually mature their MFA systems,” Liebermann continued. For example, companies now should implement MFA that uses authenticator apps rather than texted codes or hardware certificates, he noted.
The narrow focus on MFA has challenged particularly the longest-regulated industries, McNicholas observed. “Many large institutions have enormously important legacy systems, and these systems sometimes cannot be re-engineered for MFA. Or they could only be re-engineered by essentially recoding them,” he said.
See “Checklist for Building an Identity-Centric Cybersecurity Framework” (Nov. 3, 2021).
Boost Access and Identity Management
Regulators expect compensating controls to balance weaker MFA, including tougher management of permissions and identity risks. “Companies are going to see more expectations around credentialing and access controls,” Van Hise cautioned. Use of password vaults and remote-access controls have entered regulatory discussions now, he noted. Enhancing “joiner-mover-leaver” processes can address regulators’ questions about departed employees and leftover log-in credentials in the system.
Companies should also manage permissions regarding assets. “Companies often don’t know what is being put on their systems,” Wilson reported. With tools and infrastructure changing for AI operations, companies should comprehensively limit unauthorized users from adding a program to the company’s systems, he advised.
Machine identities and service accounts deserve distinct attention, Wugmeister urged. “Companies have machine-to-machine talking for certain functions to work, which cannot have MFA. But bad guys sometimes log in and add themselves to a group as if they were a machine,” she highlighted. To combat this issue, “a best practice is to have an alert when a new user joins such groups,” she recommended.
With identity management necessitating complicated modernization, the New York Department of Financial Services (NYDFS) and other regulators may expect a company’s top leaders to explicitly encourage efforts in this top area of vulnerability.
See “NYDFS Changes Its Cybersecurity Regulation Requirements Through Enforcement – Again” (Jul. 19, 2023).
Fortify Vendor Risk Management
Vendor incidents have driven tough state regulator questions because they expose the gap between contractual accountability and day-to-day dependence on a supplier. “States take the position that companies cannot contract around their obligation to safeguard data,” Van Hise noted. With the abundance of attacks, the details of how a company manages third parties will be a key area of scrutiny going forward, he posited.
See “Guidance From NYDFS in Industry Letter Stressing Vendor Risk Management and Oversight” (Dec. 10, 2025).
Determine the Riskiest Relationships
A key challenge for managing vendors is scale. Companies rely on providers for cloud services, software, cyber services and many business processes. Prioritization is a starting point. “A strong third-party risk management program will have an assessment of where your vulnerabilities are and your dependencies are,” Liebermann noted.
Critical vendors need closer review and strong due diligence. However, “parties often have significant reliance on a third party, with no bargaining power,” McNicholas warned. In those situations, he advised, the company should seek ample information about a vendor’s access to data and systems, breach notification obligations and cybersecurity program disclosures to better understand and manage the related risks.
When the company does have leverage with a vendor critical to its operations, regulators expect the company to obtain audit rights and greater disclosures about their business continuity measures and subcontractors. Regular review of contracts to limit “the downstream and upstream risks with vendors” is another good practice that regulators may ask about, Wilson noted.
Streamline Diligence Procedures
Vendor questionnaires can become self-defeating. “If the survey, inventory or form is too cumbersome, people won’t use it or give proper answers,” Reed warned. A helpful approach may be to use tiers: short, mandatory questions for all vendors; deeper interrogation of high-risk vendors; and evidence-based examination of critical ones.
Compliance teams can streamline the inquiry by choosing five aspects of vendor relationships that cause their own company the biggest trouble, Reed recommended. The affected stakeholders – lawyers, vendor managers, CISOs, etc. – “can make time to look at the answers to five core questions. They don’t have time to look at the answers to 300 questions for 20 different companies,” she proposed.
Overall, companies need to dedicate “more resources to improving their monitoring of who they’re relying on” and the recipients of their data, Wilson urged.
Plan for Vendor Failure
A company’s third-party management should include planning for trouble. Companies should identify alternative suppliers, risk mitigation steps and exit paths if a key provider leaks data or serves as an attack conduit. “When a vendor has had an incident, I’ve seen people ending that relationship and moving on” more often, Wilson said.
“Two Settlements Show NYDFS’ Hidden Power to Use Other States’ Breach Laws” (May 5, 2021).