<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	>

<channel>
	<title>Risk Assessment Archives - Third Rock</title>
	<atom:link href="https://thirdrock.com/blog/category/risk-assessment/feed/" rel="self" type="application/rss+xml" />
	<link>https://thirdrock.com/blog/category/risk-assessment/</link>
	<description>Building a Cyber Confident World</description>
	<lastBuildDate>Tue, 21 Jul 2020 12:34:47 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.8</generator>

<image>
	<url>https://i0.wp.com/thirdrock.com/wp-content/uploads/cropped-favicon-check.png?fit=32%2C32&#038;ssl=1</url>
	<title>Risk Assessment Archives - Third Rock</title>
	<link>https://thirdrock.com/blog/category/risk-assessment/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">65153150</site>	<item>
		<title>EXEMPT is not a FREE PASS with 23 CRR 500 NY DFS</title>
		<link>https://thirdrock.com/blog/2020/01/31/exempt-is-not-a-free-pass-with-23-crr-500-ny-dfs/</link>
		
		<dc:creator><![CDATA[Robert Felps]]></dc:creator>
		<pubDate>Fri, 31 Jan 2020 15:00:00 +0000</pubDate>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=8754</guid>

					<description><![CDATA[<p>Exempt. When we hear that word, we think about being “off the hook” or that we have immunity. We feel free of meeting the same expectation as someone else. &#160;We’ve [&#8230;]</p>
<p>The post <a href="https://thirdrock.com/blog/2020/01/31/exempt-is-not-a-free-pass-with-23-crr-500-ny-dfs/">EXEMPT is not a FREE PASS with 23 CRR 500 NY DFS</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-normal-font-size">Exempt. When we hear that word, we think about being
“off the hook” or that we have immunity. We feel free of meeting the same expectation
as someone else. &nbsp;We’ve escaped fulfilling
requirements.</p>



<p class="has-normal-font-size">Not so fast! If you’re an insurance broker with clients in New York,
the NY Department of Financial Services (NYDFS) 23 NYCRR 500 cybersecurity
regulations still apply to your company.&nbsp;
Exempt means most brokers, bankers and all other financial service
organizations need to complete a risk assessment and attest to them before <strong>April
15, 2020</strong> to avoid fines and penalties.</p>



<h3 class="wp-block-heading"><strong>I’m a small, exempt, business. Why is compliance important?</strong></h3>



<p class="has-normal-font-size">Often times, small to medium sized companies get the raw end of the
deal when it comes to compliance. Higher expectations usually mean more money
and more personnel, which is easier said than done.</p>



<p class="has-normal-font-size">NYDFS recognizes how cybercrime is wreaking havoc on the financial
industry.&nbsp; They want even the smallest
companies to have basic security in place to best protect their clients and
themselves. Why? Cyber criminals know small and medium sized companies tend to
have lower security in place, making them a perfect target. In fact, according
to Verizon’s Data Breach Report, 43% of cyber-attacks targeted small
businesses.&nbsp; NYDFS is leading the nation
in getting the industry more cybersecure at all levels.</p>



<div class="wp-block-image"><figure class="alignleft size-medium"><img fetchpriority="high" decoding="async" width="286" height="300" src="//i1.wp.com/thirdrock.com/wp-content/uploads/blog-pullout-286x300.png" alt="Reserved: NYDFS regulation 500.19(a)(1) – You are entitled to this exemption when a Covered Entity has fewer than 10 employees, including independent contractors.  This is a limited exemption and you must still design and implement a cybersecurity program that meets some but not all the regulatory requirements.  This includes submitting an annual Certification of Compliance.


" class="wp-image-8761" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/blog-pullout.png?resize=286%2C300&amp;ssl=1 286w, https://i0.wp.com/thirdrock.com/wp-content/uploads/blog-pullout.png?w=366&amp;ssl=1 366w" sizes="(max-width: 286px) 100vw, 286px" /></figure></div>



<p></p>



<p></p>



<h3 class="wp-block-heading"><strong>IT manages our cyber risk, right?</strong></h3>



<p class="has-normal-font-size">This is where the false sense of security
is with many insurance brokers and organizations. Most IT departments or Manage
Service Providers (MSPs) are focused on technology and data access.&nbsp; They don’t know if you are conducting cyber
security awareness training for your employees or if you have accurate security
measures in place for vendors.</p>



<p class="has-normal-font-size">NYDFS wants businesses to move to a holistic and vigilant approach by
building a cyber resilient culture that goes beyond technology.&nbsp; To outpace the cyber criminals, you must
create a culture of cybersecurity within your company that covers your people,
processes, technology and vendors.</p>



<p class="has-normal-font-size">Not sure of your next step?&nbsp; Here
is a break down and what you need to do before April 15, 2020:</p>



<p></p>



<p></p>



<p></p>



<p></p>



<h3 class="wp-block-heading"><strong>Compliance starts with knowing your risk across your organization</strong></h3>



<p class="has-normal-font-size">All financial services, regardless of size, must do the following to design and implement a cybersecurity program to meet regulations.  </p>



<p class="has-normal-font-size">1 &#8211; <span style="font-size: inherit;">Conduct a proper risk assessment that covers </span><strong style="font-size: inherit;">14 topics around people, processes, technology and vendors.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img decoding="async" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?fit=1024%2C488&amp;ssl=1" alt="" class="wp-image-8762" width="823" height="392" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?w=1889&amp;ssl=1 1889w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=300%2C143&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=1024%2C488&amp;ssl=1 1024w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=768%2C366&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=1536%2C732&amp;ssl=1 1536w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=1080%2C515&amp;ssl=1 1080w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=1280%2C610&amp;ssl=1 1280w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=980%2C467&amp;ssl=1 980w, https://i0.wp.com/thirdrock.com/wp-content/uploads/Assessment-cart.png?resize=480%2C229&amp;ssl=1 480w" sizes="(max-width: 823px) 100vw, 823px" /></figure></div>



<p class="has-normal-font-size">2 &#8211; Make sure you have policies, procedures, and documentation that covers the 14 areas. </p>



<p class="has-normal-font-size">3 &#8211; NYDFS requires documentation for several plans: <em>(Make sure you check with your IT and/or IT provider you have to make sure these plans are available regarding cyber breach!)</em></p>



<figure class="wp-block-table is-style-stripes"><table><tbody><tr><td><strong>Risk Management Plan   </strong></td><td><em>Outlines what you are doing to   prevent cybercrime, improve cybersecurity and information protection and reduce cyber risk</em>   </td></tr><tr><td><strong>Incident Response Plan </strong>  </td><td><em>Details action to respond to an incident across your organization</em>   </td></tr><tr><td><strong>Business Continuity/Disaster Recovery Plan   </strong></td><td><em>Details actions to minimize and recover from a breach   across your organization</em>   </td></tr><tr><td><strong>Breach Notification Plan </strong>  </td><td><em>Defines who you need to notify, when to notify and how to notify to avoid penalties and limit liabilities</em>   </td></tr></tbody></table></figure>



<h3 class="wp-block-heading"><strong>Lacking resources, time and expertise to get NYDFS 500
compliant by April 15, 2020?</strong></h3>



<p class="has-normal-font-size">We understand that compliance can feel overwhelming. It seems
expensive, difficult, and almost unattainable.&nbsp;
The deadline looks like a huge mountain you have to climb.&nbsp; At Third Rock, we offer <a href="https://thirdrock.com/nydfs/">CyberCompass®,</a> a self-guided
automation tool to make your compliance journey easier and affordable while
still meeting the deadline. &nbsp;</p>



<p class="has-normal-font-size">CyberCompass® is automated, cloud-based compliance
software with built-in expertise that translates NYDFS government requirements
into layman’s terms. It does most of the heavy lifting for your risk
assessment, analysis, remediation and compliance documentation- including
updated policies and procedures and all the required plans. There is no
software to download or install and it can be accessed anywhere. <a href="https://youtu.be/0STdfcFqjLg">Click here</a> for a quick video about how CyberCompass® works with NYDFS
compliance. &nbsp;<strong>Note: If you are an ELANY
member, check out this CyberCompass</strong><strong>®</strong><strong> offer to </strong><a href="https://elany.org/CyberSecurityCompliance.aspx"><strong>ELANY members!</strong></a><strong></strong></p>



<p class="has-normal-font-size">Need assistance and want a compliance coach? Third Rock offers
affordable expertise to help you get to the deadline.

Don’t let cyber uncertainty keep you from
protecting your business and your clients. <a href="mailto:info@thirdrock.com?subject=Tell%20me%20more%20about%20CyberCompass™">Contact us today</a> and see how we can prepare you for the NYDFS
deadline and to best protect your clients and business.



</p>
<p>The post <a href="https://thirdrock.com/blog/2020/01/31/exempt-is-not-a-free-pass-with-23-crr-500-ny-dfs/">EXEMPT is not a FREE PASS with 23 CRR 500 NY DFS</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">8754</post-id>	</item>
		<item>
		<title>Am I a Data Processor or a Data Controller? &#8211; Check the GDPR glossary</title>
		<link>https://thirdrock.com/blog/2018/05/30/am-i-a-data-processor-or-a-data-controller-check-the-gdpr-glossary/</link>
		
		<dc:creator><![CDATA[Julie Rennecker, PhD, BSN]]></dc:creator>
		<pubDate>Wed, 30 May 2018 18:53:36 +0000</pubDate>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[complete GDPR Assessment]]></category>
		<category><![CDATA[GDPR glossary page]]></category>
		<category><![CDATA[GDPR infographic]]></category>
		<category><![CDATA[GDPR risk assessment]]></category>
		<category><![CDATA[key terms]]></category>
		<category><![CDATA[risk assessment]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=5657</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2018/05/30/am-i-a-data-processor-or-a-data-controller-check-the-gdpr-glossary/">Am I a Data Processor or a Data Controller? &#8211; Check the GDPR glossary</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
							<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p style="padding-left: 120px;"><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter wp-image-5682" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/gdpr_3-D-word-cloud.jpg?resize=428%2C257&#038;ssl=1" alt="Dynamic GDPR infographic | GDPR Risk Assessment | key terms" width="428" height="257" /></p>
<p>Ok, so the GDPR &#8220;deadline&#8221; has passed, but many of you are still tying up loose ends &#8211; or perhaps just discovering that the law applies to you! Whatever the case, don&#8217;t let confusion over a few terms slow your progress. Some vendors got together to create a great <a href="https://www.eugdpr.org/glossary-of-terms.html">glossary page</a> that defines all the key terms.</p>
<p>If you&#8217;re still uncertain about what you need to <em>do</em>, the official GDPR page summarizes the key points in a dynamic <a href="https://ec.europa.eu/justice/smedataprotect/index_en.htm">infographic</a>.</p>
<p>Need to get GDPR compliant and don&#8217;t have time or expertise to learn all the rules? Third Rock can deliver a complete GDPR Assessment with a prioritized list of corrective actions in just 5-7 business days for any size organization. Plus, based on your assessment results, we can help you determine whether you need additional help from us or one of our technical partners.</p>
<p>Third Rock is all about Complete Cyber Confidence. <a href="https://thirdrock.com/contact-us/">Contact us</a> today to achieve Complete GDPR Confidence.</div>
			</div>
			</div>		
				
				
				
				
			</div>	
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2018/05/30/am-i-a-data-processor-or-a-data-controller-check-the-gdpr-glossary/">Am I a Data Processor or a Data Controller? &#8211; Check the GDPR glossary</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5657</post-id>	</item>
		<item>
		<title>The GDPR deadline is here &#8211; are you ready?</title>
		<link>https://thirdrock.com/blog/2018/05/25/the-gdpr-deadline-is-here-are-you-ready/</link>
		
		<dc:creator><![CDATA[Julie Rennecker, PhD, BSN]]></dc:creator>
		<pubDate>Fri, 25 May 2018 18:02:14 +0000</pubDate>
				<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[CyberCompass™]]></category>
		<category><![CDATA[first step]]></category>
		<category><![CDATA[GDPR risk assessment]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[security risk analysis]]></category>
		<category><![CDATA[Security Risk Assessment]]></category>
		<category><![CDATA[Third Rock]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=5665</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2018/05/25/the-gdpr-deadline-is-here-are-you-ready/">The GDPR deadline is here &#8211; are you ready?</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_1 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><img data-recalc-dims="1" loading="lazy" decoding="async" class="wp-image-5522 size-medium alignright" style="margin-top: 5px; margin-left: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/AdobeStock_157142521.jpeg?resize=300%2C214&#038;ssl=1" alt="GDPR Deadline | Risk Assessment " width="300" height="214" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/AdobeStock_157142521.jpeg?resize=300%2C214&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/AdobeStock_157142521.jpeg?resize=768%2C549&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/AdobeStock_157142521.jpeg?resize=1024%2C731&amp;ssl=1 1024w, https://i0.wp.com/thirdrock.com/wp-content/uploads/AdobeStock_157142521.jpeg?w=2160&amp;ssl=1 2160w, https://i0.wp.com/thirdrock.com/wp-content/uploads/AdobeStock_157142521.jpeg?w=3240&amp;ssl=1 3240w" sizes="(max-width: 300px) 100vw, 300px" />If you are not yet GDPR-ready, you&#8217;re not alone. Many companies are still scrambling to meet the requirements. Some U.S.-based companies didn&#8217;t realize the law would apply to them. Others did not realize the full extent of the law &#8211;&nbsp;<em>or of their own data collection!&nbsp;</em></p>
<p>Don&#8217;t worry &#8211; whether starting from scratch or needing to document your current GDPR status, Third Rock&#8217;s CyberCompass™ streamlines the assessment process and automates the report generation, making it possible for Third Rock to give you a full report, including a prioritized list of action items, within a few days. Then, if needed, our consultants and technology partners can work with you to address the action items and come into compliance.&nbsp;<a href="https://thirdrock.com/contact-us/">Contact us</a> today to <strong>schedule a GDPR assessment</strong>, the<em> first step</em> in becoming compliant.</p>
<p style="text-align: center;"><strong>GDPR&nbsp;</strong><strong>&#8211; Automated. Simplified. Affordable.</strong></p>
<p style="text-align: center;"></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2018/05/25/the-gdpr-deadline-is-here-are-you-ready/">The GDPR deadline is here &#8211; are you ready?</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5665</post-id>	</item>
	</channel>
</rss>
