Cybersecurity & Data Protection

Security obligations, written down and testable.

Counselize advises on the privacy and information-security requirements that apply to a business, the written program a regulator expects to see, and what has to happen in the first days of an incident.

Security is a legal obligation before it is a technical one. Most regimes do not ask whether a company is secure, which is not a question anyone can answer. They ask whether it maintains a written information security program, whether that program follows from a risk assessment, whether a named person is accountable for it, and whether it is tested. A company can be well defended and still fail an examination for having none of that on paper.

Which rules apply turns on what the business does and whose data it holds. Financial institutions face the Gramm-Leach-Bliley Safeguards Rule, and companies regulated in New York face the Department of Financial Services cybersecurity regulation, with its multi-factor authentication, asset inventory, testing, and senior-officer certification requirements. State consumer privacy laws now reach most businesses of any size through thresholds on revenue and volume of personal data, carrying rights of access, deletion, and opt-out along with obligations on sensitive data and targeted advertising.

A great deal of this lives in contracts rather than in policies. Data processing agreements, security exhibits and audit rights, breach-notification timelines negotiated with vendors, and the third-party risk program that reviews them are where the obligations are actually created and where they are most often breached. A vendor's failure is generally still the client's notification obligation.

Incident response is the part that cannot be improvised. Notification deadlines run in days, they differ by state and by regulator, and they start before the technical picture is complete. Counselize prepares the plan while there is time, advises during the event on what is reportable and to whom, and handles the notifications and regulator communications that follow.

Scope

What this covers.

01Written information security programA program document built on a risk assessment specific to the business, with assigned accountability, control descriptions, review cadence, and the evidence an examiner asks for.
02Financial-sector requirementsGramm-Leach-Bliley Safeguards Rule obligations and the New York Department of Financial Services cybersecurity regulation, including asset inventory, testing, board reporting, and senior-officer certification.
03State privacy complianceApplicability analysis across state consumer privacy laws, including CCPA and CPRA, with the notices, disclosures, and internal procedures each requires.
04Data mapping and recordsWhat personal data the business collects, where it goes, who it is shared with, and the records of processing that support a notice or a regulator response.
05Consumer rights proceduresAccess, deletion, correction, and opt-out request handling, including sensitive data and targeted advertising obligations and the timelines that apply.
06Vendor and third-party riskData processing and data-sharing agreements, security exhibits, audit rights, negotiated breach-notification timelines, and the diligence program that reviews vendors before and after signature.
07Incident response planningAn incident response plan with roles, escalation, and decision points, prepared before it is needed and reviewed against the obligations that actually apply to the business.
08Breach notificationAnalysis of whether an event is reportable, to which regulators and individuals, on what timeline, together with the notifications, filings, and regulator communications that follow.
Counselize advises on the legal and regulatory side of security and privacy. It does not perform penetration testing, security engineering, or technical audits, and works alongside the provider that does.

Start with a conversation.