New York State Education Department Proposes New Regulations to Strengthen PII Security

Stu Sjouwerman | Feb 13, 2019
NYSED

The new proposed amendments seek to protect the personally identifiable information for students and school personnel accessible by both educational agencies and contractors.

In the wake of 2018’s massive data breaches and lawsuits involving employers not protecting PII, organizations are waking up to the need to put specific policies, processes, and solutions in place to ensure the security of the personal information they maintain.

The proposed regulation includes a level of focus found in current consumer privacy laws such as GDPR, CCPA, and the Ohio Data Privacy Act. While most aspects of the security required remain generic, one aspect of the plan stands out – the specific need for Security Awareness Training. The regulation seeks to have all officers and employees with access to PII undergo annual training. It also intends that all employees take training around data security and privacy. The regulation also seeks to apply the same standards to third-party contractors.

Organizations employing Security Awareness Training elevate their user’s understanding of first, why being security-conscious is critical and needs to be in place as part of their job. Specific training around data security, privacy, handling of data, and good security practices will help to protect PII and other sensitive data sets. Lastly, Security Awareness Training educates users on cyberattacks, scams, and social engineering techniques used by cybercriminals to gain access to credentials, endpoints, and entire networks.

New York’s State Education Department is on the right track – by putting Security Awareness Training in place, the organization, its’ data, and users will all be more secure, lowering the risk of threat and data breach.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.