3 ms·
(i) is enforceable. You could have a negligence claim, but customer (if a regulated entity) is generally required (on a principles basis, not necessarily presc
by zonethundery 5y ago
(i) is enforceable. You could have a negligence claim, but customer (if a regulated entity) is generally required (on a principles basis, not necessarily prescriptive) to do their own due diligence on the adequacy of the vendor's security practices. The shift away from assigning liability to vendors was part of Dodd-Frank, and NYDFS has taken a similar tack with its cybersecurity rules.