Compliance / NY SHIELD Act

New York Stop Hacks and Improve Electronic Data Security Act for MSPs

New York's data-security law — broader than a typical state breach-notification statute, requiring any business handling a New York resident's private information to maintain a documented, reasonable security program, not just notify after a breach.

Why this reaches an MSP, not just the client

The SHIELD Act applies based on holding a New York resident's private information, not on where the business itself is located — a client with even a handful of New York customers or employees is in scope, and the law's "reasonable safeguards" requirement (administrative, technical, and physical) reaches the MSP maintaining the technical safeguards on the client's behalf.

What the Nexus compliance module tracks

  • Posture tracked against the SHIELD Act's technical safeguard expectations — access control, encryption, monitoring for unauthorized access — using the same three-state model as every other framework here
  • Evidence attached directly to the control it supports, giving a client a documented security program instead of an assumed one
  • Breach-notification readiness tracked as a specific control, since the Act's notification obligations are triggered by unauthorized access, not only confirmed data exfiltration
  • A QBR rollup a client's counsel or business owner can point to as evidence a "reasonable" program actually exists

This describes what the module tracks against NY SHIELD Act — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.

Ready to see NY SHIELD Act posture tracked for real?

Join the design-partner cohort and we'll walk through the control mapping for your own clients.