Compliance / NY SHIELD Act
New York Stop Hacks and Improve Electronic Data Security Act for MSPs
New York's data-security law — broader than a typical state breach-notification statute, requiring any business handling a New York resident's private information to maintain a documented, reasonable security program, not just notify after a breach.
Why this reaches an MSP, not just the client
The SHIELD Act applies based on holding a New York resident's private information, not on where the business itself is located — a client with even a handful of New York customers or employees is in scope, and the law's "reasonable safeguards" requirement (administrative, technical, and physical) reaches the MSP maintaining the technical safeguards on the client's behalf.
What the Nexus compliance module tracks
- Posture tracked against the SHIELD Act's technical safeguard expectations — access control, encryption, monitoring for unauthorized access — using the same three-state model as every other framework here
- Evidence attached directly to the control it supports, giving a client a documented security program instead of an assumed one
- Breach-notification readiness tracked as a specific control, since the Act's notification obligations are triggered by unauthorized access, not only confirmed data exfiltration
- A QBR rollup a client's counsel or business owner can point to as evidence a "reasonable" program actually exists
This describes what the module tracks against NY SHIELD Act — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.
Other frameworks
SOC 2
The audit framework a lot of your clients' own customers require them to answer for — and that requirement flows straight down to you as their MSP.
NIST CSF
A widely-adopted, vendor-neutral structure for cybersecurity posture — Identify, Protect, Detect, Respond, Recover — that shows up in RFPs, cyber-insurance questionnaires, and board conversations alike.
HIPAA
If any client handles protected health information, HIPAA's Security Rule reaches your MSP the moment you touch their systems — business associate agreement or not.
Ready to see NY SHIELD Act posture tracked for real?
Join the design-partner cohort and we'll walk through the control mapping for your own clients.