The State of New York has issued new guidance addressing the impact of artificial intelligence (AI) on cybersecurity, aimed at entities regulated by the Department of Financial Services, referred to as “Covered Entities.” As AI continues to evolve, it brings both enhanced cybersecurity capabilities and new vulnerabilities, which HR professionals should understand to protect sensitive company and employee data.
AI has proven valuable in bolstering cybersecurity measures, such as improving threat detection and enhancing incident response strategies. However, the state’s guidance highlights the risks associated with AI, focusing on areas that cybercriminals increasingly exploit.
AI-Related Cybersecurity Risks
The guidance outlines several AI-related threats, including:
Recommended Cybersecurity Controls
The guidance advises Covered Entities to utilize already established cybersecurity frameworks including conducting thorough risk assessments, enhancing access controls, and ensuring third-party service providers comply with robust cybersecurity standards.
Risk Assessments: Entities should incorporate AI-specific risks into their cybersecurity risk assessments. This helps determine appropriate defensive measures, including periodic updates to ensure new AI-related threats are addressed.
Access Controls: Strengthening access controls, such as Multi-Factor Authentication, is essential to combat threats posed by AI-enhanced social engineering attacks. The guidance recommends avoiding easily compromised authentication methods and considering advanced biometrics with anti-spoofing technology.
Vendor Management: Organizations should conduct thorough due diligence on third-party vendors to assess how they handle AI and protect data. The guidance suggests including contractual clauses to require notification of AI-related security incidents.
Implications for HR Professionals
HR teams must recognize the evolving landscape of AI-related cybersecurity risks and work closely with IT to implement recommended controls. By understanding these risks, HR professionals can help safeguard sensitive employee data and reinforce company-wide cybersecurity protocols.
Benefit Allocation Systems (BAS) provides best-in-class, online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.
MyEnroll360 can Integrate with any insurance carrier for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and many others), and integrate with any payroll system for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and many others).