Why New York Businesses Need Proactive IT Support for Cybersecurity and Compliance
Without proactive IT support, you leave your business exposed to cyber threats such as phishing, ransomware, and data breaches, as well as compliance violations that can lead to costly fines.
And in New York, keeping your business safe and running smoothly is how you stay competitive. The key is protecting yourself before these risks happen, which is why partnering with a managed service provider (MSP) is so important.
In this post, we’ll look at the current state of cybercrime in New York, the city’s unique compliance requirement, the SHIELD Act, and why partnering with an MSP is one of the best ways to protect your business.
The State of Cybercrime in New York
A report published in 2023 found that New York experienced a 53% increase in cybercrime between 2016 and 2022, resulting in more than $775 million in losses. And that increase hasn’t slowed.
While we don’t have New York-specific numbers, the national average shows just how fast cybercrime is growing. The FBI reported that cybercrime losses reached nearly $21 billion in 2025, up from approximately $12.5 billion back in 2023 nationwide.
The thing is, cybercrime isn’t restricted to organized criminal groups or highly skilled hackers anymore. Thanks to AI advancements and increasingly sophisticated attack methods, the barrier to entry is lower than ever. For example, a Tufin survey found that a stunning one in six New York teenagers reported being involved in some form of cybercrime – testament to cybercrime’s accessibility in the modern age.
For small businesses that lack the security resources of larger enterprises, overcoming these risks can be a serious challenge. Without the right protection, a single attack can close a business for good.
The Impact of Cybercrime on New York Small Businesses
Cybercrime may wear different masks, but the impact typically results in the following:
Expensive Downtime
Cyberattacks force business operations to halt or go offline altogether. Every minute of downtime that passes is lost revenue, with the average cost of downtime estimated at around $9,000 per minute.
For example, if an employee opens up a malicious email that leads to a data breach (human error causes roughly 60% of security incidents), your security team might disable your network to keep the breach from spreading. That forces everything to pause while they work to contain the attack and recover your systems.
Damaged Reputation
Then there’s how your customers react. 75% of consumers say they’d stop purchasing from a brand after a security incident.
Think about it. Would you create an account on someone’s website right after a massive data breach that leaked every user’s password?
Compliance Fines
Then, after all that, a cyberattack can directly cause a compliance violation. Because at the end of the day, compliance regulations are there to enforce good cybersecurity practices.
By falling victim to an attack, businesses might be questioned about whether they had the proper safeguards in place to protect sensitive information and meet regulatory requirements.
Let’s say cybercriminals expose the sensitive medical records of a small healthcare practice. That incident could directly violate HIPAA requirements and result in penalties ranging from $50-$50,000 per violation.
Reporting Cybercrime
Luckily, New York offers small businesses several ways to report cybercrime. That said, where you report your incident depends on the type of offence, the category of crime, and the financial or operational impact.
Some of the major reporting channels include:
Internet Crime Complaint Center (IC3): An FBI-run reporting center that receives internet crime complaints and routes them to the appropriate law enforcement agencies.
- New York State Police Cyber Analysis Unit: For state-level cybercrime.
- New York Police Department Cyber Unit: For cyber-enabled offenses across New York City’s five boroughs.
- New York Attorney General Internet & Technology Bureau: For online fraud, identity theft, and online scams.
- NYDFS Cybersecurity Incident Reporting: For organizations regulated under 23 NYCRR 500 that need to report qualifying cybersecurity events.
- Cybersecurity and Infrastructure Security Agency (CISA): For attacks affecting critical infrastructure.
New York provides a complete guide explaining how and where to report cybercrime, along with a separate page covering cybersecurity regulations and reporting requirements.
Compliance in New York
Compliance is no less of a challenge for New York businesses. Regulations are constantly evolving, customer expectations continue to rise, and the penalties for noncompliance can be substantial.
Then New York adds another layer with the SHIELD Act.
Understanding the New York SHIELD Act
Any business that handles private resident data (yes, even if your business technically isn’t in NY) must follow the New York SHIELD Act (Stop Hacks and Improve Electronic Data Security Act).
The SHIELD Act is New York’s primary data security law. It expands the definition of a reportable data breach, and enforces “reasonable safeguards” to protect private information.
These safeguards fall into three categories:
- Administrative safeguards: Designate someone to coordinate your security program, identify risks, assess your current safeguards, train your employees, and manage third-party vendors.
- Technical safeguards: Assess risk in your network and software, secure how information is processed, transmitted, and stored, and regularly test and monitor key systems.
- Physical safeguards: Control access to computers and other devices, secure physical equipment, and properly dispose of devices containing private information.
IMPORTANT: These safeguards aren’t “best practices” or recommendations, but are specifically outlined in the SHIELD Act itself under Section 899-bb(2)(b)(ii).
Small Business-Tier
The SHIELD Act scales to fit small businesses, meaning small businesses aren’t held to the same standard as larger companies. That doesn’t mean security is any less important; it just means your safeguards should be appropriate for the size and complexity of your business.
Under the SHIELD Act, a small business meets any of the following criteria:
- Has fewer than 50 employees.
- Earns less than $3 million in gross annual revenue in each of the previous three fiscal years.
- Has less than $5 million in year-end total assets.
How an MSP Helps Protect Small Businesses
Managed service providers (MSPs) are in a perfect position to help businesses strengthen their security posture. That’s because they use a proactive approach to prevent problems before they happen while also helping businesses navigate compliance requirements like the SHIELD Act.
Here’s how:
24/7 Monitoring Keeps Things Working
Yes, continuous monitoring means having a partner who can respond quickly when something goes wrong. But more than that, monitoring tools help MSPs stay on top of updates and regular maintenance. By keeping your systems in good shape, you reduce the chances of something going wrong in the first place.
Security Software and Business Continuity Keep You Ready
A good MSP will equip your business with strong security tools such as multi-factor authentication (MFA alone stops 99.9% of account-based attacks), network encryption, and antivirus software. They can also help implement security frameworks like Zero Trust Security to reduce the risk of unauthorized access.
Beyond prevention, they’ll help build a business continuity plan and disaster recovery plan so that if the worst does happen, your business has a clear path to getting back up and running as fast as possible.
Security Awareness Training Helps Employees Stay Vigilant
Your employees are your first line of defense against social engineering attacks like phishing. That’s why a good MSP provides security awareness training to help your team recognize suspicious emails and other attack methods before they impact your company.
SHIELD Act Assistance
Many of the safeguards required by the SHIELD Act naturally align with the services an MSP already provides.
Continuous monitoring, access control, endpoint protection, and regular testing help satisfy the Act’s technical safeguards. Secure device management and disposal support physical safeguards. Employee training, vendor oversight, and security planning support administrative safeguards.
On top of that, an MSP familiar with New York regulations can help your business navigate incident reporting requirements during an emergency.
Partner With The 20 MSP to Protect Your Business
If you’re looking for a partner to protect your business, look no further than The 20 MSP.
We know how hard you’ve worked to build your business. Don’t let a cyberattack put everything you’ve built at risk.
From endpoint management and compliance assistance to security awareness training, we make sure our clients are equipped with exactly what they need to stay safe. And with one predictable, flat-rate fee, you’ll always know what to expect – no surprises.
If you’re ready to get your business properly secured and keep it that way, let’s talk. We’d love to see how we can help.
Want more tips like this?
Subscribe using the form on the right and get our latest insights delivered straight to your inbox.
About The 20 MSP
As a leading provider of managed IT services, The 20 MSP serves thousands of businesses nationwide, providing each one with white-glove service, secure and streamlined IT infrastructure, and 24/7/365 dedicated IT support. We believe in building lasting relationships with clients founded on trust, communication, and the delivery of high-value services for a fair and predictable price. Our clients’ success is our success, and we are committed to helping each and every organization we serve leverage technology to secure a competitive advantage and achieve new growth.

