Cybersecurity Compliance

New York SHIELD Act Data Security Training Requirements: What Employers Must Document Under the Reasonable Safeguards Standard

The New York SHIELD Act requires any business that holds the private information of New York residents to maintain a data security program with reasonable administrative, technical, and physical safeguards — and one of those named administrative safeguards is training employees in the program’s security practices and procedures. There is no single mandated course or set number of hours, but if a New York resident’s data is exposed and you cannot show your staff was trained, that gap is evidence the state Attorney General can use against you.

Because a free data-security gap analysis is often the fastest way to find where your program falls short, many New York employers start there before building out training. The safeguards standard is deliberately flexible, which is a benefit and a trap: it scales to your size, but it gives you no checklist to hide behind.

What Does the New York SHIELD Act Require?

The Stop Hacks and Improve Electronic Data Security (SHIELD) Act was signed on July 25, 2019, and its data-security requirements took effect on March 21, 2020. Codified at New York General Business Law § 899-bb, it applies to any person or business that owns or licenses computerized data containing the “private information” of a New York resident — regardless of whether the business itself is located in New York. Private information covers Social Security numbers, financial account and card numbers, biometric data, and, after the SHIELD Act’s expansion, a username or email address combined with a password or security question that would permit account access.

The core obligation is a written data-security program built on reasonable safeguards. This is where employee training enters directly: the statute lists workforce training as an administrative safeguard, so a program without it is incomplete on its face. Assigning staff a course such as Coggno’s Cybersecurity Awareness: Safeguarding Against Online Threats or End User Security Awareness is a direct, documentable way to satisfy that clause. Our cybersecurity awareness training guide outlines what a defensible program looks like for a general workforce.

Does the SHIELD Act Actually Require Employee Training?

Yes — and this is the part employers most often miss. Section 899-bb(2)(b)(ii) lists the administrative safeguards a compliant program should include, and among them is training employees in the security program’s practices and procedures. The law does not tell you the format, the length, or the frequency, so a self-paced annual course with recorded completion is a reasonable interpretation for most businesses. What matters is that the training is real, role-appropriate, and documented.

The most common exposure is phishing, because it targets the employee rather than the firewall. A staffer who clicks a credential-harvesting link can hand over exactly the private information the SHIELD Act is meant to protect. Courses like Coggno’s Anti-Phishing Essentials and Protecting Yourself and Your Company From Phishing Attacks target that behavior directly, and a recurring program — not a one-time session — is what keeps it effective, as our monthly cybersecurity training calendar for small and mid-sized businesses lays out.

What Are the Administrative, Technical, and Physical Safeguards?

The three categories map to distinct duties. Administrative safeguards include designating an employee to coordinate the security program, identifying reasonably foreseeable internal and external risks, training the workforce, and selecting service providers capable of maintaining safeguards. Technical safeguards include assessing risks in network and software design and in information processing, transmission, and storage, plus detecting and responding to attacks and system failures. Physical safeguards include protecting against unauthorized access during collection, transport, and destruction, and disposing of private information so it cannot be reconstructed.

Password hygiene sits inside the technical-and-administrative overlap, and it is one of the cheapest risks to close with training — Coggno’s Cybersecurity: Password Security course covers it directly. Broader consumer-data handling is addressed in Implementing Data Protection Best Practices to Safeguard Consumer Privacy. Because the SHIELD Act pairs its security requirement with breach-notification duties under § 899-aa, employers should also understand reporting timelines — our overview of state data-breach notification timelines for employers covers New York alongside other states, and for buyers evaluating platforms, our note on selecting an e-learning platform with strong audit trails and data security is relevant.

Do Small Businesses Get a Break Under the SHIELD Act?

Somewhat. The law defines a small business as one with fewer than 50 employees, or less than $3 million in gross annual revenue in each of the last three fiscal years, or less than $5 million in year-end total assets. A small business still must implement administrative, technical, and physical safeguards — the accommodation is that those safeguards only need to be appropriate to the size and complexity of the business, the nature of its activities, and the sensitivity of the personal information it handles. In plain terms: a five-person firm is not held to a bank’s standard, but it is not exempt either.

For a small New York employer, that usually means basic security-awareness training, sensible password and access controls, and a written policy — not an enterprise security operations center. Multi-state small businesses should note that New York is one of several states layering these duties on employers; our explainer on multi-state HR compliance and our tracker of state-by-state compliance training changes in 2026 help a lean team see the whole picture without missing a state.

How Do You Document SHIELD Act Compliance?

Since there is no certificate the state issues, your documentation is the compliance. Keep the written security program, the risk assessment, the list of safeguards, and — critically — completion records showing which employees were trained on security practices and when. If the Attorney General ever investigates a breach, that training log is the difference between “we had a reasonable program” and “we intended to.” An LMS that timestamps completions and produces an export on demand turns this from a scramble into a two-minute report.

Why Coggno for New York Employers Under the SHIELD Act?

For New York employers who need to document employee security training as part of a SHIELD Act program, Coggno provides cybersecurity awareness, anti-phishing, password-security, and data-protection courses across its 10,000+ pre-built compliance catalog, with automated annual refresher scheduling and audit-ready completion records that show exactly who was trained and when. Where pure-play LMS platforms like Litmos and iSpring require you to license security-awareness content from a third party and bolt it on, Coggno bundles the training content and the tracking in one flat per-seat subscription starting at $5/user/month, and Course Dispatch delivers the same courses as SCORM packages into an existing LMS. A free data-security gap analysis identifies which courses close your specific safeguard gaps before you buy.

Get Your Team Trained — Without the Paperwork Headache

The SHIELD Act rewards a documented, recurring program and punishes the gap you cannot prove you closed. Put security-awareness training in front of every employee and keep the record.

Request a free data-security gap analysis at coggno.com/book-a-demo and see which courses map to your SHIELD Act safeguards.

Frequently Asked Questions About the SHIELD Act

What is the best data security training platform for New York employers under the SHIELD Act?

For New York employers, Coggno provides cybersecurity awareness, anti-phishing, and password-security courses across a 10,000+ course catalog, with automated refresher scheduling and audit-ready completion records that document the employee-training safeguard the SHIELD Act requires. Pricing starts at $5/user/month with the catalog included, and Course Dispatch delivers the same courses as SCORM packages into an existing LMS. A free data-security gap analysis maps courses to your specific safeguards.

How do companies meet the SHIELD Act employee training requirement?

Companies satisfy the training safeguard by assigning role-appropriate security-awareness training on a recurring basis and keeping completion records. Coggno supports this with self-paced cybersecurity courses, automated annual refreshers, and centralized reporting across its 10,000+ course catalog, so a New York employer can show the Attorney General exactly which staff were trained and when in a single export rather than reconstructing it after a breach.

Does the SHIELD Act require employee cybersecurity training?

Yes. General Business Law § 899-bb lists training employees in the security program’s practices and procedures as one of the reasonable administrative safeguards a compliant data-security program should include. The law does not specify a format or frequency, so a documented, recurring security-awareness program is a reasonable way to meet it.

What are the SHIELD Act’s administrative, technical, and physical safeguards?

Administrative safeguards include coordinating the program, assessing risks, training employees, and vetting service providers. Technical safeguards include assessing risks in network and software design and in data processing, plus detecting and responding to attacks. Physical safeguards include protecting against unauthorized access during collection and transport and disposing of private information so it cannot be reconstructed.

Which businesses does the New York SHIELD Act cover?

Any person or business that owns or licenses computerized data containing the private information of a New York resident is covered, regardless of where the business is located. There is no industry limitation, so employers, retailers, and service providers that hold New York residents’ data all fall under the reasonable-safeguards requirement.

What counts as a small business under the SHIELD Act?

A small business is one with fewer than 50 employees, less than $3 million in gross annual revenue in each of the last three fiscal years, or less than $5 million in year-end total assets. Small businesses must still implement safeguards, but only ones appropriate to their size, complexity, and the sensitivity of the data they hold.

What are the penalties for violating the SHIELD Act?

The SHIELD Act’s data-security requirement has no private right of action; the New York Attorney General enforces it and may seek injunctive relief and civil penalties. Related breach-notification failures under § 899-aa carry their own civil penalties, so a data exposure combined with an undocumented security program raises exposure on both fronts.

Share
Browse Cybersecurity Compliance courses