{"id":19708,"date":"2026-05-12T09:04:38","date_gmt":"2026-05-12T13:04:38","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19708"},"modified":"2026-05-12T09:04:38","modified_gmt":"2026-05-12T13:04:38","slug":"2026-may-newsletter","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19708","title":{"rendered":"2026 May Newsletter"},"content":{"rendered":"<h1>ELTENI&#8217;S CYBER SCOOP<\/h1>\n<h3>Latest News<\/h3>\n<p>Regulators continue to try to find ways to incentivize proactive transparency and collaboration around cybersecurity.\u00a0 Conversely, they continue to penalize firms for neglecting to implement and follow basic cybersecurity controls.<\/p>\n<h1>REGULATORY CORNER<\/h1>\n<p><strong>FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats<\/strong><\/p>\n<p><em>Building on FINRA&#8217;s continued commitment to help member firms combat cyber and financial crime threats, the FIFC will collect, analyze and disseminate threat intelligence to bolster member firms\u2019 awareness and ability to quickly respond to these threats. <\/em>FINRA began piloting the FIFC last year with a diverse group of member firms, whose participation and feedback have helped strengthen the portal\u2019s functionality and effectiveness for member firms of all sizes.<\/p>\n<h3>Notes<\/h3>\n<p><em>Traditionally, funds have been reluctant to adopt a high degree of transparency due to concerns about revealing potential weaknesses in their cybersecurity practices. Nonetheless, FINRA&#8217;s initiative underscores the importance of transparency and collaboration as effective strategies for addressing cyber threats across the industry. By sharing threat intelligence, organizations gain greater awareness of evolving risks and can proactively refine their security measures. Additionally, centralized regulatory bodies are more informed of realistic risks in near real-time and can disseminate information regarding these threats more broadly to participating institutions within the program.<\/em><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/finra-launches-financial-intelligence-fusion-center\">FINRA Launches Financial Intelligence Fusion Center | Dark Reading<\/a><\/p>\n<h1>ENFORCEMENT NEWS<\/h1>\n<p><strong>NYDFS\u2019s First 2026 Cyber Enforcement Action <\/strong><\/p>\n<p><em>On April 29, 2026, the New York State Department of Financial Services (\u201cDFS\u201d) issued its first cybersecurity enforcement action of 2026\u2014a Consent Order against Delta Dental Insurance Company and Delta Dental of New York, Inc. (the \u201cCompanies\u201d) imposing a $2,250,000 civil monetary penalty for violations of the Part 500 Cybersecurity Regulation. The Consent Order underscores two key themes that continue to drive NYDFS enforcement: dispose of data that you no longer need and notify the Department early.<\/em><\/p>\n<h3>Notes<\/h3>\n<p><em>Companies often view data protection narrowly, focusing on safeguarding information they actively store, process, or use in day-to-day operations. Data retention is often considered through the lens of disaster recovery, business continuity, or compliance-driven archiving. The NYDFS settlement is a reminder that retained data itself can create cybersecurity risk. When organizations keep data longer than necessary, particularly sensitive, stale, or no longer relevant information, they expand their attack surface and increase the volume of information that must be protected, monitored, and governed. Effective cybersecurity programs should therefore treat data minimization and retention governance as core security controls, not merely administrative or compliance exercises.<\/em><\/p>\n<p><a href=\"https:\/\/www.debevoisedatablog.com\/2026\/05\/06\/nydfss-first-2026-cyber-enforcement-action-highlights-imperative-of-early-notification-robust-ir-plans-and-data-minimization\/\">NYDFS\u2019s First 2026 Cyber Enforcement Action | Debevoise &amp; Plimpton<\/a><\/p>\n<h1>CYBER NEWS<\/h1>\n<p><strong>MSPs confront operational reality of the AI surge<\/strong><\/p>\n<p><em>Cybersecurity fundamentals are a priority along with emerging threats<\/em><\/p>\n<p><em>The challenge for MSPs is not just keeping pace with attackers but ensuring that the basics are consistently applied \u2014 because in many cases, the biggest risks are not new, just unresolved.<\/em><\/p>\n<p><a href=\"https:\/\/iteuropa.com\/news\/channel-sec-26-msps-confront-operational-reality-ai-surge\">Channel-Sec 26: MSPs confront operational reality of the AI surge | ITEuropa<\/a><\/p>\n<p><strong>CareCloud notifies the SEC after attack on one of its EHR environments <\/strong><\/p>\n<p><em>Classifying material risk when determining notification protocols<\/em><\/p>\n<p><em>In a March 27\u00a0<\/em><a href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1582982\/000149315226013239\/form8-k.htm?ref=dysruptionhub.com\"><em>SEC filing<\/em><\/a><em>, the Somerset, New Jersey-based company CareCloud (a health technology firm and business associate to covered entities), said an unauthorized third party temporarily accessed part of its CareCloud Health division on March 16, partially disrupting functionality and data access.\u00a0<\/em><\/p>\n<p><a href=\"https:\/\/databreaches.net\/2026\/03\/29\/carecloud-notifies-the-sec-after-attack-on-one-of-its-ehr-environments\/\">CareCloud notifies the SEC after attack on one of its EHR environments | DataBreaches.Net<\/a><\/p>\n<p><strong>Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk<\/strong><\/p>\n<p><em>Password management continues to show up as risk in the enterprise<\/em><\/p>\n<p><em>An attacker with administrative privileges can gain access to Microsoft Edge user\u00a0<\/em><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/10b-passwords-pop-up-on-dark-web-rockyou2024-release\"><em>passwords<\/em><\/a><em>\u00a0even when they&#8217;re not in use, because the browser stores them in cleartext in process memory as part of a design decision by Microsoft.<\/em><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/microsoft-edge-passwords-enterprise-risk\">Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk | DarkReading<\/a><\/p>\n<p><strong>Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom<\/strong><\/p>\n<p><em>Summarize the breach, threat trend, vulnerability, or operational risk<\/em><\/p>\n<p><em>A system that thousands of schools and universities use was offline Thursday during a cyberattack, creating chaos as students tried to study for finals and underscoring education\u2019s dependence on technology.<\/em><\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/cyberattack-hits-canvas-system-used-by-thousands-of-schools-as-finals-loom\/\">Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom | SecurityWeek<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ELTENI&#8217;S CYBER SCOOP Latest News Regulators continue to try to find ways to incentivize proactive transparency and collaboration around cybersecurity.\u00a0 Conversely, they continue to penalize firms for neglecting [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":19713,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,67,134,113,68,3,133,135,101,102,103,18,140,136,47,17,25,106,137,89,138,90,127,19],"tags":[],"class_list":["post-19708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alternative-asset-management","category-awareness","category-breaches","category-business-email-compromise","category-cloud","category-cyber","category-finra","category-ftc","category-hackers","category-hedge-fund","category-investment-adviser","category-microsoft","category-newsletter","category-nydfs","category-ocie","category-password","category-pii","category-private-equity","category-private-funds","category-regulatory","category-rules","category-sec","category-technology","category-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>2026 May Newsletter - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19708\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2026 May Newsletter - Insights\" \/>\n<meta property=\"og:description\" content=\"ELTENI&#8217;S CYBER SCOOP Latest News Regulators continue to try to find ways to incentivize proactive transparency and collaboration around cybersecurity.\u00a0 Conversely, they continue to penalize firms for neglecting [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19708\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-12T13:04:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2026\/05\/May-2026-Cover-Page-v2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"736\" \/>\n\t<meta property=\"og:image:height\" content=\"934\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"dtuck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dtuck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708\"},\"author\":{\"name\":\"dtuck\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"headline\":\"2026 May Newsletter\",\"datePublished\":\"2026-05-12T13:04:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708\"},\"wordCount\":688,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/May-2026-Cover-Page-v2.png\",\"articleSection\":[\"Alternative Asset Management\",\"Awareness\",\"Breaches\",\"Business Email Compromise\",\"Cloud\",\"Cyber\",\"FINRA\",\"FTC\",\"Hackers\",\"Hedge Fund\",\"Investment Adviser\",\"Microsoft\",\"Newsletter\",\"NYDFS\",\"OCIE\",\"Password\",\"PII\",\"Private Equity\",\"Private Funds\",\"Regulatory\",\"Rules\",\"SEC\",\"Technology\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708\",\"name\":\"2026 May Newsletter - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/May-2026-Cover-Page-v2.png\",\"datePublished\":\"2026-05-12T13:04:38+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/May-2026-Cover-Page-v2.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/May-2026-Cover-Page-v2.png\",\"width\":736,\"height\":934},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19708#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2026 May Newsletter\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\",\"name\":\"dtuck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"dtuck\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2026 May Newsletter - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19708","og_locale":"en_US","og_type":"article","og_title":"2026 May Newsletter - Insights","og_description":"ELTENI&#8217;S CYBER SCOOP Latest News Regulators continue to try to find ways to incentivize proactive transparency and collaboration around cybersecurity.\u00a0 Conversely, they continue to penalize firms for neglecting [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19708","og_site_name":"Insights","article_published_time":"2026-05-12T13:04:38+00:00","og_image":[{"width":736,"height":934,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2026\/05\/May-2026-Cover-Page-v2.png","type":"image\/png"}],"author":"dtuck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dtuck","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19708#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19708"},"author":{"name":"dtuck","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"headline":"2026 May Newsletter","datePublished":"2026-05-12T13:04:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19708"},"wordCount":688,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19708#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2026\/05\/May-2026-Cover-Page-v2.png","articleSection":["Alternative Asset Management","Awareness","Breaches","Business Email Compromise","Cloud","Cyber","FINRA","FTC","Hackers","Hedge Fund","Investment Adviser","Microsoft","Newsletter","NYDFS","OCIE","Password","PII","Private Equity","Private Funds","Regulatory","Rules","SEC","Technology","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19708","url":"https:\/\/www.elteni.com\/insights\/?p=19708","name":"2026 May Newsletter - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19708#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19708#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2026\/05\/May-2026-Cover-Page-v2.png","datePublished":"2026-05-12T13:04:38+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19708#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19708"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19708#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2026\/05\/May-2026-Cover-Page-v2.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2026\/05\/May-2026-Cover-Page-v2.png","width":736,"height":934},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19708#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"2026 May Newsletter"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b","name":"dtuck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"dtuck"},"url":"https:\/\/www.elteni.com\/insights\/?author=3"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19708"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19708\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19713"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}