IS THERE ANY GOVERNMENT AGENCY NOT REGULATING CYBERSECURITY? This past week, New York's Attorney General announced a settlement with a healthcare provider requiring the firm to invest millions to better protect patient data, along with imposing hefty penalties for their historically lax security controls and vendor management. In this episode, David discusses how to address the very real exposure of third party risk, and offers some pointers on coverage for regulatory proceedings.