{"data":{"id":"us-ky/krs-304.3-758","jurisdiction":"us-ky","citation":"KRS 304.3-758","heading":"Cybersecurity event investigation.","body":"(1) (a) If a licensee learns that a cybersecurity event has or may have occurred, the\nlicensee, or an outside vendor or service provider designated to act on behalf\nof the licensee, shall conduct a prompt investigation.\n(b) During an investigation required under this subsection, the licensee, or outside\nvendor or service provider designated to act on behalf of the licensee, shall, at\na minimum:\n1. Determine whether a cybersecurity event has occurred;\n2. Assess the nature and scope of the cybersecurity event;\n3. Identify any nonpublic information that may have been involved in the\ncybersecurity event; and\n4. Perform or oversee reasonable measures to restore the security of the\ninformation systems compromised in the cybersecurity event in order to\nprevent further unau thorized acquisition, release, or use of nonpublic\ninformation in the licensee's possession, custody, or control.\n(2) If a licensee learns that a cybersecurity event has or may have occurred in a system\nmaintained by a third-party service provider, the licensee shall complete, or confirm\nand document that the third-party service provider has completed, the steps listed in\nsubsection (1)(b) of this section.\n(3) Each licensee shall maintain, and produce upon demand of the commissioner,\nrecords concerning all cybersecurity events for a period of at least five (5) years\nfrom the date of the cybersecurity event.","path":[],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=53295","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:57:38Z","sha256":"eed7bf065899357076b9b16decda3806ed99769f66d0e7d950d53afb675ecfb5","source_id":"us-ky","stale":false,"prev":"us-ky/krs-304.3-756","next":"us-ky/krs-304.3-760"},"notice":"GroundRules: Original legal text. Not legal advice."}
