top of page

Small Business Cybersecurity Compliance in 2026: a Primer for New Jersey, New York, Pennsylvania, and Illinois Businesses

dnelson58
Aug 11
6 min read

For years, owners treated small business cybersecurity as a technical problem: install antivirus software, choose strong passwords, and hope the backup works. In 2026, that approach is (massively) incomplete. A cyber incident can trigger state data-breach notices, federal regulatory scrutiny, contract claims, litigation expense, business interruption, and lost customer goodwill.


The hard part is that no single U.S. cybersecurity law covers every business. The rules depend on what data the company holds, where affected people live, what industry the company serves, and what promises appear in its privacy policy and contracts. A New Jersey company with New York employees, Pennsylvania customers, and an Illinois fingerprint time clock may face several different legal regimes after one event.


Why Small Business Cybersecurity Compliance Matters Now

Cybercriminals target companies of every size. Small businesses can be attractive because they often hold payroll records, payment data, health information, customer credentials, or access to larger clients while operating with lean security teams. Common entry points remain ordinary: phishing, reused passwords, unpatched software, exposed remote access, and compromised vendors.


The Federal Trade Commission recommends multifactor authentication, encryption, regular backups, software updates, employee training, vendor oversight, and a written incident-response plan. Those controls are not merely technical housekeeping. They help a company show that it identified foreseeable risks and adopted safeguards appropriate to its operations.


The Federal Baseline: Reasonable Security and Truthful Promises

At the federal level, the FTC may challenge unfair or deceptive data-security practices under Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45(a). Risk increases when a business’s actual practices conflict with its privacy policy, customer statements, or contractual commitments.


Some sectors have specific duties. Financial institutions subject to the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, 16 C.F.R. Part 314, must maintain a written information-security program with administrative, technical, and physical protections.


Covered institutions must also report certain notification events involving at least 500 consumers’ unencrypted customer information to the FTC no later than 30 days after discovery. 16 C.F.R. § 314.4(j). Coverage is broader than banks and can include businesses such as certain lenders, finance companies, mortgage brokers, and tax-preparation firms.


New Jersey: Privacy Compliance Reaches Beyond a Privacy Policy

The New Jersey Data Privacy Act took effect January 15, 2025. It applies to controllers doing business in New Jersey or targeting New Jersey residents that meet either of two annual thresholds: processing personal data of at least 100,000 consumers, excluding data used solely to complete payment transactions; or processing at least 25,000 consumers’ data while receiving revenue or a discount from selling personal data. N.J.S.A. 56:8-166.5.


Covered businesses must provide a meaningful privacy notice, honor consumer rights, use contracts with processors, assess certain high-risk processing, minimize collection, and maintain reasonable administrative, technical, and physical security measures appropriate to the volume and nature of the data. N.J.S.A. 56:8-166.6, -166.12, and -166.16. The New Jersey Attorney General has exclusive enforcement authority; the statute does not create a private right of action. N.J.S.A. 56:8-166.19.


Two points are easy to miss. The Act protects consumers acting in an individual or household context and expressly excludes people acting in a commercial or employment context, so it governs customer data rather than employee data. N.J.S.A. 56:8-166.4. And the 30-day right to cure was temporary; it applied only until the first day of the 18th month following the effective date and has now expired, so the Division of Consumer Affairs is no longer required to give notice and an opportunity to fix a violation before enforcement. N.J.S.A. 56:8-166.17.


Many small businesses will fall below the numerical thresholds. Even then, breach-notification laws, sector rules, common-law duties, and customer contracts may still apply. Being exempt from one comprehensive privacy statute is not the same as being exempt from cybersecurity obligations.


New York: the SHIELD Act Requires Reasonable Safeguards

New York’s SHIELD Act requires businesses that own or license computerized data containing a New York resident’s private information to develop, implement, and maintain reasonable safeguards. The statute identifies administrative, technical, and physical measures, including risk assessment, employee training, service-provider oversight, attack detection, system testing, access controls, and secure disposal. N.Y. Gen. Bus. Law § 899-bb. The statute scales to size. A business with fewer than 50 employees, under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets satisfies the standard with safeguards appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the information it holds. N.Y. Gen. Bus. Law § 899-bb(1)(c), (2)(c). That is a scaled obligation, not an exemption. The SHIELD Act creates no private right of action; the Attorney General enforces it. N.Y. Gen. Bus. Law § 899-bb(2)(d) and (e).


This matters to companies outside New York. A New Jersey or Pennsylvania business may be covered because it holds private information about New York residents, even if it has no New York office. New York’s separate breach-notification provisions appear in N.Y. Gen. Bus. Law § 899-aa.


Pennsylvania: a Breach can Create Immediate Notice Duties

Pennsylvania’s Breach of Personal Information Notification Act generally requires notice without unreasonable delay when a qualifying breach affects Pennsylvania residents. 73 P.S. §§ 2301–2329. If notice must be given to more than 500 affected individuals in Pennsylvania, notice must be made concurrently to the Pennsylvania Office of Attorney General. Act § 3(c.1), added by Act 33 of 2024, effective September 26, 2024. Notice to nationwide consumer reporting agencies is also required when an entity notifies more than 500 people at one time. Act § 5.


Pennsylvania also requires twelve months of no-cost credit-monitoring services, and access to a credit report when the statutory conditions are met, if a breach involves a person’s name or first initial and last name combined with a Social Security number, bank-account number, driver’s-license number, or state ID number. Act § 5.4. Two conditions must both be met: the breach must involve those data elements, and the entity must be required to notify consumer reporting agencies under Act § 5. The requirement therefore does not attach to every security incident.


Illinois: Biometric Tools Carry Special Legal Risk

Illinois businesses using fingerprint time clocks, facial geometry, voiceprints, or similar tools should review the Biometric Information Privacy Act (BIPA). Before collecting covered biometric identifiers or information, a private entity generally must provide written disclosures and obtain a written release. It must also maintain a publicly available retention-and-destruction policy. 740 ILCS 14/15.


BIPA is especially significant because an aggrieved person may sue. The statute authorizes liquidated or actual damages, attorneys’ fees, costs, and other relief, subject to its terms. 740 ILCS 14/20. Exposure narrowed in 2024. Public Act 103-0769, effective August 2, 2024, provides that repeatedly collecting or disclosing the same biometric identifier from the same person by the same method is a single violation permitting at most one recovery, displacing the per-scan damages theory of Cothron v. White Castle System, Inc., 2023 IL 128004. The same amendment confirms that an electronic signature satisfies the written-release requirement. In April 2026 the U.S. Court of Appeals for the Seventh Circuit held the damages amendment applies retroactively to pending cases; Illinois state courts have not uniformly resolved that question. A vendor’s promise that a device is secure does not replace the employer’s obligation to understand what is collected, where it goes, who can access it, and when it is deleted.


A 10-step Cybersecurity Compliance Checklist for Small Businesses

  1. Inventory sensitive data. Identify what the business collects, where it is stored, who can access it, and which states’ residents are represented.

  2. Delete what is no longer needed. Data minimization reduces both attack surface and notification exposure.

  3. Require multifactor authentication. Prioritize email, banking, payroll, administrative, cloud, and remote-access accounts.

  4. Encrypt sensitive data. Protect information both in storage and during transmission, including backups and portable devices.

  5. Train employees regularly. Cover phishing, impersonation, fraudulent payment requests, password practices, and rapid reporting.

  6. Limit access by role. Remove stale accounts promptly and review privileged access on a schedule.

  7. Manage vendor risk. Put security, data-use, deletion, insurance, and incident-notice obligations into contracts, and verify performance.

  8. Maintain tested, isolated backups. A backup that has never been restored is only an assumption.

  9. Review cyber insurance. Confirm coverage for forensics, notice, business interruption, social engineering, ransomware, and regulatory response.

  10. Create and test an incident-response plan. Assign decision-makers, preserve evidence, involve counsel early, and map notice obligations by residence.


FAQs


Does every small business need a written cybersecurity plan?

Not every law uses the same words, but a written, risk-based plan is increasingly the most defensible approach. Some laws and contracts expressly require written programs; others evaluate whether safeguards were reasonable. Documentation also improves speed and consistency during an incident.


Do state privacy laws apply only where the business is located?

No. Coverage often turns on the residence of the person whose data is held, the consumers a business targets, or statutory processing thresholds. A company may need a multistate analysis even when it operates from one office.


Can an IT provider handle cybersecurity compliance alone?

No. An IT provider can implement controls, but leadership must decide what data to collect, which risks to accept, what vendors and contracts require, whether insurance is adequate, and how to respond to an incident. Those are legal and governance decisions.


The Bottom Line

Small business cybersecurity compliance is now part of responsible corporate governance. The goal is not perfect security; no system can guarantee that. The goal is to identify foreseeable risks, implement proportionate safeguards, honor legal and contractual promises, and be ready to respond quickly when something goes wrong. For businesses serving customers or employees in New Jersey, New York, Pennsylvania, or Illinois, that preparation should begin with a data inventory and a state-by-state legal review.


Legal note: This article provides general information and is not legal advice.



 
 
 

Comments


bottom of page