If the licensee learns that a cybersecurity event has or may have occurred, the licensee, or an outside vendor or service provider designated to act on behalf of the licensee, shall conduct a prompt investigation.
During the investigation, the licensee, or an outside vendor or service provider designated to act on behalf of the licensee, shall, at a minimum and to the extent possible:
If the licensee learns that a cybersecurity event has or may have occurred in a system maintained by a third-party service provider, the licensee will complete the steps listed in subdivision 2 or confirm and document that the third-party service provider has completed those steps.
The licensee shall maintain records concerning all cybersecurity events for a period of at least five years from the date of the cybersecurity event and shall produce those records upon demand of the commissioner.
Minn. Stat. § 60A.9852