State regulators have ramped up their questions following cybersecurity incidents. After providing notice of a breach, companies should expect an extensive dialogue with AGs, in which inquiries are made about data minimization and retention, access controls, vendor due diligence, procedures for logging and patching, and risk-based resilience planning. This second article in a three-part series on state cybersecurity law and enforcement, published in conjunction with IAPP’s Cybersecurity Law Center, provides practical recommendations for building readiness for regulatory investigation and enforcement. It includes commentary from experts at BakerHostetler, Debevoise, Morrison & Foerster, Paul Hastings, Ropes & Gray, and Shook, Hardy & Bacon. Part one analyzed changes to the state law toolkit for regulators and examined key enforcement actions. The final installment will cover important reasonable security and business resilience steps and will discuss the first impacts of AI on state cybersecurity enforcement. See “Practical Compliance Implications From NYDFS’ Healthplex Settlement” (Sep. 17, 2025).