Whether you’re a small financial service provider or a major institution, if you’re doing business in the state of New York, you need to meet New York Department of Financial Services (NYDFS) regulations. Formerly known as 23 NYCRR 500, these standards ensure the security and resilience of technology-driven financial systems. Understanding them is crucial for safeguarding your operations and, most importantly, your customers.
Here’s a guide to NYDFS cybersecurity regulations, along with key compliance elements and practical steps to help you turn compliance into a strategic advantage.
The NYDFS Cybersecurity Regulation imposes requirements on all financial institutions operating under NYDFS licensure, registration, or charter. These requirements apply to organizations based in New York and those conducting financial business within the state, as well as third-party service providers who provide services to entities operating under NYDFS requirements.
On March 1, 2017, the NYDFS first established cybersecurity requirements for financial services companies. The regulation, commonly called “23 NYCRR Part 500” or “the Cybersecurity Regulation,” requires that affected organizations implement measures to ensure their systems and private data remain secure, unaltered, and accessible. An amendment on November 1, 2023 updated the standards to address more modern threats.
Failure to comply with these regulations can lead to hefty penalties. For example, in May 2019, First American Title Insurance Company faced a significant cybersecurity breach due to insufficient access controls in their EaglePro application, which exposed sensitive consumer data. This breach resulted in a $1 million penalty from NYDFS and mandated remedial measures to improve data security. This example shows the importance of adhering to NYDFS regulations to avoid costly fines, reputational damage, and compromised customer trust.
The NYCRR Part 500 aims to address the increasing complexity of cyberthreats and the risks that U.S. financial institutions encounter. The primary objectives are to protect sensitive customer data and ensure the integrity of technology systems.
As a service provider looking to meet the regulations, you must assess your cybersecurity risks and implement a comprehensive risk management plan. Incorporate the NYDFS’s minimum standards for data protection, which include:
The NYDFS Cybersecurity Regulation applies to any entity conducting business in New York that operates under a license, accreditation, or similar authorization under New York’s Banking Law, Insurance Law, or Financial Services Law. This includes:
Additionally, you may need out-of-state suppliers or third-party service providers to comply with certain parts of the regulation, especially if they have access to sensitive information.
Some smaller organizations may qualify for exemptions under specific circumstances. You may be exempt if you meet one or more of the following criteria:
Even if your organization qualifies for an exemption, you may still need to comply with core cybersecurity requirements to meet the NYFDS basic protection standards. These core requirements often include:
If you do need to meet 23 NYCRR Part 500, here’s what to do to ensure your readiness and compliance, according to the NYDFS:
Create and maintain a cybersecurity policy outlining how you plan to protect your information systems and nonpublic information. Include guidelines for data governance, access controls, and incident response, and make sure senior management reviews and approves the policy.
Conduct regular risk assessments to identify vulnerabilities in your information systems and understand potential threats. The landscape changes often, so regularly update these assessments to reflect any updates to operations, technology, or risks. The results give you the information needed to place appropriate security measures.
Implement technical security controls, like MFA for accessing sensitive systems, encryption to protect nonpublic information in transit and at rest, and continuous network monitoring, to keep systems safe. Annual penetration testing and regular vulnerability assessments also help you proactively identify and address security weaknesses.
Designate a CISO responsible for managing and overseeing your cybersecurity program. You can either fulfill this role internally or outsource it to a third-party provider.
The CISO must report annually to your board of directors or equivalent governing body regarding the status of the entity’s cybersecurity program. Reports should include any significant incidents for maximum visibility.
Develop an incident response plan to respond effectively to cybersecurity issues. This plan should detail how to mitigate harm, preserve data, and notify the NYDFS of significant events. Additionally, you should periodically review and update the plan based on past incidents to enhance its response capabilities continuously.
All personnel involved in cybersecurity management should receive adequate training. Conduct regular training sessions to inform teams about the latest cybersecurity threats, like phishing and social engineering attacks, and give updates on the best practices for defending against these risks. Well-trained personnel are your first line of defense in maintaining cybersecurity resilience.
Aligning with New York cybersecurity regulations can be challenging, but Legit Security’s services are here to help.
Legit Security provides tools and expertise to help you develop and implement a robust cybersecurity program, ensuring that your organization meets all regulatory requirements efficiently. In addition, Legit helps you map security guardrails to specific guidelines, like NYDFS. You’ll then benefit from real-time monitoring and alerts on compliance violation.
Schedule a demo to learn more.
*** This is a Security Bloggers Network syndicated blog from Legit Security Blog authored by Legit Security. Read the original post at: https://www.legitsecurity.com/blog/understanding-nydfs-cybersecurity-regulation