In March 2017, the New York Department of Financial Services (NYDFS) cybersecurity regulations—known as 23 NYCRR Part 500—went into effect. According to the regulation, “any Person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law” is considered a covered entity and must comply.
The new regulations acknowledge that the threat posed by bad actors and cybercriminals over the past decade has significantly increased. In the early 2000s, a significant number of state laws were passed which, among other things, required companies to disclose a data breach to consumers if their data or personally-identifiable information (PII) was compromised. The new NYDFS cybersecurity regulations indicate a new wave of regulations that now require certain cybersecurity measures to be put into place so breaches are less likely to occur. 23 NYCRR Part 500 signals a shift from regulating breach disclosure to regulating the implementation of appropriate security controls.
Noncompliance with 23 NYCRR Part 500 can lead to fines or program reviews, but the scope of those consequences are not fully known. It’s important for your organization to thoroughly review and consider the regulation in full—but there are five high-level requirements of the NYDFS regulation you should know about:
5 Highlights Of The NYDFS Cybersecurity Regulations
1. Covered entities are required to have a cybersecurity program.
According to section 500.02 (on page 3), “Each Covered Entity shall maintain a cybersecurity program designed to protect the confidentiality, integrity and availability of the Covered Entity’s Information Systems.”
In addition to this overarching requirement, covered entities must employ a chief information security officer (CISO) who must report to the board, and senior management must review and approve the cybersecurity policies.
2. Covered entities are required to have a third-party service provider risk management program.
According to section 500.11 (on page 7), “Each Covered Entity shall implement written policies and procedures designed to ensure the security of Information Systems and Nonpublic Information that are accessible to, or held by, Third Party Service Providers.”
As part of this requirement, covered entities must perform due diligence on all third-party vendors and periodically assess their security. Continuous monitoring programs like Bitsight Security Ratings make the vendor risk management process much simpler.