New York DFS Cybersecurity Rules Take Effect March 1

The New York Department of Financial Services (“DFS”) recently issued a revised rules proposal that will add its own cybersecurity requirements to those already in place for banks, insurance companies and other financial services companies. While the proposed rules would only be applicable to financial firms licensed by the New York DFS, they reveal that state regulators are just as concerned about the growing risk of cybersecurity breaches. New York’s proposed rules are the first of their kind in the United States for a state regulator to issue, and may portend a sign of things to come.

Due in part to the nature and volume of the personally identifiable information (PII) they maintain, and partially attributable to the name recognition of some high-profile banks and financial institutions, these firms are increasingly finding themselves at the receiving end of targeted and sophisticated cyber-attacks.

As proposed, 23 NYCRR 500 (“Cybersecurity Requirements for Financial Services Companies”) will require financial institutions under the jurisdiction of the DFS “to establish and maintain a cybersecurity program designed to protect consumers and ensure the safety and soundness of New York State’s financial services industry.”

The Cyber Rules will become effective on March 1, 2017, and covered entities will be required to submit annual certificates of compliance to the DFS beginning February 15, 2018.

Take Action Now to Ensure DFS Compliance

Ascendant creates tailored and risk-based policies and procedures for firms designed to address the DFS Cybersecurity Regulation to include the following areas to the extent applicable to the Company’s operations:

  • Information Security
  • Data Governance and Classification
  • Asset Inventory and Device Management
  • Access Controls and Identity Management
  • Business Continuity and Disaster Recovery Planning and Resources
  • Systems Operations and Availability Concerns
  • Systems and Network Security
  • Systems and Network Monitoring
  • Systems and Application Development and Quality Assurance
  • Physical Security and Environmental Controls
  • Customer Data Privacy
  • Vendor and Third-Party Service Provider Management
  • Risk Assessment
  • Incident Response

For more information about how we can help you reach compliance with New York’s new DFS Cybersecurity requirements, contact us.

Related Content

Latest Content

Coming to America – California Adopts GDPR-Like Privacy Regulation

After a number of firms struggled last year to get their marketing and information systems into compliance with the EU’s General Data Protection Regulation (GDPR), advisers to U.S. clients will soon be facing similar requirements on the home front.  On the heels of the Cambridge Analytica scandal, California enacted the California Consumer Privacy Act of … Continued

SEC and FINRA 2019 Examination Priorities

The SEC and FINRA have recently released their examination priorities for 2019. These releases provide insight into regulatory priorities and serve as guidance for a firm in evaluating its compliance program. We will discuss topics covered in these releases, including: Protecting retail investors Fees and expenses Disclosure Conflicts of interest Suitability Protecting senior investors Trading … Continued

SEC Reopened After 35-Day Government Shutdown

SEC Chairman Jay Clayton announced on Saturday, January 26 that with an agreement reached to end the government shutdown, the “Commission has resumed normal staffing levels and is returning to normal operations.” In total, about 94% of the commission’s approximately 4,400 employees had been furloughed during the 35-day shutdown, according to its operations plan. In a … Continued

FINRA Rolls Out New Central Registration Depository Functionality; Annual Verification Deadline Nears

FINRA first introduced enhancements to the Central Registration Depository (“CRD”) on October 1, 2018, which were rolled out in support of FINRA’s restructured qualification examination program as well as the adoption of consolidated FINRA registration rules. The new enhancements were intended to also more easily assist member firms with satisfying their reporting and compliance obligations. … Continued

SEC’s Latest Risk Alert Focuses on Electronic Communications

The SEC’s most recent risk alert, “Observations from Investment Adviser Examinations Relating to Electronic Messaging,” issued on December 14, 2019, focuses on the use and maintenance of electronic communications for business purposes. The purpose of the alert is to remind advisers of their obligations related to personal use of electronic messaging and the requirements for … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.