Major amendments to the New York Department of Financial Services Cybersecurity Regulation (23 NYCRR Part 500) take effect today.
Key points
- Senior governing bodies must have sufficient understanding of cyber risk and oversee the programme.
- A new category of larger “Class A” companies faces additional requirements, including independent audits.
- Ransom payments must be reported within 24 hours, with a written explanation within 30 days.
- Requirements such as MFA for all remote access and asset inventories are phased in to November 2025.
UK suppliers to New York financial institutions should expect stronger oversight and incident notification terms in their contracts.
Source: 23 NYCRR Part 500 Cybersecurity Regulation (NYDFS)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.