The New York Department of Financial Services Cybersecurity Regulation (23 NYCRR Part 500) comes into force today, one of the most prescriptive cyber security regulations in the United States.
Key points
- Covered entities must maintain a risk-based cybersecurity programme and policy.
- A Chief Information Security Officer must be designated and report to the board.
- Cybersecurity events must be notified to the regulator within 72 hours.
- Requirements such as penetration testing, MFA, encryption and third-party security policies are phased in over two years.
UK firms regulated in New York, and service providers to New York financial institutions, should expect detailed security requirements in contracts.
Source: 23 NYCRR Part 500 Cybersecurity Regulation (NYDFS)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.