New York State Department of Financial Services (DFS) first-in-the-nation cybersecurity regulation to protect New York State from the ever-growing threat of cyber-attacks is now in effect. DFS Cybersecurity requires banks, insurance companies, and other financial services institutions regulated by DFS to establish and maintain a cybersecurity program designed to protect consumers and ensure the safety and soundness of New York State’s financial services industry.

“New Yorkers must be confident that the banks, insurance companies and the other financial institutions that they rely on are securely handling and establishing necessary protocols that ensure the security and privacy of their sensitive personal information,” said Superintendent Vullo. “This updated proposal allows an appropriate period of time for regulated entities to review the rule before it becomes final and make certain that their systems can effectively and efficiently meet the risks associated with cyber threats.” New York, Financial Services Superintendent Maria T. Vullo

..."Companies must disclose, within 72 hours, to the Secretary of DFS any cybersecurity event that either (1) must be disclosed to another government or self-regulating agency, or (2) has a “reasonable likelihood of materially harming any material part” of the normal operations of the company"

Corporate Governance: The DFS regulation requires engagement at the top of an organization. The regulation provides that senior management and boards of directors “must take” cyber security issues “seriously and be responsible for an organization’s cybersecurity program.”  This obligation starts with the creation of a cybersecurity policy—the framework for protecting a company’s IT network and most sensitive information.  Covered companies must also designate a Chief Information Security Officer (“CISO”), who must report to the board annually.  The cybersecurity policy must be in place, and the CISO designated, by August 28, 2017.

New York City

Main Menu