Testing and Assessments: The regulation requires companies to conduct a number of cybersecurity tests and analyses. First and foremost, companies will have to perform a “risk assessment.” The risk assessment must “evaluate and categorize risks,” evaluate the integrity and confidentiality of the company’s information systems and non-public information and develop a process to mitigate any identified risks. 
Companies must also conduct annual penetration testing and bi-annual vulnerability testing. Each of these tests and assessments must be conducted by March 1, 2018.
Day-to-Day Requirements: The regulation’s day-to-day and technical requirements are substantial and detailed. Among others, companies must develop access controls for their information systems, ensure the physical security of computer systems, encrypt or protect personally identifiable information, perform reviews of in-house and externally created applications, train employees, and build an audit trail system. The timeline to ensure compliance with these rules ranges from one year to eighteen months.
Third-Party Rules: The new regulation not only contains extensive requirements for covered entities but also regulates third-party vendors with access to an institution’s IT network or non-public information. Covered banks and insurers are required to develop and implement written policies and procedures to ensure the security of IT systems or non-public information that can be accessed by their vendors. At a minimum, these policies must identify the risks from third-party access, impose minimum cybersecurity practices for vendors, and create a due-diligence process for evaluating those vendors. Covered entities will have two years to satisfy these extensive requirements.
Notification Requirements: Finally, the new regulation includes a mandatory notification process for any material cybersecurity event. Within 72 hours, companies must report to the DFS a cybersecurity event that has a “reasonable likelihood” of “materially harming” the company or that must be reported to another government or self-regulating agency. In addition, companies—through a certification from either the board or a senior officer—must annually attest to their compliance with the DFS regulation.
The final regulation also provides some relief from the regulation’s strict requirements for a number of entities including:
- Companies that earn less than $5 million in gross revenue in New York (in each of the past three years), that have less than $10 million in year-end total assets from all operations, or that have fewer than ten employees in New York (including independent contractors) are exempt from a number of the regulation’s provisions.
- Companies that do not have information systems and access to nonpublic information are, likewise, exempt from a number of the DFS requirements.
- Captive insurance companies—both pure and group captive insurers—are also exempt from many of the DFS requirements.
- And, subject to certain limitations, the regulation exempts a small number of entities from the regulation, including Rule 125 certified and accredited reinsurers.
On Dec. 28, 2016, the New York State Department of Financial Services (“NYDFS”) issued revisions to its proposed regulation that would impose new, rigorous cybersecurity requirements on banks, consumer lenders, money transmitters, insurance companies and certain other financial service providers (each a “Covered Entity”) regulated by the NYDFS (the “Proposed Regulation”). The Proposed Regulation’s effective date was delayed two months, from Jan. 1, 2017 to March 1, 2017. In the meantime, a new 30-day public comment period will run until Jan. 27, 2017.
Even as revised, the Proposed Regulation still exceeds what other regulators have suggested, much less required, and given the scope and footprint of many New York financial institutions, the impact of the Proposed Regulation will likely far exceed the state of New York. However, the NYDFS did make several significant modifications, mostly in response to industry concerns. This post focuses on those changes. For more information on the aspects of the Proposed Regulation that remain unchanged, please refer to our Sept. 15, 2016 post on the original version.
(As summarized by Harvard Business School)

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics