Data Destruction

The Regulation required Covered Entities to securely dispose of Nonpublic Information when it was no longer necessary for the provision of the products or services to which such information relates, except when maintenance of the information was required by law. A number of commentators asserted that this exception was too narrow, as it did not take into account other legitimate business purposes for which data may ordinarily be retained. In response, the NYDFS modified the Proposed Regulation so that the permissibility of data retention is not tied solely to the specific product or service at issue. Instead, data may be retained whenever necessary “for business operations or for other legitimate business purposes.” As revised, the data destruction requirement now also includes a feasibility exception. Secure disposal need not occur “where targeted disposal is not reasonably feasible due to the manner in which the information is maintained.”

Third Party Service Providers

The Regulation required Covered Entities to (a) implement written policies and procures to ensure the security of systems and Nonpublic Information accessible to, or held by, third parties with which they do business (“Third Party Service Providers”); and (b) negotiate for certain “preferred provisions” to be included in contracts with Third Party Service Providers. While the Proposed Regulation still retains the requirement to maintain written policies and procedures, it now makes clear that they should be based on the Covered Entity’s Risk Assessment. For example, whereas previously the Proposed Regulation required a Covered Entity to conduct an annual assessment of each of its Third-Party Service Providers and the adequacy of their cybersecurity practices, now such assessments are only required based on the risk a particular Third-Party Service Provider presents.

Moreover, in response to the concern expressed by numerous Covered Entities that they would not always have sufficient leverage to force Third Party Service Providers to accept the preferred provisions, the NYDFS modified the requirement to permit the use of “relevant guidelines for due diligence” instead of actual contractual provisions. Further, the NYDFS eliminated a preferred provision that seemed to suggest that Covered Entities were required to conduct cybersecurity audits of all Third-Party Service Providers. Significantly, the NYDFS also amended a preferred provision that would have previously required Third Party Service Providers to warrant that no viruses, trap doors, time bombs and other security threats existed. As revised, the Proposed Regulation simply advises Covered Entities to obtain “representations and warranties addressing the Third-Party Service Provider’s cybersecurity policies and procedures that relate to the security” of the Covered Entity.

Cybersecurity Event Reporting

The Rule required that all “Cybersecurity Events” that have “a reasonable likelihood of materially affecting the normal operation of the Covered Entity or that affects Nonpublic Information” (including any “actual or potential unauthorized tampering with, or access to or use of, Nonpublic Information)” be reported to the superintendent (“Superintendent”) of the NYDFS within 72 hours. Many commentators understandably complained that the requirement was overly broad and, therefore, would result in many reports that were of little value. In addition, many commentators asserted that the 72-hour time frame was too short and would not afford a Covered Entity enough time to gather necessary information prior to reporting.

The Regulation raises Covered Entities’ notification obligations beyond what existing law requires, but it reduces their obligations as compared to the original draft. The requirement that the superintendent be notified “in no event later than 72 hours” remains, but that time period now begins only once the Covered Entity determines that a Cybersecurity Event with “a reasonable likelihood of materially harming any material part of the normal operations of the Covered Entity” occurred (unless notice is otherwise required to a government body, self-regulatory agency or other supervisory body, in which case the Covered Entity must notify the NYDFS within 72 hours of the determination that the Cybersecurity Event occurred).

New Exemptions

The NYDFS added several new exemptions or partial exemption. If a Covered Entity has: (1) fewer than 10 employees or independent contractors; (2) less than $5 million in gross annual revenue each of the past three fiscal years; or (3) less than $10 million in it and its affiliates’ GAAP year-end total assets, it is exempt from the CISO, penetration testing, audit trail, application development, cybersecurity personnel, multifactor identification, training, encryption and incident response plan obligations of the Proposed Regulation. Moreover, a Covered Entity need not adopt its own program if it is an “employee, agent, representative, or designee” of a Covered Entity and is covered under that Covered Entity’s program.

Finally, a Covered Entity that does not directly or indirectly maintain “Information Systems” or have Nonpublic Information is exempt from most requirements of the Proposed Regulation. It must still conduct a risk assessment, develop a written Third-Party Service Provider Security Policy, abide by the data retention requirement and provide notice to the Superintendent under the Proposed Regulation.

Any Covered Entity that wishes to benefit from an exemption must file a “Notice of Exemption” with the Superintendent.

Main Menu