The New York State Department of Financial Services (NYDFS) has recently implemented the Second Amendment to 23 NYCRR 500, a regulation that lays down cybersecurity requirements for financial services companies. This amendment reflects the ever-evolving cybersecurity landscape and the increasing need for a robust cybersecurity program in the financial sector.
Revised Definitions and Classifications: The amendment introduces new definitions and modifies existing ones to provide greater clarity. The new regulations add three key definitions, among other additions and modifications.
3 Types of Entities: As stated above, NYDFS has added a new organization classification; this must adhere to all the regulation requirements. The other two types of organizations are Standard Covered Entities and Exempt organizations. Standard Covered Entities are required to adhere to every regulation, barring certain additions for just Class A organizations.
Enhanced Cybersecurity Program Requirements: Covered entities are now mandated to have a more comprehensive cybersecurity program. This includes a detailed risk assessment and implementing core cybersecurity functions like identifying and assessing cybersecurity risks, defending against unauthorized access, detecting cybersecurity events, and responding to and recovering from these events.
Vulnerability Management: The amendment requires covered entities to develop and implement written policies and procedures for vulnerability management, aiming to assess and maintain the effectiveness of the cybersecurity program. NYDFS more clearly defines that a Vulnerability Management program must include:
Access Privileges and Management: There are stricter controls on user access privileges, with an emphasis on limiting these privileges to what is necessary for job performance and regularly reviewing and updating these privileges.
Multi-factor Authentication and Encryption: The amendment specifies more rigorous multi-factor authentication and encryption requirements, ensuring better protection of nonpublic information.
Incident Response and Business Continuity Management: Covered entities must establish written plans containing proactive measures for managing cybersecurity events and ensuring operational resilience, including incident response, business continuity, and disaster recovery plans.
Notices and Compliance Certifications: The amendment outlines the requirements for how to notify the superintendent of cybersecurity incidents and the annual submission of compliance certifications.
The changes went into effect on November 1, 2023, with a progressive implementation timeline that starts on April 29, 2024 and requires full compliance with all newly amended regulations by November 1, 2025.
The changes brought by this amendment emphasize a more proactive and structured approach to managing cybersecurity risks. Financial services companies must:
The Second Amendment to 23 NYCRR 500 marks a significant step forward in strengthening cybersecurity standards in the New York financial sector. It will surely have ripple effects on compliance and regulations across other industries as well. It underscores the importance of having strong cybersecurity measures in an increasingly risky world. Financial institutions need to plan for compliance with the new regulations in the phased implementation program delivered by NYDFS based on their covered entity type (Class A, Standard, Limited Exemption). By focusing on compliance, covered entities will align their cybersecurity strategies with these new requirements to ensure compliance and protect their information systems and client information.
For organizations looking for assistance in complying with these newly amended regulations, RM Cyber offers a range of services, including vulnerability management and penetration testing, Cybersecurity program buildout, managed security services, and virtual CISO services. Our expertise can guide your organization through the complexities of adhering to these newly enhanced cybersecurity standards, ensuring that your cybersecurity measures are not only compliant but also effective and resilient in this ever-evolving cyber landscape. Contact info@richeymay.com to learn more.