On Nov. 9, 2022, the New York Department of Financial Services (NYDFS) issued a proposed second amendment to its 2017 cybersecurity regulation for financial service companies.[1] In July 2022, NYDFS issued a draft version of the changes, but the current amendment has significant changes. Most of the proposed changes will take effect 180 days after final regulation adoption, likely soon after the comment period closes on Jan. 9, 2023, making most new regulations effective after July 8, 2023.[2]
Go-To Guide:
- Detailed requirements of NYDFS’ proposed amendments to the cybersecurity regulation;
- Heightened requirements for larger financial services companies (“Class A Companies”);
- Changes to limited exemptions.
***
The proposed amendments move beyond administrative and technical safeguards to granular regulations on cybersecurity governance and risk management. Additionally, NYDFS places stricter requirements, detailed below, on larger financial services companies, “Class A Companies.” Class A Companies are those with greater than or equal to $20 million in New York gross annual revenue in the last two fiscal years, and either: greater than 2,000 employees (including affiliate’s employees), or greater than $1 billion in gross annual revenue (including affiliate revenue) globally in the last two fiscal years. With the new regulations expected to take effect in 2023 (potentially as early as March for sections with a 30-day implementation timeline), companies should begin planning and budgeting for the changes now to avoid legal compliance risks.
New Requirements for All Covered Entities:
New Requirements for Class A Companies:
- Audits and Risk Assessments. Conduct an independent audit (using external auditors) of the cybersecurity program at least annually. (500.2(c)) Use external experts to conduct a risk assessment at least every three years. (500.9(d))
- Access Management.[10] Implement privileged access management solution and an automated method of blocking commonly used passwords. (500.7(b))
- Training and Monitoring.[11] Implement endpoint detection and response solution to monitor anomalous activity (including lateral movement), and a solution centralizing logging and security event alerting. (500.14(b))
The proposed amendments also provide changes to the limited exemptions for small companies. An entity (including affiliates) with either fewer than 20 employees (including independent contractors) or less than $15 million in year-end total assets, is exempt from the following regulation sections: 500.4 (CISO requirements), 500.5 (penetration testing and vulnerability assessments), 500.6 (audit trails), 500.8 (application security), 500.10 (cybersecurity personnel), 500.14 (training and monitoring), 500.15 (encryption), and 500.16 (BCDR & IRP Plans).
NYDFS has taken note of the comments submitted to the original draft changes published in July; while they retained many of the proposed changes, the new version provides clarifications, relaxes some of the implementation timelines, and removes certain requirements for Class A Companies (such as weekly vulnerability scans and requiring password vaults for privileged access).
Learn about GT’s Tabletops/Incident Response Training.
[1] 23 NYCRR § 500 et seq.
[2] The amendment’s 60-day comment period is open to public feedback until 5 pm EST on Monday, Jan. 9, 2023. Comments must be submitted in writing either via email or by mail to the New York State Department of Financial Services c/o Cybersecurity Division, Attn: Joanne Berman, One State Street, Floor 19, New York, NY, 10004. No special form is required.
[3] Covered entities have 18 months from the amendment’s effective date to implement automated scans of information systems per 500.5(a)(2).
[4] Covered entities have 18 months from the amendment’s effective date to implement MFA per 500.12(b).
[5] Covered entities have two years from the amendment’s effective date to implement the asset management and data inventory requirements per 500.13(a).
[6] Covered entities have 18 months from the amendment’s effective date to implement protections against malicious code per 500.14(a)(2).
[7] Covered entities have one year from the amendment’s effective date to implement network isolated backups per 500.16(e).
[8] Covered entities have 30 days from the amendment’s effective date to implement notification requirements per 500.17.
[9] Covered entities have 30 days from the amendment’s effective date to implement notification requirements per 500.17.
[10] Class A companies have 18 months from the amendment’s effective date to implement changes to passwords per 500.7(b).
[11] Class A companies have 18 months from the amendment’s effective date to implement endpoint and centralized logging solutions per 500.14(b).
