Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

New York State Proposes Cybersecurity Regulation for Financial Services Institutions

By Harriet Pearson & Jasmeet Ahuja on September 23, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

shutterstock_71527090-300x194On September 12, New York Governor Andrew Cuomo broke new ground in proposing a state-level regulation that would require banks, insurance companies, and other financial services entities regulated by the New York Department of Financial Services (“NYDFS”) to establish formal cybersecurity programs.

Having a written cybersecurity policy and a designated chief information security officer responsible for overseeing a company’s cybersecurity program are only two of the requirements imposed by the proposed regulation. The proposed regulation specifies a number of minimum standards. For instance, a regulated entity’s written cybersecurity policy is expected to address, “at a minimum,” 14 different topic areas ranging from incident response to customer data privacy. It also requires that regulated entities notify NYDFS of any “material” breach 72 hours after identifying it and mandates that financial services institutions undergo an annual risk assessment and penetration testing.

The proposal comes in the wake of the SEC’s and other federal financial services regulators’ increased focus on the financial industry’s cybersecurity practices, including the SEC’s Office of Compliance Inspections and Examination’s ongoing “cyber initiative.” Prior to proposing the new regulation, the NYDFS signaled its intent and surveyed nearly 200 regulated financial services institutions to better understand the industry’s efforts to combat cybercrime. Those surveys culminated in “Reports on Cyber Security” for the banking sector, the insurance sector, and on third-party service providers within the banking sector, which ultimately informed NYDFS’s rulemaking process.

In its announcement, the Governor’s office explained that the minimum standards included in the proposed regulation are intended to “maintain[] flexibility” in the industry” so that the final rule does not limit industry innovation.” That being said, compliance with the regulation, once it is finalized, would at the least require regulated entities to take steps to confirm that their current cybersecurity programs align with this new layer of requirements.

The proposed regulation is subject to a 45-day notice and public comment period once it is published to the New York State Register.

Photo of Harriet Pearson Harriet Pearson
Read more about Harriet PearsonEmail
  • Posted in:
    Banking, Finance and Securities, Privacy and Cybersecurity
  • Blog:
    Global Media and Communications Watch
  • Organization:
    Hogan Lovells
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo