Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

New York Proposes Cybersecurity Rules for Financial Institutions

By Moorari Shah, A.J. Dhaliwal & Pouneh Almasi on August 26, 2022
Email this postTweet this postLike this postShare this post on LinkedIn
Labor-and-Employment-NY-Blog-Image-660x283

On July 29, the New York Department of Financial Services (NYDFS) released Draft Amendments to its Part 500 Cybersecurity Rules that would impose new obligations on financial institutions on reporting, governance, testing, access management, risk assessment, business continuity plans, among others.

If adopted, the new rules would require financial institutions to:

  • notify NYDFS within 72 hours of any unauthorized access to privileged accounts or detection of ransomware affecting a material part of its information system;
  • update risk assessment and obtain approval of its cybersecurity policy from its board of directors or senior governing body at least annually;
  • require its board to have sufficient expertise and knowledge, or be advised by persons with such expertise and knowledge, to exercise effective oversight of cyber risk and its cybersecurity personnel;
  • provide adequate independence and risk management authority to its chief information security officer, or CISO;
  • ensure timely reporting by the CISO to its senior governing body of material cybersecurity issues; and
  • utilize multi-factor authentication for all privileged accounts, except service accounts, and remote access to nonpublic information.

Putting It Into Practice: Financial institutions subject to the NYDFS regulations should continue to monitor the proposed rulemaking, which, if approved, would impose significant obligations on covered entities. Companies should also begin to evaluate the extent to which their cyber programs are compliant with these new requirements. After the proposed rules go into effect, covered entities will have 180 days to ensure compliance.

Photo of Moorari Shah Moorari Shah

Moorari Shah is a partner in the Finance and Bankruptcy Practice Group in the firm’s Los Angeles and San Francisco offices.

Read more about Moorari ShahEmail
Photo of A.J. Dhaliwal A.J. Dhaliwal

A.J. is a partner in the Finance and Bankruptcy Practice Group in the firm’s Washington, D.C. office.

Read more about A.J. DhaliwalEmail
Photo of Pouneh Almasi Pouneh Almasi

Pouneh Almasi is an associate in the Intellectual Property Practice Group in the firm’s San Francisco office.

Read more about Pouneh AlmasiEmail
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Consumer Finance and Fintech Blog
  • Organization:
    Sheppard, Mullin, Richter & Hampton LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo