In a conversation last month with one of our good customers, the subject of NYDFS Cybersecurity Regulations came up with a question of potential service opportunities for our customers. It seemed that changes in the regulations, especially for the SMB marketplace, might require additional expertise or bandwidth that typical SMB organizations either cannot or choose not to employ. Whether you can hire the expertise or not to address their requirements, NYDFS will still hold companies accountable that fall under their regulation guidelines.
Our team has looked at the impact for our clients who are covered entities including NY insurance companies, banks, and other regulated financial service institutions. They are all aware that the NYDFS established the 23 NYCRR Part 500 (Cybersecurity Rules) to combat the ever-growing threat posed to information and financial systems by nation-states, terrorist organizations and independent criminal actors.
It is the changes that are bringing a challenge and opportunity to our customers, as well as cybersecurity service providers. Not all the changes directly impact smaller firms that are covered entities, but there may be a downstream effect to supplier companies of covered entities via third party risk management programs. These firms may be asked for compliance to DYDFS to share accountability to the regulators.
What NYDFS is requiring is good cybersecurity hygiene; things that will make your cybersecurity program a bit better. All covered entities as well as third parties who support those entities should review your Information Security Program against the updated requirements. Covered entities should make sure your Board has cyber expertise if they do not already.
The requirements for Class A covered entities, have increased quite a bit – however large organizations in the financial service industry should be able to comply with these new requirements and should be complying with most of new requirements already. Class A organizations will likely be spending more money on outside services for assessments.
Here is a link that highlights the changes, underlined in this pdf:
Click here for the full list of changes
If you want to learn more, or dive deeper into the NYDFS Cybersecurity Regulation impact on your company, please reach back to SEVN-X. Our goal is to help you Achieve Better Cybersecurity. We are happy to help!