{"id":1201,"date":"2017-06-27T09:59:49","date_gmt":"2017-06-27T06:59:49","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=1201"},"modified":"2026-04-07T14:12:28","modified_gmt":"2026-04-07T11:12:28","slug":"an-overview-of-the-nydfs-cybersecurity-regulation","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/an-overview-of-the-nydfs-cybersecurity-regulation\/","title":{"rendered":"An Overview of The\u00a0NYDFS Cybersecurity Regulation"},"content":{"rendered":"<p><em>The NYDFS cybersecurity regulation requires financial institutions to implement risk-based security programs to protect sensitive data and systems. Key requirements include encryption, access controls, incident response, employee training, and breach reporting within 72 hours. Organizations must also ensure third-party compliance and submit annual certifications.<\/em><\/p>\n<h2>What is NYFDS?<\/h2>\n<p>Last year, New York became the 1st state that proposed cyber security regulations for the financial organisations. This year, on March 1st, the New York Department of Financial Services (NYDFS) Cybersecurity Requirements came into effect.<\/p>\n<p>This new regulation requires financial institutions like banks and insurance companies, and others\u00a0to establish and maintain cybersecurity programs in order to protect consumers\u2019 private data.\u00a0 Financial organisations have an 180-days transition period to enhance their\u00a0infosec implementation\u00a0in\u00a0order to\u00a0protect\u00a0their Information Systems and Nonpublic Information (NPI). By August 28, 2017, must have a cybersecurity program in place and starting February 15, 2018,\u00a0they\u00a0must be able to demonstrate they are compliant by submitting annual\u00a0Certifications\u00a0of\u00a0Compliance.<\/p>\n<h2>What is\u00a0the\u00a0Information System?<\/h2>\n<p>The\u00a0<a href=\"http:\/\/www.dfs.ny.gov\/legal\/regulations\/proposed\/rp500t.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Information System<\/a> represents\u00a0\u00a0\u201ca discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information, as well as any specialized system such as industrial\/process controls systems, telephone switching, and private branch exchange systems, and environmental control systems.\u201d<br \/>\nBasically, the NYDFS uses the Information System\u00a0to express the sensitive data as well as the systems that must be safeguarded against cybercriminals and other cyber security threats.<\/p>\n<h2>What is Nonpublic Information (NPI)?<\/h2>\n<p><a href=\"http:\/\/www.dfs.ny.gov\/legal\/regulations\/proposed\/rp500t.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Nonpublic Information<\/a>\u00a0means \u201call electronic information that is not Publicly Available Information\u00a0and\u00a0contains:<\/p>\n<ol>\n<li>Business related information<\/li>\n<li>Information concerning an individual\u00a0that can be used to identify him\/her &#8211;\u00a0name, number, personal mark, or other identifier, in combination with social security number, drivers\u2019 license number or non-driver identification card number, account number, credit or debit card number, any security code, access code or password that would permit access to an individual\u2019s financial account,\u00a0or biometric records.<\/li>\n<li>Any information or data, except age or gender,\u00a0related to the physical, mental or behavioral health of any individual or his\/her family collected and processed by a health care provider or derived from a health care institution.<\/li>\n<\/ol>\n<h2>Whom it covers?<\/h2>\n<p>The NYDFS rule focuses on protecting the data of customers of financial institutions with branches in NY, third-party suppliers, like banks, insurance companies, brokers, mortgage lenders, investment companies, and others.<br \/>\nAccording to the\u00a0<a href=\"http:\/\/www.dfs.ny.gov\/reportpub\/annual\/dfs_annualrpt_2013.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">NYDFS website<\/a>, the new rule supervises \u201cnearly 1,900 banking and other financial institutions with assets of more than $2.9 trillion\u201d and \u201call insurance companies that do business in New York,\u201d which includes \u201cnearly 1,700 insurance companies with assets exceeding $4.2 trillion.\u201d<br \/>\nThe proposed regulations will reduce the risk of data breaches caused by insider threats, ignorance or unintentional data leakage.<\/p>\n<h2>What are the key\u00a0points?<\/h2>\n<p>NYDFS regulations require Covered Entities to:<\/p>\n<ul>\n<li>Set a robust cybersecurity program<\/li>\n<li>Perform\u00a0regular cybersecurity awareness training for all employees<\/li>\n<li>Set risk-based minimum standards for technology systems including; <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a>, encryption, access controls, and penetration testing<\/li>\n<li>Establish an incident response plan<\/li>\n<li>Require identification and documentation of material deficiencies, remediation plans and annual certifications of regulatory compliance<\/li>\n<li>Protect data in transit and at rest; as a protective measure\u00a0encryption\u00a0is specified\u00a0as well as\u00a0alternative solutions\u00a0approved by the CISO\u00a0in case encryption is not feasible<\/li>\n<li>Notify\u00a0the\u00a0NYDFS when a breach occurs no later than 72 hours<\/li>\n<li>Engage a Chief Information Security Officer internally or through a third-party provider\u00a0to conduct the cyber security program<\/li>\n<li>Make sure that third party organizations having access to their Information Systems also adhere to the NYDFS regulation<\/li>\n<\/ul>\n<p>Across the world, new cybersecurity regulations\u00a0emerge\u00a0and\u00a0others are strengthened, demonstrating once again that cybersecurity is becoming\u00a0a\u00a0pressing in the\u00a0financial,\u00a0economic, political or social area.\u00a0Some organizations are forced to step up their game,\u00a0many of them must catch up years&#8217; worth of work in a few months\u00a0and others are just formalizing what they have already implemented. A risk-based approach is encouraged by the NYDFS regulation,\u00a0the risk assessment providing the basis for actions to be taken to address revealed vulnerabilities.<\/p>\n<p><a href=\"https:\/\/www.endpointprotector.com\/solutions\/enforced-encryption\" target=\"_blank\" rel=\"noopener noreferrer\">Encryption<\/a>\u00a0is assigned great importance and protecting data in transit and <a href=\"https:\/\/www.endpointprotector.com\/blog\/is-your-data-at-rest-safe\/\">data at rest<\/a> is also stressed out, making\u00a0<a href=\"https:\/\/www.endpointprotector.com\/solutions\/data-loss-prevention\" target=\"_blank\" rel=\"noopener noreferrer\">Data Loss Prevention\u00a0software<\/a> one of the relevant solutions to be enforced. For more information about the NYDFS regulation, visit the <a href=\"http:\/\/www.dfs.ny.gov\/about\/cybersecurity.htm\" target=\"_blank\" rel=\"noopener noreferrer\">DFS\u00a0<\/a>website and their\u00a0<a href=\"http:\/\/www.dfs.ny.gov\/about\/cybersecurity_faqs.htm\" target=\"_blank\" rel=\"noopener noreferrer\">FAQ<\/a>\u00a0section.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The NYDFS cybersecurity regulation requires financial institutions to implement risk-based security programs to protect sensitive data and systems. Key requirements include encryption, access controls, incident response, employee training, and breach reporting within 72 hours. Organizations must also ensure third-party compliance and submit annual certifications. What is NYFDS? Last year, New York became the 1st state &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/an-overview-of-the-nydfs-cybersecurity-regulation\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;An Overview of The\u00a0NYDFS Cybersecurity Regulation&#8221;<\/span><\/a><\/p>\n","protected":false},"author":8,"featured_media":1202,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[162,115],"tags":[],"class_list":["post-1201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-financial-institutions","category-compliance","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=1201"}],"version-history":[{"count":18,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1201\/revisions"}],"predecessor-version":[{"id":8317,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1201\/revisions\/8317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/1202"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=1201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=1201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=1201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}