NYS Financial Services Department Proposes Cybersecurity Regulations

A&O Shearman
Contact

Shearman & Sterling LLP


The New York State Department of Financial Services proposed regulations requiring banks, insurance companies and other NYDFS-regulated institutions to promptly adopt a cybersecurity program and setting forth certain minimum standards with respect to such program. As part of the establishment of a cybersecurity program, each covered entity would be required to, among other things, adopt a written cybersecurity policy, designate a chief information security officer responsible for implementing, overseeing and enforcing its new program and policy and have policies and procedures designed to ensure the security of information systems and nonpublic information accessible to, or held by, third-parties.  Institutions would also be required to comply with additional requirements in order to protect the confidentiality, integrity and availability of information systems.  The proposed regulations would also require senior management of covered entities to file an annual certification confirming compliance with the regulations, beginning in January 2018.

The NYDFS notes that while these regulatory minimum standards are warranted, it is not the intention that such standards be overly prescriptive so that cybersecurity programs can match the relevant risks and keep pace with technological advances. The proposed regulations are subject to a 45-day notice and public comment period before their final issuance.

View proposed regulations.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© A&O Shearman

Written by:

A&O Shearman
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

A&O Shearman on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide