Skip to Primary Navigation

New York’s new guidance on third-party service provider cyber risk

Image of a laptop computer screen.
Photo: Lisa Maree Williams/Getty Images

The guidance does not impose new requirements; it helps NYDFS-regulated institutions meet existing obligations in light of evolving vendor-related cybersecurity risks.

The New York Department of Financial Services has issued new guidance on cybersecurity risks connected to third-party service providers.

Acting Superintendent Kaitlin Asrow announced it, highlighting the risks related to entities becoming increasingly reliant on third-party service providers (TPSPs).

She said the guidance builds on NYDFS’s ongoing efforts to protect

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience