Skip to Primary Navigation

NYDFS updates cybersecurity requirements for financial services companies

Image of bright screen with flashes of light over United States map.
Photo: Adrian Bretscher/Getty Images for Kaspersky Lab

Major amendments to Part 500 cybersecurity regs adopted – we set out what you need to know.

New York’s financial watchdog published significant updates to its cybersecurity regulations Wednesday, adding strict internal controls and risk assessment requirements, plus notification obligations around ransom payments, that go further than recent federal rules.

The New York State Department of Financial Services (NYDFS) – which oversees banks, insurance firms, mortgagestatement

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience