NYDFS updates cybersecurity requirements for financial services companies

Major amendments to Part 500 cybersecurity regs adopted – we set out what you need to know.

New York’s financial watchdog published significant updates to its cybersecurity regulations Wednesday, adding strict internal controls and risk assessment requirements, plus notification obligations around ransom payments, that go further than recent federal rules.

The New York State Department of Financial Services (NYDFS) – which oversees banks, insurance firms, mortgagestatement

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in