23 NYCRR 500
-

New York’s new guidance on third-party service provider cyber risk
The guidance does not impose new requirements; it helps NYDFS-regulated institutions meet existing obligations in light of evolving vendor-related cybersecurity risks.
-

NYDFS fines dental plan firm $2m in phishing breach
Failure to use MFA to protect data of 90,000 customers leads to fine and raises legal questions.
-

New York fines Geico and Travelers $11.3m for data breaches
Auto insurers will pay fines totaling $11.3m for data breaches that New York officials say compromised personal information of 120,000 customers.
