Cyber Security Regulations Ahead Says New York State’s Dept. of Financial Services

Proskauer - Corporate Defense and Disputes
Contact

Based on a report released last week about cyber security vulnerabilities faced by financial institutions, New York State Department of Financial Services (“NYDFS”) Superintendent Benjamin Lawsky signaled that the agency will soon move forward with cyber security regulations. The report concluded that banks’ third-party vendors have significant potential cyber security vulnerabilities. Superintendent Lawsky said that the regulations will strengthen cyber security standards for banks’ third-party vendors, including potential measures related to cyber security representations and warranties that banks receive from their vendors.

The NYDFS report surveyed 40 covered entities and identified what it described as a number of potentially significant security gaps.  Among other issues, the report found that:

  • Less than 50% of the institutions surveyed required any on-site assessments of vendor cybersecurity practices; only 46% required these evaluations to be conducted before a vendor was retained; and only 35% conducted periodic on-site inspection after the vendor was hired.
  • Over 20% of surveyed banks did not ask vendors to warrant that they had adequate cybersecurity practices and procedures in place. Of the banks that called for such representations, only 36% required that the warranties also apply to subcontractors.
  • 44% of banks did not expect their vendors to guarantee that data and other products provided by them would be free of viruses and other cybersecurity issues.
  • 30% of the surveyed organizations did not require vendors to notify them of cybersecurity breaches.

The agency also stated that it would be surveying a group of regulated insurers for similar issues concerning the cybersecurity of third-party vendors.

For more information, the full statement can be found here and the report can be accessed here.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Proskauer - Corporate Defense and Disputes

Written by:

Proskauer - Corporate Defense and Disputes
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Proskauer - Corporate Defense and Disputes on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide