March 2, 2017 By Larry Loeb 2 min read

This week, New York released cybersecurity regulations that monitor required infrastructure for regulated financial services institutions. Though the regulations have been in development for a while, CSO Online reported they were only finalized about a month ago.

A Much-Needed Initiative

The regulations include mandating the establishment of a cybersecurity program within financial institutions. Each companywide program must have an appointed chief information security officer (CISO). The CISO is held responsible for the operation of the program, which is to be run on a risk-assessment model.

This means that decision-making is based on an evaluation of the various risks that present themselves and the process that leads to a decision can be transparently demonstrated to a regulator. Also, the cybersecurity of any business partners must now be entered into the overall risk assessment.

The regulations can get technique-specific. For instance, an annual penetration test will be a criterion, and vulnerability assessments are to be performed twice a year, at minimum. Also, the definition of nonpublic information expands in the regulations to more than what is usually considered confidential. Organizations will have to prove that nonpublic information is protected by cybersecurity efforts.

Increasing Cybersecurity Regulations

The next six months will be a period of transition under the regulations. Richard Santalesa, of the Smartedge Law Group, outlined the deadlines that the regulations mandate in an email.

“The deadline for compliance with many of the Regulations requirements is Sept. 1, 2017, while compliance with the more technical requirements is either March 1, 2018 or Sept. 1, 2018. And the requirements to be imposed upon third-party service providers is now March 1, 2019,” he wrote. “Together the staggered and extended deadlines for compliance should provide entities with a modicum of breathing room to employ requirement measures, procedures and policies.”

Many institutions are now facing some needed efforts in compliance resolution, even though professional organizations have recommended the risk-assessment approach be used in cybersecurity for many years.

Santalesa went on to list what will be expected of financial services institutions. He said they “have six months to review the requirements, update their cybersecurity policy, incident response plan, craft a third-party service provider policy, conduct and document a risk assessment.” Then, by Sept. 1, 2017, those organizations must submit a certification of compliance or exemption.

These New York regulations may end up serving as a model for adoption by other states. Additionally, the effort made to comply with this governance may actually serve an institution well in other jurisdictions, which can lower the overall cost of compliance.

More from

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today