This week, New York released cybersecurity regulations that monitor required infrastructure for regulated financial services institutions. Though the regulations have been in development for a while, CSO Online reported they were only finalized about a month ago.

A Much-Needed Initiative

The regulations include mandating the establishment of a cybersecurity program within financial institutions. Each companywide program must have an appointed chief information security officer (CISO). The CISO is held responsible for the operation of the program, which is to be run on a risk-assessment model.

This means that decision-making is based on an evaluation of the various risks that present themselves and the process that leads to a decision can be transparently demonstrated to a regulator. Also, the cybersecurity of any business partners must now be entered into the overall risk assessment.

The regulations can get technique-specific. For instance, an annual penetration test will be a criterion, and vulnerability assessments are to be performed twice a year, at minimum. Also, the definition of nonpublic information expands in the regulations to more than what is usually considered confidential. Organizations will have to prove that nonpublic information is protected by cybersecurity efforts.

Increasing Cybersecurity Regulations

The next six months will be a period of transition under the regulations. Richard Santalesa, of the Smartedge Law Group, outlined the deadlines that the regulations mandate in an email.

“The deadline for compliance with many of the Regulations requirements is Sept. 1, 2017, while compliance with the more technical requirements is either March 1, 2018 or Sept. 1, 2018. And the requirements to be imposed upon third-party service providers is now March 1, 2019,” he wrote. “Together the staggered and extended deadlines for compliance should provide entities with a modicum of breathing room to employ requirement measures, procedures and policies.”

Many institutions are now facing some needed efforts in compliance resolution, even though professional organizations have recommended the risk-assessment approach be used in cybersecurity for many years.

Santalesa went on to list what will be expected of financial services institutions. He said they “have six months to review the requirements, update their cybersecurity policy, incident response plan, craft a third-party service provider policy, conduct and document a risk assessment.” Then, by Sept. 1, 2017, those organizations must submit a certification of compliance or exemption.

These New York regulations may end up serving as a model for adoption by other states. Additionally, the effort made to comply with this governance may actually serve an institution well in other jurisdictions, which can lower the overall cost of compliance.

More from

Who Carries the Weight of a Cyberattack?

Almost immediately after a company discovers a data breach, the finger-pointing begins. Who is to blame? Most often, it is the chief information security officer (CISO) or chief security officer (CSO) because protecting the network infrastructure is their job. Heck, it is even in their job title: they are the security officer. Security is their responsibility. But is that fair – or even right? After all, the most common sources of data breaches and other cyber incidents are situations caused…

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

Abuse of Privilege Enabled Long-Term DIB Organization Hack

From November 2021 through January 2022, the Cybersecurity and Infrastructure Security Agency (CISA) responded to an advanced cyberattack on a Defense Industrial Base (DIB) organization’s enterprise network. During that time frame, advanced persistent threat (APT) adversaries used an open-source toolkit called Impacket to breach the environment and further penetrate the organization’s network. Even worse, CISA reported that multiple APT groups may have hacked into the organization’s network. Data breaches such as these are almost always the result of compromised endpoints…

How Do You Plan to Celebrate National Computer Security Day?

In October 2022, the world marked the 19th Cybersecurity Awareness Month. October might be over, but employers can still talk about awareness of digital threats. We all have another chance before then: National Computer Security Day. The History of National Computer Security Day The origins of National Computer Security Day trace back to 1988 and the Washington, D.C. chapter of the Association for Computing Machinery’s Special Interest Group on Security, Audit and Control. As noted by National Today, those in…