Home / Blog / Cybersecurity
January 5, 2024 by Christopher Salone
After a multiyear process of proposals and assessment of public comments, the New York State Department of Financial Services (NYSDFS) has made significant amendments to its Cybersecurity Regulation, 23 NYCRR Part 500. The rule is final and effective as of November 1, 2023. Let’s take a comprehensive look at each requirement of the regulation and how it has changed.
One of the most notable changes to the NYSDFS Cybersecurity Regulation is the broadened scope of its applicability. The regulation now encompasses a wider range of entities, ensuring that not only banks and insurers but also smaller financial institutions and even third-party service providers must adhere to its requirements.
With these changes, many want to know, “Does this apply to my company?” Let’s break down the different types of Covered Entities, and what parts of the regulation they will have to comply with.
NYSDFS has proposed several compliance dates, all based off the new regulation’s effective date of November 1, 2023. Most changes will take effect in 180 days (Monday, April 29, 2024). There are several other compliance dates that include different transition periods where covered entities will have:
Conclusion
The amended regulation significantly raises the bar for cybersecurity in the financial sector, likely influencing similar regulations in other states and potentially at a federal level. While it enhances consumer data protection, it also poses challenges for companies in terms of compliance. Ensuring adherence to these more stringent requirements might demand increased investments in technology and manpower.
Please do not hesitate to reach out with any questions. FoxPointe Solutions is equipped to assist your organization in complying with the new requirements.