Search
By Kathryn Rock, Prasun Howli
On November 1, 2023, the New York State Department of Financial Services (NYDFS) announced the amendments to its initial cybersecurity regulation, 23 New York Codes, Rules and Regulations (NYCRR) 5001. The purpose of the NYDFS 23 NYCRR 500 is to protect financial services companies and their customers from ever-growing cybersecurity threats. The regulation is applicable to banks, insurance companies, New York State-licensed branches, and agencies of non-US banks, and all other financial services companies that are supervised by the NYDFS. The objective of the amendment update is to address new threats from cybersecurity attacks using sophisticated technologies. The proposed amendment has introduced the concept of Class A companies, which will be required to follow more stringent requirements.
The amendment states2: “Class A companies mean those covered entities with at least $20,000,000 in gross annual revenue in each of the last two fiscal years from business operations of the covered entity and its affiliates in this State and (1) over 2,000 employees averaged over the last two fiscal years, including those of both the covered entity and all of its affiliates no matter where located; or (2) over $1,000,000,000 in gross annual revenue in each of the last two fiscal years from all business operations of the covered entity and all of its affiliates.”
The 23 NYCRR 500 rule requires that each entity assess its cybersecurity risk profile and develop a robust program to address cybersecurity risks. The key amendments to the regulations include:
In today’s world, cybersecurity has become more critical than ever before. As regulators seek to outmaneuver the cybersecurity threats by introducing new regulations or amendments to the existing regulations, the growth of digital technologies is introducing new challenges. With the advent of artificial intelligence, big data, cloud infrastructure, and an expanding digital universe more generally with its inherent omnipresent opportunities and risks, the complexity of managing cybersecurity risks will only increase. The key to success is to treat cybersecurity as a critical leadership and management issue rather than only a technology or information security requirement.
Guidehouse has assisted numerous clients in assessing their cybersecurity and operationalizing compliance requirements using regulations, standards, and guidance issued by cybersecurity authorities and global data privacy regulations. We have supported our clients by:
This post was updated on November 15, 2023 for accuracy and comprehensiveness.
1. “New York State Department of Financial Services (NYDFS) 23 NYCRR 500 Cybersecurity Requirements For Financial Services Companies.” n.d. https://www.dfs.ny.gov/system/files/documents/2023/03/23NYCRR500_0.pdf.
2. “New York State Department of Financial Services (NYDFS) 23 NYCRR 500 Cybersecurity Requirements For Financial Services Companies.” n.d. https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf.
3. See Footnote 2
Guidehouse is a global consultancy providing advisory, digital, and managed services to the commercial and public sectors. Purpose-built to serve the national security, financial services, healthcare, energy, and infrastructure industries, the firm collaborates with leaders to outwit complexity and achieve transformational changes that meaningfully shape the future.