New York DFS Enhances Cybersecurity Requirements for Financial Services Sector

The New York State Department of Financial Services (“DFS”) has increased its cybersecurity requirements for the financial services industry, as of November 1, 2023. It has implemented supplementary standards and controls with the aim of ensuring security for sensitive data, according to an update from Patterson Belknap Webb & Tyler LLP.

The fresh modifications call for enhanced governance alongside more controls to prevent and manage cyber-attacks. Augmented risk and vulnerability assessments have been introduced, as well as rapid notification for ransomware attacks. Notably, there are also new training requirements for personnel operating in this sector.

These amendments build on DFS’s pre-existing cybersecurity regulations. It’s an indication of the increasing importance of digital security across industries and reflects a broader trend in regulatory compliance.

As the financial services sector continues to be a prime target for cybercriminals, taking steps to ensure the robustness of cyber defenses is not just crucial, but also mandatory. Both the companies and the regulatory bodies must work in tandem to secure their systems, data, and client information.

It’s anticipated that other regulatory bodies across different states, and indeed, globally, might follow suit, ramping up their cybersecurity regulations. It’s a clear message for financial service providers everywhere: Ignorance or lackadaisical approach to cybersafety is no longer an excuse.