Strengthening Cybersecurity Compliance: SEC and NYDFS Increase Enforcement Efforts

Recent actions taken by the New York Department of Financial Services (NYDFS) and the Securities and Exchange Commission (SEC) underscore the continued commitment from government regulators on cybersecurity topics. The increased assertiveness of these regulatory entities is prompting companies to put more thought into constructing their cybersecurity compliance programs.

The NYDFS has adopted final amendments to its cybersecurity regulations, enhancing the focus on cybersecurity issues for financial institutions in New York. The regulation has implications not only for the protection of financial information but also for the larger aspect of safeguarding sensitive data.

Meanwhile, the SEC has initiated a lawsuit against SolarWinds, an executive within the company, in an assertive enforcement posture to protect cyber integrity. Details regarding the case have not been publicly disclosed, but the case illustrates the increasing rigor of cybersecurity enforcement in the corporate sector.

This amplified focus from the SEC and NYDFS is resulting in a higher level of scrutiny for companies and their cybersecurity compliance programs. In an environment where data breaches can lead to significant fines and damage to reputation, companies are advised to be proactive in structuring their cybersecurity compliance programs.

The objective should always be twofold – to avoid fines and penalties that may be imposed by regulatory bodies for non-compliance and also to protect sensitive data, thereby safeguarding corporate reputation.