On November 1, 2023, significant amendments were finalized to the New York State Department of Financial Services’ (NYDFS) cybersecurity regulations, according to a report by Shearman & Sterling LLP. These cybersecurity requirements for financial services companies, originally implemented in 2017, have been codified in Section 500 of 23 NYCRR 500.
These updated provisions, referred to as the Second Amendment, present substantial revisions to the NYDFS’s Cybersecurity Requirements. These changes are a part of a broader, statewide initiative to enhance cybersecurity practices and protocols.
Since its inception in 2017, the Cybersecurity Requirements have functioned as a regulatory framework to ensure the integrity and security of data and information systems within financial services companies. Considering the magnitude of these changes, it is crucial that legal professionals working in financial firms thoroughly review the Amended Cybersecurity Requirements.
Pending full disclosure of the amended contents, immediate implications and potential impacts of this amendment remain to be explored. As we seek to grasp the potential effects on our industry, we will keep you informed with any upcoming details and interpretations of this critical regulatory change.