NYDFS Considering Significant Updates to Its Cybersecurity Rule
NYDFS Considering Significant Updates to Its Cybersecurity Rule
The New York Department of Financial Services (“NYDFS”) recently released new draft amendments (“Draft Amendments”) to its controversial cybersecurity rule (“Cybersecurity Rule” or “Rule”) that would include significant changes to the Rule, including, for example, a mandatory 24-hour notification for cyber ransom payments, heightened cyber expertise requirements for board members, and new access restrictions to privileged accounts. If proposed and ultimately adopted, the draft amendments would further expand the Cybersecurity Rule’s requirements and, in particular, impose heightened obligations on certain types of larger financial institutions.
The Draft Amendments would create new requirements to notify NYDFS of certain incidents. For example, the Draft Amendments would require notification to NYDFS within 72 hours of any unauthorized access to privileged accounts or deployment of ransomware within a material part of the covered entity’s information systems. In addition, the Draft Amendments would require notification to NYDFS within 24 hours of a covered financial institution making a ransomware payment connected to a cybersecurity event, as well as introduce a requirement to provide NYDFS within 30 days with an “explanation” of why the payment was necessary, whether alternatives were considered, and what sanctions diligence was conducted.
The Draft Amendments would make meaningful changes to the risk assessment requirements under the Cybersecurity Rule. Under the Rule, a covered entity must conduct a periodic risk assessment of its information systems “sufficient to inform the design of” its cybersecurity program required by the Rule and must update the risk assessment to address various changes, developments, and threats. The Draft Amendments would expand upon the Rule’s definition of a “Risk Assessment” and more clearly articulate that an assessment must, for example, “take into account the specific circumstances of the covered entity.” The Draft Amendments also would clarify that a covered entity’s risk assessment must be updated at least annually or whenever a change in business or technology “causes a material change to the covered entity’s cyber risk.”
The Draft Amendments would add a number of new technical requirements to the Rule, including:
The Draft Amendments would impose a number of new governance obligations, including:
The Draft Amendments also would impose additional cybersecurity obligations on a new category of covered entities, “Class A Companies.” Under the Draft Amendments, a “Class A Company” would be a covered entity with: (1) over 2,000 employees; or (2) over $1 billion in gross annual revenues averaged over the last three years from all of its business operations and those of its affiliates. These Class A Companies would be subject to additional cybersecurity obligations, including:
The Draft Amendments also would clarify two aspects of enforcement of the Cybersecurity Rule. First, the Draft Amendments would make clear that the commission of a single act prohibited by or the failure to satisfy an obligation required by the Cybersecurity Rule would constitute a violation of the Rule. Second, the Draft Amendments would clarify that the NYDFS will consider certain mitigating factors when assessing penalties, including cooperation, good faith, intentionality, history of prior violations, harm to customers, gravity of violation, number of violations, and involvement of senior management.
The Draft Amendments signal a continued focus by the NYDFS on elevating cybersecurity requirements for covered entities. In particular, the Draft Amendments would represent the first significant overhaul of the controversial Cybersecurity Rule since it was first issued. Nonetheless, the Draft Amendments appear intended to address a number of changes that have occurred since the Rule became effective in 2017, including the rapidly evolving cyber threat landscape and, in particular, the growing prevalence of ransomware incidents. Though many aspects of the Draft Amendments reflect best practices (including those outlined in current NYDFS industry guidance), covered entities should monitor whether NYFDS formally proposes the Draft Amendments in order to ensure that they are equipped technically, organizationally, and financially to meet the heightened governance, technical, and notification obligations in the event that the Draft Amendments are adopted.