NY regulator urges firms to comply with cybersecurity regulation

Maria Nikolova

The final implementation period for the regulation ends March 1, 2019.

Financial Services Superintendent Maria T. Vullo today reminded all entities regulated by the New York State Department of Financial Services (DFS) that they have to be in full compliance with the cybersecurity regulation by March 1, 2019.

Let’s recall that New York’s cybersecurity regulation became effective March 1, 2017. DFS, however, offered a two-year timeline for implementation of the regulation’s requirements, with a final compliance deadline of March 1, 2019. The final step in the implementation timeline requires regulated entities that use third-party providers to put in place policies and procedures ensuring the security of information systems and nonpublic information accessible to, or held by, such providers.

Superintendent Vullo today also reminded all regulated entities that the second certification of compliance covering the prior calendar year must be filed electronically via the DFS cybersecurity portal not later than February 15, 2019.

Under the cybersecurity rules, all banks, insurance companies, and other financial services institutions and licensees regulated by DFS are now required to have a cybersecurity program in place that is designed to protect consumers’ private data. The cybersecurity program has to perform a number of core cybersecurity functions, such as identification and assessment of cybersecurity risks regarding the Nonpublic Information stored on the Covered Entity’s Information Systems. The program also has to detect cybersecurity events, and respond to such events.

The entities also have to have a written policy or policies that are approved by the board or a senior officer. This policy has to address matters like data governance and classification, risk assessment, and incident response.

The firms affected by the new rules must have a Chief Information Security Officer to help protect data and systems. They also must secure protections of data at third-party providers. Furthermore, they need to have in place controls and plans to help ensure the safety and soundness of New York’s financial services industry.

Finally, covered entities and licensees must also report cybersecurity events to DFS through the Department’s online cybersecurity portal.

Cyber security is high on the agenda of the United States National Futures Association (NFA) too. Early in January this year, NFA clarified the amendments to its Information Systems Security Programs Interpretive Notice. The Association plans a raft of changes, including a requirement for members to inform it about certain cybersecurity-related incidents. Members (other than futures commission merchants for which NFA is not the DSRO) will have notify NFA of cybersecurity incidents related to their commodity interest business that:

  • result in a loss of customer or counterparty funds or loss of a Member firm’s capital; or
  • if a Member notifies its customers or counterparties of an incident pursuant to state or federal law.

Read this next

Metaverse Gaming NFT

Mon Protocol and Pixelverse Forge a Groundbreaking Partnership to Revolutionize Blockchain Gaming

Mon Protocol and Pixelverse make history in the annals of Blockchain gaming as they set up the architecture for the melding of their technologies.

Chainwire

Nimiq Pay Launch: A New Standard For Self-Custodial Crypto Payments

Nimiq, the blockchain ecosystem for payments that is designed to make cryptocurrency easy for everyone to use, has taken the first concrete steps towards its goal of becoming the world’s most widely-accepted digital asset for payments with the launch of Nimiq Pay.

Inside View, Interviews

Exclusive: GoMining’s Mark Zalan wants to democratize opportunities of Bitcoin halving

As the Bitcoin community counts down to the upcoming Bitcoin halving, Mark Zalan, CEO of GoMining, shared exclusive insights into how the company is gearing up for this pivotal event in the cryptocurrency world.

Digital Assets

Umoja Partners with Merlin Chain to Launch Revolutionary Bitcoin-Based Synthetic Dollar – USDb

Umoja, an innovative smart money protocol, has embarked on a strategic partnership with Merlin Chain, a leading Bitcoin Layer-2 network, to introduce USDb, the first Bitcoin-based, high-yield synthetic dollar.

Crypto Insider

Bybit Report Highlights Imminent Bitcoin Supply Shortage and Rising Scarcity Post-Halving

Bybit, recognized as one of the top three cryptocurrency exchanges globally in terms of trading volume, has recently published a comprehensive report highlighting the future supply constraints of Bitcoin.

blockdag

BlockDAG Outshines XRP Price Breakout and Uniswap Crypto Forecast with 20,000x ROI Potential and Teaser for Keynote on Moon

BlockDAG has become the latest sensation in the crypto world, which has taken the spotlight by storm, overshadowing even the most optimistic projections for XRP’s price breakout and Uniswap’s crypto forecast.

Digital Assets

Binance announces blockchain courses at European universities

“Education plays a pivotal role in advancing adoption and fostering opportunities as these technologies redefine our future and global economic landscape.”

Fintech, Uncategorized

Kepler Cheuvreux taps Adaptive for new execution equities platform

KCx, Kepler Cheuvreux’s execution division, has partnered with trading technology firm Adaptive Financial Consulting to create a new event-driven trading system based on Aeron and its own Hydra technology.

Chainwire

Bybit Livestream: Thought Leaders from Bybit, OKX and Wintermute on the 2024 Crypto Market Bull Run, April 19. Register and Secure Your Spot Now.

In a post-ETF and BTC halving world, a new era has opened as the infrastructure in the crypto industry has changed tremendously from the last bull run and halving cycle.

<