2023 DFS Cybersecurity Regulation Analysis – Client Update – November 2023
NY finalizes major changes to its cyber security regulation.
On November 1, 2023, New York State’s Department of Financial Services issued final regulations regarding cybersecurity for financial services companies. They also posted links to upcoming training sessions starting on November 15, 2023. This final regulation adopted many of the changes proposed in the July 2023 draft amendment, which drew on those first proposed in a November 2022 draft but also adopted a limited number of changes suggested by commenters. The preamble to the adopted regulation highlights the department’s approach of requiring regulated entities to deploy reasonable, risk-based measures to protect themselves and their customers from foreseeable cybersecurity threats.