Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Malicious Code Protection and Class A Company Monitoring Solutions
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The limited exemption in section 500.19(a) lifts these duties for a covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides. Section 500.19(c) lifts section 500.14 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.14 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates.
- Implement risk-based controls designed to protect against malicious code, including controls that monitor and filter web traffic and electronic mail to block malicious content.
- If you are a Class A company as 23 NYCRR 500.1(d) defines it, implement an endpoint detection and response solution to monitor anomalous activity, including lateral movement, and a solution that centralizes logging and security event alerting, unless your Chief Information Security Officer has approved in writing the use of reasonably equivalent or more secure compensating controls.
What this law does
Section 500.14(a)(2) requires a covered entity, as part of its cybersecurity program, to implement risk-based controls designed to protect against malicious code, including controls that monitor and filter web traffic and electronic mail to block malicious content.
Section 500.14(b) requires a Class A company to implement an endpoint detection and response solution to monitor anomalous activity, including lateral movement, and a solution that centralizes logging and security event alerting, unless its Chief Information Security Officer has approved in writing the use of reasonably equivalent or more secure compensating controls.
A Class A company is a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years and either over 2,000 employees averaged over those years or over $1,000,000,000 in gross annual revenue in each of those years, counted as section 500.1(d) provides.
A covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides, is exempt from section 500.14(a)(2) and (b) under that section.
Section 500.19(c) and (d) name section 500.14 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. Part 500 took effect on , and its Second Amendment on .
Section 500.22(d)(3) gives covered entities 18 months from the effective date of the Second Amendment to comply with its new requirements in sections 500.14(a)(2) and 500.14(b).
When LexLint raises it
When your app profile says your app provides financial services.