Law / United States / New York

New York Department of Financial Services Cybersecurity Regulation, Malicious Code Protection and Class A Company Monitoring Solutions

23 NYCRR 500.14(a)(2), (b)

In force.

A sector security regimes rule binding private bodies.

Enforcement body
The Superintendent of Financial Services.
Instrument type
a regulation made under an act
Obligation class
Security

As of .

What it requires

  • It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The limited exemption in section 500.19(a) lifts these duties for a covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides. Section 500.19(c) lifts section 500.14 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.14 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates.
  • Implement risk-based controls designed to protect against malicious code, including controls that monitor and filter web traffic and electronic mail to block malicious content.
  • If you are a Class A company as 23 NYCRR 500.1(d) defines it, implement an endpoint detection and response solution to monitor anomalous activity, including lateral movement, and a solution that centralizes logging and security event alerting, unless your Chief Information Security Officer has approved in writing the use of reasonably equivalent or more secure compensating controls.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Section 500.14(a)(2) requires a covered entity, as part of its cybersecurity program, to implement risk-based controls designed to protect against malicious code, including controls that monitor and filter web traffic and electronic mail to block malicious content.

Section 500.14(b) requires a Class A company to implement an endpoint detection and response solution to monitor anomalous activity, including lateral movement, and a solution that centralizes logging and security event alerting, unless its Chief Information Security Officer has approved in writing the use of reasonably equivalent or more secure compensating controls.

A Class A company is a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years and either over 2,000 employees averaged over those years or over $1,000,000,000 in gross annual revenue in each of those years, counted as section 500.1(d) provides.

A covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides, is exempt from section 500.14(a)(2) and (b) under that section.

Section 500.19(c) and (d) name section 500.14 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. Part 500 took effect on , and its Second Amendment on .

Section 500.22(d)(3) gives covered entities 18 months from the effective date of the Second Amendment to comply with its new requirements in sections 500.14(a)(2) and 500.14(b).

When LexLint raises it

When your app profile says your app provides financial services.

Back to the example  ·  Lint your app