Law / United States / New York

DFS Guidance: Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment

DFS Industry Letter of on a Heightened Cybersecurity Threat Environment

Guidance, not a law: the New York Department of Financial Services's reading of New York Department of Financial Services Cybersecurity Regulation, Cybersecurity Program and Cybersecurity Policy. It binds nobody by itself; the law it reads does.

Guidance on a sector security regimes rule, addressed to private bodies.

Instrument type
guidance published by a regulator
Obligation class
Security, Governance

As of .

What the regulator expects

  • The letter is addressed to the organizations and individuals the Department regulates, and it reads 23 NYCRR Part 500, which reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The Department states that the letter does not establish new legal requirements and does not alter the requirements under Part 500.
  • The Department says that when you become aware of a heightened threat environment, one in which cybersecurity risks are significantly elevated and have a high likelihood of impacting your information systems, nonpublic information or operations, you should consider additional steps that may go beyond the minimum requirements of Part 500, to the extent not already required and implemented, depending on your circumstances and operations.
  • The Department says you should consider expeditiously identifying and remediating known exploited vulnerabilities in firmware, hardware and software, especially on systems exposed to the Internet; disabling inactive or unnecessary ports and protocols where possible; establishing network access protections and segmenting networks; and reviewing and validating cloud application configurations against your risk tolerance.
  • The Department says you should consider restricting multi-factor authentication enrollment and changes to authorized processes with strong identity verification, employing phishing-resistant multi-factor authentication methods such as authenticator applications with number matching or hardware tokens, and conducting privileged access reviews, especially for threat-relevant users, systems and devices.
  • The Department says you should consider confirming that secure programming practices are used, including validating user inputs and restricting unsafe execution of commands, scripts, processes or generated outputs.
  • The Department says you should consider confirming that intrusion prevention, detection and response controls are in use, up-to-date and appropriately deployed; that log and security event alerting data is captured and anomalous or suspicious activity is promptly identified and appropriately actioned; that appropriate personnel review and act on relevant threat intelligence, including known indicators of compromise and complete remediation steps; and that all personnel are alerted to the steps they can take against ongoing cyber threat campaigns, including social engineering.
  • The Department says you should consider enhancing monitoring and validation of the expected behavior of third-party code, applications, permissions and practices, and engaging with critical third-party service providers to confirm awareness of heightened cybersecurity risks and readiness to respond to potential disruptions.
  • The Department says you should consider testing the integrity, immutability and restorability of backups, including validation of recovery time objectives, and reviewing and testing threat-relevant operational resilience procedures, such as incident response and business continuity plans, to protect and restore critical functions, information systems and nonpublic information.
  • The Department says you should consider reviewing or developing threat-relevant personnel, customer and third-party communication strategies sufficient to address prolonged system and service disruptions; if you use operational technologies, confirming that critical system functions can operate if other information systems are unavailable or compromised; and monitoring financial transactions, including virtual currency business activity, to ensure compliance with applicable orders and guidance on sanctions and anti-money laundering.

Who enforces it

Enforcement body

The Superintendent of Financial Services, who enforces 23 NYCRR Part 500, the regulation the letter reads.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The Department's industry letter of is addressed to the organizations and individuals the Department regulates and gives guidance on measures regulated entities should consider in a heightened cybersecurity threat environment. The letter states that it is intended to inform risk management and compliance efforts and does not establish new legal requirements. It states that it does not alter the requirements under Part 500.

It describes a heightened threat environment as one in which cybersecurity risks are significantly elevated and therefore have a high likelihood of impacting information systems, nonpublic information or operations. It says regulated entities are required to identify and assess internal and external cybersecurity risks that may threaten the security or integrity of nonpublic information stored on their information systems.

It says regulated entities should consider taking additional steps that may go beyond those minimum requirements when they become aware of a heightened threat environment. It gives geopolitical events that may increase the risk of cyberattacks, and technological developments that materially change cybersecurity risks such as the release of frontier AI models, as examples of what may result in a heightened threat environment.

It identifies a non-exhaustive list of best practices to consider incorporating into an existing cybersecurity program, to the extent not already required and implemented. It says whether to adopt such practices depends on the unique circumstances and operations of an organization. It says some of the recommendations may go beyond the explicit minimum controls required under Part 500.

Its first group of measures reduces the attack surface and begins with expeditiously identifying and remediating known exploited vulnerabilities in firmware, hardware and software, especially for information systems exposed to the Internet. That group also recommends disabling inactive or unnecessary ports and protocols where possible. That group also recommends restricting multi-factor authentication enrollment and changes to authorized processes with strong identity verification.

That group also recommends phishing-resistant multi-factor authentication methods, such as authenticator applications with number matching or hardware tokens. That group also recommends establishing network access protections and segmenting networks to limit movement across information systems. That group also recommends reviewing and validating cloud application configurations to ensure alignment with the regulated entity's risk tolerance.

That group also recommends conducting privileged access reviews, especially for threat-relevant users, systems and devices. That group also recommends confirming that secure programming practices are used, including validating user inputs and restricting unsafe execution of commands, scripts, processes or generated outputs.

Its second group of measures improves threat detection and readiness and recommends confirming that intrusion prevention, detection and response controls are in use, up-to-date and appropriately deployed. That group also recommends confirming that log and security event alerting data is captured and that anomalous or suspicious activity is promptly identified and appropriately actioned.

That group also recommends that appropriate personnel review and take appropriate action on relevant threat intelligence, including known indicators of compromise and complete remediation steps. That group also recommends alerting all personnel to the steps they can take to prevent, detect and respond to ongoing cyber threat campaigns, including social engineering techniques.

That group also recommends enhancing monitoring and validation of the expected behavior of third-party code, applications, permissions and practices. That group also recommends engaging with critical third-party service providers to confirm awareness of and appropriate action on heightened cybersecurity risks and readiness to respond to potential disruptions.

Its third group of measures improves resilience and response and recommends testing the integrity, immutability and restorability of backups, including validation of recovery time objectives. That group also recommends reviewing and testing threat-relevant operational resilience procedures, such as incident response and business continuity plans, to protect and restore critical functions, information systems and nonpublic information.

That group also recommends reviewing or developing threat-relevant personnel, customer and third-party communication strategies to confirm they are sufficient to address prolonged system and service disruptions. That group also recommends that a regulated entity that uses operational technologies confirm that critical system functions can operate if other information systems are unavailable or otherwise compromised.

That group also recommends monitoring financial transactions, including virtual currency business activity, to ensure compliance with applicable orders and guidance on sanctions and anti-money laundering.

Back to the example  ·  Lint your app