ARTICLE
11 December 2017

What New Cyber Protocol Rules In New York Mean For Directors And Officers

WE
Wilson Elser Moskowitz Edelman & Dicker LLP

Contributor

More than 800 attorneys strong, Wilson Elser serves clients of all sizes across multiple industries. It maintains 38 domestic offices, another in London and enjoys more extensive international reach as a founding member of Legalign Global.  The firm is currently ranked 56th in the National Law Journal’s NLJ 500.
The NYDFS, which is responsible for the regulation of banks, insurers and other financial institutions that do business in New York, is a leader in the United States in putting more responsibility...
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

The New York Department of Financial Services (NYDFS), which is responsible for the regulation of banks, insurers and other financial institutions that do business in New York, is a leader in the United States in putting more responsibility for cybersecurity on the entities it regulates and their respective directors and officers.

New rules developed by the NYDFS under 23 NYCRR Part 500 (the Regulation), which went into effect on March 1, 2017, require such entities within DFS's regulatory jurisdiction to implement specific cybersecurity protocols. These include the enactment of a comprehensive cybersecurity policy, a written incident response plan that reports breaches within 72 hours to the NYDFS, and security policies for third-party service providers who access nonpublic information. The new rules also put more responsibilities on directors and officers, requiring not only the designation of a chief information security officer (CISO) but also board certification to the NYDFS of compliance with the regulations.

The Regulation requires the CISO to prepare an annual report to the board of directors of the regulated entity regarding its cybersecurity program. The report must (1) specifically address the identification of material cyber risks to the regulated entity, including any past material cybersecurity event and  (2) report on any penetration testing and vulnerability assessments. The Regulation also requires reporting on multifactor authentication and cyber awareness training for all personnel.

Further, the first compliance certification from the directors and officers of covered entities must be submitted to the NYDFS by February 15, 2018. The Regulation requires that a "Certification of Compliance" be signed by the chairman of the board of directors or a senior officer, who certifies that the regulated entity's cybersecurity program has been reviewed and that its cybersecurity protocol complies with the New York state law.

Threats from hackers, thieves, third-party contractors, competitors and employees and inadvertent misuse or loss of data present potentially catastrophic financial and reputational risks to companies today. Even the most vigilant company can be a victim of a data breach or other cyber loss. With the enactment of this Regulation, New York is providing clear notice that it intends to hold directors and officers more responsible for ensuring that their companies are undertaking more active assessment of their own security policies and procedures. Even for those directors and officers whose companies are not subject to this Regulation, the responsibilities outlined in the enacted rules set forth a general standard of care that they, too, would be well advised to consider and follow.

This article was published in the DAC Beachcroft LLP D&O and FI Newsletter – Autumn 2017. DAC Beachcroft is a founding member of Legalign Global, an alliance comprised of best-in-region insurance law firms that include Wilson Elser, Bach Langheid Dallmayr and Wotton + Kearney. 

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
11 December 2017

What New Cyber Protocol Rules In New York Mean For Directors And Officers

United States Technology

Contributor

More than 800 attorneys strong, Wilson Elser serves clients of all sizes across multiple industries. It maintains 38 domestic offices, another in London and enjoys more extensive international reach as a founding member of Legalign Global.  The firm is currently ranked 56th in the National Law Journal’s NLJ 500.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More