Finance Firms, March 1st is Looming
On
Amid the surge in global attacks on financial institutions and corporate computer networks,
Visit https://myportal.dfs.ny.gov/web/guest-applications/who-we-supervise to find out if your institution is a covered entity.
DFS received more than 150 comment letters during a 45-day period, many of which were highly critical of the rule. Reasons varied from inconsistency with laws already on the books at the federal level to significant departures from established and accepted cybersecurity frameworks utilized by many institutions already, to the overall lack of flexibility in the initial DFS rule that could lead to a "by-rote" risk-neutral set of implementations.
Some important distinctions in the now revised rule are:
* Removal of requirement to place a single executive (typically a chief information security officer or CISO) in charge of cybersecurity;
* Covered entities are now required to simply have programs "reasonably designed to protect data" as opposed to the original mandate to have a "program designed to ensure the confidentiality, integrity and availability of the covered entity's information systems;
* The definition of "nonpublic information" for customers now includes only sensitive personal information: person's name in conjunction with Social, driver's license or biometric data. Nonpublic does still include "business-related information" that, if confidentiality or integrity of that information were violated, could cause a material adverse impact to the covered entity; and
* Multifactor authentication requirement has been simplified and streamlined, only mandatory for access to "internal networks from an external network" unless an even stronger access control mechanism is used in its place for remote access.
One area still lacking some specificity is that of encryption of nonpublic information, in that:
* While encryption is no longer required for all nonpublic information in-transit and at-rest, under the revised proposal, a covered entity would be required, based on its risk assessment, to "implement controls, including encryption to protect nonpublic information." In essence, it is open to interpretation as to whether encryption is optional and downstream or compensating controls can be used as a substitute.
The softened rules also provide more discretion to covered entities to develop their cybersecurity policies and practices based on assessment of risk conducted by the entity. The Revised Proposed Rules are now subject to a renewed 30-day public notice-and-comment period, during which financial institutions can elaborate on additional concerns they have regarding the revised proposal language.
Breach reporting no longer requires notification of the cyber event to DFS in 72 hours, but is still required in 72 hours if any other government entity requires such notice or where there is "reasonable likelihood of material harm to the covered entity's 'normal operations'.
Lastly, third-party providers have been defined with more clarity and that the covered entity's policies and procedures for the third party can be "risk-based".
We recommend covered entities begin considering their current state of security versus the mandated compliant staged implementation that phases in over four six-month periods, and requires annual certification beginning
NEED TO CREATE AN IT SECURITY POLICY?
Your first step to cyber strength begins with policy. Annese can review your existing policy or help you construct one. Learn more at www.annese.com/ blog/policy or contact us at [email protected].


State health exchange plans enrollment changes
BREAKING THE PATTERN
Advisor News
- Your client’s $3 million portfolio doesn’t tell you their insurance needs
- How life insurance can provide liquidity for wealthy families
- Retirement providers turn to digital engagement to retain assets
- Looking out for clients with diminished mental capacity
- House panel advances CLEAR Forms Act backed by IRI
More Advisor NewsAnnuity News
- What lower interest rates mean to annuity payouts
- AM Best downgrades A-Cap insurers amid financial and regulatory troubles
- Lawsuit claims Delaware Life hid billions in insurer-linked investments
- AM Best to Deliver Presentation at 2026 ACLI Annual Conference
- Global Atlantic Announces Launch of ForeLifetime Income, a New Fixed Index Annuity
More Annuity NewsHealth/Employee Benefits News
Life Insurance News