Finance Firms, March 1st is Looming - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
February 14, 2017 Newswires
Share
Share
Post
Email

Finance Firms, March 1st is Looming

Westchester County Business Journal (NY)

On Dec. 28,2016, the Department of Financial Services (NYSDFS) released a revised version of the first-in-nation "Cybersecurity Requirements for Financial Services Companies" (The Revised Proposed Rules), Initially issued on Sept. 13,2016.

Amid the surge in global attacks on financial institutions and corporate computer networks, New York state lowered the bar for banks, credit unions, insurers and mortgage companies to comply with the new rule, that if adopted, goes into effect on March 1, 2017. The proposed rules only apply to "covered entitles," defined as, "any person operating under or required to operate under a license, registration charter, certificate, permit, accreditation or similar authorization under the banking law, the insurance law or the financial services.law." Since some investment advisers register or notice file in New York pursuant to NYIAA (New York Investment Advisory Act), there is an argument such an investment adviser is operating under or required to operate under, "similar authorization."

Visit https://myportal.dfs.ny.gov/web/guest-applications/who-we-supervise to find out if your institution is a covered entity.

DFS received more than 150 comment letters during a 45-day period, many of which were highly critical of the rule. Reasons varied from inconsistency with laws already on the books at the federal level to significant departures from established and accepted cybersecurity frameworks utilized by many institutions already, to the overall lack of flexibility in the initial DFS rule that could lead to a "by-rote" risk-neutral set of implementations.

Some important distinctions in the now revised rule are:

* Removal of requirement to place a single executive (typically a chief information security officer or CISO) in charge of cybersecurity;

* Covered entities are now required to simply have programs "reasonably designed to protect data" as opposed to the original mandate to have a "program designed to ensure the confidentiality, integrity and availability of the covered entity's information systems;

* The definition of "nonpublic information" for customers now includes only sensitive personal information: person's name in conjunction with Social, driver's license or biometric data. Nonpublic does still include "business-related information" that, if confidentiality or integrity of that information were violated, could cause a material adverse impact to the covered entity; and

* Multifactor authentication requirement has been simplified and streamlined, only mandatory for access to "internal networks from an external network" unless an even stronger access control mechanism is used in its place for remote access.

One area still lacking some specificity is that of encryption of nonpublic information, in that:

* While encryption is no longer required for all nonpublic information in-transit and at-rest, under the revised proposal, a covered entity would be required, based on its risk assessment, to "implement controls, including encryption to protect nonpublic information." In essence, it is open to interpretation as to whether encryption is optional and downstream or compensating controls can be used as a substitute.

The softened rules also provide more discretion to covered entities to develop their cybersecurity policies and practices based on assessment of risk conducted by the entity. The Revised Proposed Rules are now subject to a renewed 30-day public notice-and-comment period, during which financial institutions can elaborate on additional concerns they have regarding the revised proposal language.

Breach reporting no longer requires notification of the cyber event to DFS in 72 hours, but is still required in 72 hours if any other government entity requires such notice or where there is "reasonable likelihood of material harm to the covered entity's 'normal operations'.

Lastly, third-party providers have been defined with more clarity and that the covered entity's policies and procedures for the third party can be "risk-based".

We recommend covered entities begin considering their current state of security versus the mandated compliant staged implementation that phases in over four six-month periods, and requires annual certification beginning Feb. 15,2018.

NEED TO CREATE AN IT SECURITY POLICY?

Your first step to cyber strength begins with policy. Annese can review your existing policy or help you construct one. Learn more at www.annese.com/ blog/policy or contact us at [email protected].

Written by Joe Vigorito, Director of Mobility & Security at Annese & Associates, Inc. With more than 20 years of experience in the industry, Vigorito is a Fellow and Diplomate at the American Board for Certification in Homeland Security, a member of the American College of Forensic Examiners, ISSA, IEEE, BICSI and FBI-Infragard.

Older

State health exchange plans enrollment changes

Newer

BREAKING THE PATTERN

Advisor News

  • Your client’s $3 million portfolio doesn’t tell you their insurance needs
  • How life insurance can provide liquidity for wealthy families
  • Retirement providers turn to digital engagement to retain assets
  • Looking out for clients with diminished mental capacity
  • House panel advances CLEAR Forms Act backed by IRI
More Advisor News

Annuity News

  • What lower interest rates mean to annuity payouts
  • AM Best downgrades A-Cap insurers amid financial and regulatory troubles
  • Lawsuit claims Delaware Life hid billions in insurer-linked investments
  • AM Best to Deliver Presentation at 2026 ACLI Annual Conference
  • Global Atlantic Announces Launch of ForeLifetime Income, a New Fixed Index Annuity
More Annuity News

Health/Employee Benefits News

  • Pennie sees another year of rate hikes
  • Colorado health insurance premiums expected to jump by 10% next year
  • When one spouse qualifies for LTCi and the other doesn’t
  • Employer health costs face biggest jump since 2003
  • Colorado faces double-digit hikes in insurance premiums
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • State reverses one-third of health insurer decisions
  • AM Best Affirms Credit Ratings of Assurant, Inc. and Its Property/Casualty and Life/Health Subsidiaries
  • AM Best Affirms Credit Ratings of Samsung Property & Casualty Insurance Company (China), Ltd.
  • Abacus Global Management Completes Landmark $400 Million Securitization
  • 3 in 4 Americans Think Market Highs are Unsustainable, Allianz Life Study Finds
Sponsor
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Lauren Sinnott Named to Ragan’s Top Women in Marketing Awards, Class of 2026 
  • Classic Car Insurer OpenRoad Insurance Expands to 40 U.S. States in Two Years
  • How Aspire General Turned an Early Technology Bet Into Claims Automation at Scale with Kyber
  • Adjusto launches AI-Native contents claims services powered by its technology platform
  • URL Insurance Group Celebrates 40 Years of Service, Growth, and Industry Leadership
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.