N.Y. issues revised draft cyber rule for banks
Full article708 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
New York state banking regulators Wednesday issued a revised draft of cybersecurity rules for the financial institutions they oversee — addressing several issues that had raised industry concerns. The regulations were praised for avoiding the "one size fits all" approach that had initially drawn criticism.
New York state banking regulators Wednesday issued a revised draft of cybersecurity rules for the financial institutions they oversee — addressing several issues that had raised industry concerns.
The new draft is slated to go into effect Mar. 1, after a 30-day comment period ends Jan. 28, according to a statement from Department of Financial Services Superintendent Maria Vullo. The regulations would be the first of their kind in the U.S.
“This updated proposal allows an appropriate period of time for regulated entities to review the rule before it becomes final and make certain that their systems can effectively and efficiently meet the risks associated with cyber threats,” said Vullo.
The new draft replaces an earlier proposal that was scheduled to come into force Jan.1, and had caused industry representatives to complain at a recent state assembly hearing. Since they cover New York, the new rules will have outsized national and international effects. The state is home to outposts of — and therefore can regulate — every major financial institution in the world.
The publication of the revised draft fulfills an undertaking the DFS made last week, when the agency said it was revising its original proposal after criticism from industry of a one-size-fits-all approach.
One close observer of the debate over the rules praised the DFS for meeting industry concerns.
“It’s clear that New York State took the public’s concerns seriously, ” said David Damato, chief security officer at cybersecurity company Tanium, which numbers several large banks among its customer base.
“They’ve gotten rid of the one-size-fits-all approach that hampered the original regulations,” he said of DFS, “by recognizing that each bank should tie their cybersecurity approach to their individual risk assessment.”
He said DFS had also acknowledged “that reporting every single incident — even unsuccessful [attacks] — would have been unfeasible for large banks that see thousands of attempted intrusions every day.”
More Scoops
New York updates third-party risk guidance, adds AI provisions
The New York Department of Financial Services has clarified rules for financial institutions, highlighting AI oversight and lessons from recent cloud outages.
CISA pushes final cyber incident reporting rule to May 2026
CISA is facing a tight CIRCIA deadline. Here’s how Sean Plankey can attempt to meet it
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ny-dfs-revised-draft-cyber-rule-banks/