ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

New York Increases Cybersecurity Rules for Financial Companies

highRansomwareimportance 57
Full article120 words · extracted from schneier.com · click to collapse

Another example of a large and influential state doing things the federal government won’t:

Boards of directors, or other senior committees, are charged with overseeing cybersecurity risk management, and must retain an appropriate level of expertise to understand cyber issues, the rules say. Directors must sign off on cybersecurity programs, and ensure that any security program has “sufficient resources” to function.

In a new addition, companies now face significant requirements related to ransom payments. Regulated firms must now report any payment made to hackers within 24 hours of that payment.

Tags: banking, computer security, cybersecurity, ransomware, regulation

Posted on November 3, 2023 at 7:01 AM20 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2023/11/new-york-increases-cybersecurity-rules-for-financial-companies.html