Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

23 NYCRR 500 Readiness with PK Protect

PKWARE

By PKWAREProductivity Protected

Share on social media

The State of New York adopted mandates and requirements for financial services institutions licensed or authorized by The New York State Department of Financial Services (DFS) to conduct business. 23 NYCRR 500 is designed to bolster defenses against cybersecurity attacks to protect customers’ private, personal, and sensitive data as well as companies’ information technology systems. The mandate requires each covered company to assess its risks, then design and implement programs to address the risks. Additionally, covered companies need to establish security policies governing sensitive data usage of any third-party service providers with whom they share data.

What the Regulation Requires

23 NYCRR 500 came into effect on 1 March 2017, with up to three years allowed for certain sections. Penalties follow New York Banking Law. The obligations placed on a covered organization are specific.

Document the compliance areas that apply, including a cybersecurity risk assessment. Identify and protect sensitive data. Actively reduce sensitive data that is not needed. Limit data retention. Implement encryption for sensitive data the company holds, uses, or shares, whether it is at rest or in transit over external networks. Test penetration and assess vulnerability. And report readiness across all of it.

Who It Applies To

The regulation covers any entity operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation, or similar authorization under the Banking Law, the Insurance Law, or the Financial Services Law. In practice that includes state banks, licensed lenders, private banks, foreign banks operating in New York, mortgage companies, insurance companies, trust companies, and service providers.

Guidelines Rather Than Prescriptions

The law sets general guidelines and minimum standards for securing and protecting sensitive data rather than naming exact technical requirements. That was deliberate. The New York DFS regulations were revised over several years, with financial firms and security experts working alongside the legislature, and the stated goal was complete protection without undue complexity or unreasonable burden. They are widely expected to become a standard bearer for other US domestic cybersecurity law.

Leaving the technology choice to each covered company has a practical consequence. Firms holding hundreds of gigabytes, and in many cases petabytes, of data across files, databases, and endpoints need something that scales to that volume, and the capabilities have to line up with what the regulation actually asks for.

Nine Requirements in Detail

Covered organizations must establish formal programs to identify and protect sensitive data, identify cyber risk, detect attacks, and mitigate damage. They must document their cybersecurity and data protection policies and have them formally approved by senior executives, officers, or the board. Each must appoint a named Chief Information Security Officer, responsible for implementing those programs and enforcing those policies.

Regular risk assessments are expected, with programs and policies revised in response. Nonpublic information that is no longer necessary for business purposes must be securely deleted. Companies that develop software must document the procedures and standards that keep their applications secure. Access controls are required, including multi-factor or risk-based authentication, limiting which people and which roles can reach sensitive data. And any breach or cybersecurity event must be notified to the NY DFS within 72 hours.

What Counts as Protected Information

The privacy requirement reaches further than financial data. Covered companies must discover and protect nonpublic personal information that could be used for identity theft, which includes personal health data and information derived from healthcare provision, Social Security numbers, personally identifiable information, access codes and passwords, and biometric data.

All of it must be protected by encryption or another effective technique such as deletion, masking, or redaction, and that protection has to hold at rest in storage as well as in use and in transit while being shared.

Third Parties Are In Scope Too

The regulation also reaches service providers who are not themselves licensed by the NY DFS. A covered organization has to establish security policies for any third party with access to nonpublic information, and those requirements look much like its own: risk assessments, access controls, notification to the covered entity of any breach or security event, and protection techniques such as redaction and encryption.

In this free whitepaper, our data experts weigh in on:

  • A detailed overview of 23 NYCRR 500 and its key requirements
  • What is involved in proving annual compliance
  • Similarities to GDPR and CCPA, and how to simplify compliance with all three

Download The Whitepaper

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.