Insight

Brand New Cybersecurity Regulations Are Now in Effect in New York: How Might They Affect Your Organization?

Brand New Cybersecurity Regulations Are Now in Effect in New York: How Might They Affect Your Organization?

New Cybersecurity Regulations
Simon Johnson

Simon Johnson

April 11, 2017 08:55 AM

They have been hailed as a world first.

New cybersecurity regulations which have just come into effect in New York will provide for specific and prescriptive requirements for the financial services industry. The regulations (New 23 NYCRR 500) may well be an indicator of things to come in Australia, where an increased focus is already being placed on cyber and data security, with laws regarding mandatory data breach notification having just come into effect.

The New York regulations were initially released in draft in September 2016. While many aspects were consistent with existing cybersecurity principles, the regulations were seen to go above and beyond the status quo. Notably, the proposed regulations dealt with ‘nonpublic information’ which was defined very broadly, meaning that entities falling within the regulations (known as ‘Covered Entities’) were burdened with protecting a wide scope of information. Covered Entities under the regulations include, for example, financial service providers, investment companies, brokers, and insurers.

Following a consultation period, changes were made to the initial draft. These included a loosening of some of the more onerous requirements. The meaning of ‘nonpublic information’ was narrowed and ‘risk assessments’ were provided for, which would inform the implementation of measures on an entity-by-entity basis (rather than a one-size fits all arrangement). The final form of the regulations came into effect on 1 March 2017 with an 180-day transitional period. However, there are some exemptions for smaller-sized companies, such as those with less than 10 employees or those with gross annual revenue or year-end total assets below certain amounts.

Noteworthy aspects of the final regulations include requiring Covered Entities to implement a cybersecurity program and cybersecurity policy which would be based on the risk assessments that must be carried out periodically. Covered Entities also need to appoint a Chief Information Security Officer responsible for overseeing the cybersecurity program and policy. Qualified cybersecurity personnel are now required to perform certain core cybersecurity functions.

Significantly, Covered Entities are required to provide a signed annual certification of compliance from February 2018. Although not spelled out under the regulations, the effect of this requirement is that it could potentially lead to individual liability for the person(s) submitting the certification (being a ‘Senior Officer’ or the board of directors for example) if a false statement is contained in the certificate.

It appears that US regulators are developing a model cybersecurity law, and as such it seems likely that the New York regulations are a sign of things to come on the US front.

Back in Australia and further to the introduction of to the mandatory data breach notification legislation, we are also shortly anticipating some cyber initiatives such as an upcoming release by the ASX of the results of its ‘ASX 100 Cyber Health Check’. We expect this will provide some insight into how some of the largest organizations in Australia manage their cybersecurity risks and cybersecurity incidents.

In addition, Australian Signals Directorate, the national agency responsible for the provision of cyber security advice, recently published their updated Strategies to Mitigate Cyber Security Incidents. This provides some key advice as to how organizations can prepare for cybersecurity incidents and notes eight essential mitigation strategies including:

  1. application whitelisting, whereby only selected software applications are to run;
  2. patch applications, to fix security vulnerabilities in software applications;
  3. configuring Microsoft Office macro settings to disable untrusted macros;
  4. restricting administrative privileges;
  5. patching operating systems;
  6. multi-factor authentication; and
  7. daily backup of important data, and securing it offline.

It’s clear that a growing focus is being placed on cybersecurity and protecting information from cyber security threats. With an ever increasing amount of cyber-attacks and data breach incidents, it is now more important than ever that organizations put systems in place to mitigate the risks, thereby placing them in good stead to prepare for any future increased levels of regulation.

Trending Articles

Presenting The Best Lawyers in Australia™ 2025


by Best Lawyers

Best Lawyers is proud to present The Best Lawyers in Australia for 2025, marking the 17th consecutive year of Best Lawyers awards in Australia.

Australia flag over outline of country

The 2024 Best Lawyers in Spain™


by Best Lawyers

Best Lawyers is honored to announce the 16th edition of The Best Lawyers in Spain™ and the third edition of Best Lawyers: Ones to Watch in Spain™ for 2024.

Tall buildings and rushing traffic against clouds and sun in sky

Best Lawyers Expands Chilean 2024 Awards


by Best Lawyers

Best Lawyers is pleased to announce the 14th edition of The Best Lawyers in Chile™ and the inaugural edition of Best Lawyers: Ones to Watch in Chile™, honoring the top lawyers and firms conferred on by their Chilean peers.

Landscape of city in Chile

Best Lawyers Expands 2024 Brazilian Awards


by Best Lawyers

Best Lawyers is honored to announce the 14th edition of The Best Lawyers in Brazil™ and the first edition of Best Lawyers: Ones to Watch in Brazil™.

Image of Brazil city and water from sky

Announcing The Best Lawyers in South Africa™ 2024


by Best Lawyers

Best Lawyers is excited to announce the landmark 15th edition of The Best Lawyers in South Africa™ for 2024, including the exclusive "Law Firm of the Year" awards.

Sky view of South Africa town and waterways

The Best Lawyers in Mexico Celebrates a Milestone Year


by Best Lawyers

Best Lawyers is excited to announce the 15th edition of The Best Lawyers in Mexico™ and the second edition of Best Lawyers: Ones to Watch in Mexico™ for 2024.

Sky view of Mexico city scape

How Palworld Is Testing the Limits of Nintendo’s Legal Power


by Gregory Sirico

Many are calling the new game Palworld “Pokémon GO with guns,” noting the games striking similarities. Experts speculate how Nintendo could take legal action.

Animated figures with guns stand on top of creatures

The Best Lawyers in Portugal™ 2024


by Best Lawyers

The 2024 awards for Portugal include the 14th edition of The Best Lawyers in Portugal™ and 2nd edition of Best Lawyers: Ones to Watch in Portugal™.

City and beach with green water and blue sky

The Best Lawyers in Peru™ 2024


by Best Lawyers

Best Lawyers is excited to announce the landmark 10th edition of The Best Lawyers in Peru, the prestigious award recognizing the country's lop legal talent.

Landscape of Peru city with cliffside and ocean

How To Find A Pro Bono Lawyer


by Best Lawyers

Best Lawyers dives into the vital role pro bono lawyers play in ensuring access to justice for all and the transformative impact they have on communities.

Hands joined around a table with phone, paper, pen and glasses

Presenting the 2024 Best Lawyers Family Law Legal Guide


by Best Lawyers

The 2024 Best Lawyers Family Law Legal Guide is now live and includes recognitions for all Best Lawyers family law awards. Read below and explore the legal guide.

Man entering home and hugging two children in doorway

Announcing The Best Lawyers in New Zealand™ 2025 Awards


by Best Lawyers

Best Lawyers is announcing the 16th edition of The Best Lawyers in New Zealand for 2025, including individual Best Lawyers and "Lawyer of the Year" awards.

New Zealand flag over image of country outline

The Best Lawyers in Colombia™ 2024


by Best Lawyers

Best Lawyers is honored to announce the 14th edition of The Best Lawyers in Colombia™ for 2024, which honors Colombia's most esteemed lawyers and law firms.

Cityscape of Colombia with blue cloudy sky above

Announcing The Best Lawyers in Japan™ 2025


by Best Lawyers

For a milestone 15th edition, Best Lawyers is proud to announce The Best Lawyers in Japan.

Japan flag over outline of country

Announcing the 2024 Best Lawyers in Puerto Rico™


by Best Lawyers

Best Lawyers is proud to announce the 11th edition of The Best Lawyers in Puerto Rico™, honoring the top lawyers and firms across the country for 2024.

View of Puerto Rico city from the ocean

The Best Lawyers in Singapore™ 2025 Edition


by Best Lawyers

For 2025, Best Lawyers presents the most esteemed awards for lawyers and law firms in Singapore.

Singapore flag over outline of country