Preparing for the November 1st NYDFS Cybersecurity Amendments: Key Changes and Actionable Steps for Financial Services
On October 16, 2024, the New York Department of Financial Services (NYDFS) issued guidance on managing cybersecurity risks associated with the use of Artificial Intelligence (AI) within the framework of 23 NYCRR Part 500. The guidance applies to all entities under NYDFS jurisdiction and provides direction for assessing and managing new cybersecurity risks posed by AI adoption, without introducing new regulatory requirements. This report consolidates the guidance from NYDFS with the upcoming amendments to Part 500, effective November 1, 2024, and explores key technical and administrative measures for financial institutions to achieve compliance and mitigate AI-related cybersecurity risks. Key Amendments Effective November 1, 2024 1. Multi-Factor Authentication (MFA) Requirement: MFA is required for all individuals accessing information systems, covering both internal access and remote access to third-party applications and privileged accounts. Exemptions: Limited exemptions may apply, though compensating controls must be implemented. Implementation: Organizations should ensure MFA systems meet the…
