23 NYCRR 500 – The deadline has passed, but there’s still time.
The New York Department of Financial Services announced a new cybersecurity regulation (23 NYCRR 500), on March 1st, 2017, due to the increase of consistency and sophistication of cyber attacks over recent years. In fairness, much of the requirements are “standard issue” in most compliance frameworks, lack of adherence to applicable New York businesses will result in fines. Even with continual extensions, the deadline for compliance was set as February 15, 2018. Like other initiatives, such as DFARS and PTC, we are seeing entities struggle to meet the requirements. As an IT Professional or business in the financial industry, a whole new level of responsibility has been forced onto your shoulders, whether based in New York or in a company that operates within the State. For most Security Professionals, this will be “business as usual” as the majority of the requirements are clearly defined in NIST 800 documents. In short,…