ARTICLE
30 March 2016

New York Financial Regulator Proposes Cybersecurity Rules

JD
Jones Day

Contributor

Jones Day is a global law firm with more than 2,500 lawyers across five continents. The Firm is distinguished by a singular tradition of client service; the mutual commitment to, and the seamless collaboration of, a true partnership; formidable legal talent across multiple disciplines and jurisdictions; and shared professional values that focus on client needs.
On November 9, 2015, former Acting New York Superintendent of Financial Services requested input from federal and state regulators on proposed rules from the New York State Department of Financial Services...
United States Privacy

On November 9, 2015, former Acting New York Superintendent of Financial Services requested input from federal and state regulators on proposed rules from the New York State Department of Financial Services designed to protect customer account information and financial institutions' information technology systems. The rules would, among other things, require banks and insurers to conduct annual penetration testing and designate a qualified employee to serve as chief information security officer responsible for overseeing, implementing, and enforcing cybersecurity programs and policies. The rules also provide for additional notification requirements in the event of a cybersecurity incident that has a "reasonable likelihood of materially affecting the normal operation" of the company.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More