ARTICLE
22 September 2021

NYDFS FAQ Provides Clarity On Breach Notification And Security Requirements

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
The New York Department of Financial Service recently clarified security incident notification requirements and the use of multi-factor authentication.
United States Technology

The New York Department of Financial Service recently clarified security incident notification requirements and the use of multi-factor authentication. On its FAQ page, the NYDFS added two new questions and answers for financial services companies subject to 23 NYCRR Part 500.

The first answer explains that covered entities must notify the NYDFS of security incidents that occur at a third party service provider. Even if the third party notifies NYDFS on the covered entity's behalf, covered entities still must directly notify the department. This requirement helps the NYDFS quickly identify threats and appropriately respond.

The second answer clarifies when covered entities must use multi-factor authentication. Namely, MFA should be used whenever accessing internal networks from an external network. This includes email, document hosting, and related services (whether on-premise or cloud-based). MFA may not be necessary if a covered entity's CISO documents approval of similar or more secure access controls.

Putting it Into Practice: These updates highlight the importance of having proper breach notification procedures and security controls. Companies are reminded to notify the department of relevant breaches and to enable MFA by default for accessing internal networks.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More