• 2025
  • April - 3 articles
  • March - 14 articles
  • February - 16 articles
  • January - 15 articles
  • 2024
  • December - 15 articles
  • November - 15 articles
  • October - 20 articles
  • September - 17 articles
  • August - 20 articles
  • July - 18 articles
  • June - 20 articles
  • May - 22 articles
  • April - 12 articles
  • March - 14 articles
  • February - 13 articles
  • January - 11 articles
  • 2023
  • December - 12 articles
  • November - 12 articles
  • October - 16 articles
  • September - 11 articles
  • August - 13 articles
  • July - 13 articles
  • June - 13 articles
  • May - 12 articles
  • April - 11 articles
  • March - 15 articles
  • February - 12 articles
  • January - 13 articles
  • 2022
  • December - 14 articles
  • November - 12 articles
  • October - 11 articles
  • September - 12 articles
  • August - 13 articles
  • July - 13 articles
  • June - 13 articles
  • May - 12 articles
  • April - 12 articles
  • March - 14 articles
  • February - 12 articles
  • January - 13 articles
  • 2021
  • December - 15 articles
  • November - 12 articles
  • October - 14 articles
  • September - 11 articles
  • August - 15 articles
  • July - 12 articles
  • June - 14 articles
  • May - 12 articles
  • April - 14 articles
  • March - 15 articles
  • February - 11 articles
  • January - 11 articles
  • 2020
  • December - 14 articles
  • November - 11 articles
  • October - 13 articles
  • September - 11 articles
  • August - 9 articles
  • July - 11 articles
  • June - 16 articles
  • May - 13 articles
  • April - 13 articles
  • March - 17 articles
  • February - 10 articles
  • January - 12 articles
  • 2019
  • December - 12 articles
  • November - 11 articles
  • October - 12 articles
  • September - 12 articles
  • August - 14 articles
  • July - 11 articles
  • June - 12 articles
  • May - 14 articles
  • April - 12 articles
  • March - 14 articles
  • February - 14 articles
  • January - 17 articles
  • 2018
  • December - 14 articles
  • November - 13 articles
  • October - 17 articles
  • September - 14 articles
  • August - 14 articles
  • July - 19 articles
  • June - 17 articles
  • May - 18 articles
  • April - 20 articles
  • March - 18 articles
  • February - 18 articles
  • January - 19 articles
  • 2017
  • December - 19 articles
  • November - 16 articles
  • October - 19 articles
  • September - 21 articles
  • August - 22 articles
  • July - 17 articles
  • June - 19 articles
  • May - 20 articles
  • April - 18 articles
  • March - 20 articles
  • February - 13 articles
  • January - 6 articles
  • 2016
  • December - 10 articles
  • November - 9 articles
  • October - 8 articles
  • September - 10 articles
  • August - 10 articles
  • July - 8 articles
  • June - 11 articles
  • May - 8 articles
  • April - 11 articles
  • March - 11 articles
  • February - 11 articles
  • January - 9 articles
  • 2015
  • December - 13 articles
  • November - 13 articles
  • October - 14 articles
  • September - 13 articles
  • August - 11 articles
  • July - 12 articles
  • June - 14 articles
  • May - 11 articles
  • April - 12 articles
  • March - 12 articles
  • February - 12 articles
  • January - 9 articles
  • 2014
  • December - 10 articles
  • November - 9 articles
  • October - 13 articles
  • September - 12 articles
  • August - 13 articles
  • July - 14 articles
  • June - 10 articles
  • May - 14 articles
  • April - 15 articles
  • March - 17 articles
  • February - 14 articles
  • January - 18 articles
  • 2013
  • December - 20 articles
  • November - 18 articles
  • October - 21 articles
  • September - 19 articles
  • August - 21 articles
  • July - 22 articles
  • June - 20 articles
  • May - 23 articles
  • April - 26 articles
  • March - 24 articles
  • February - 29 articles
  • January - 24 articles
  • 2012
  • December - 22 articles
  • November - 24 articles
  • October - 27 articles
  • September - 27 articles
  • August - 25 articles
  • July - 22 articles
  • June - 20 articles
  • May - 28 articles
  • April - 24 articles
  • March - 28 articles
  • February - 24 articles
  • January - 24 articles
  • 2011
  • December - 24 articles
  • November - 18 articles
  • October - 21 articles
  • September - 21 articles
  • August - 21 articles
  • July - 20 articles
  • June - 23 articles
  • May - 27 articles
  • April - 22 articles
  • March - 22 articles
  • February - 16 articles
  • January - 20 articles
  • 2010
  • December - 21 articles
  • November - 18 articles
  • October - 20 articles
  • September - 13 articles
  • August - 11 articles
  • July - 9 articles
  • June - 8 articles
  • May - 9 articles
  • April - 11 articles
  • March - 12 articles
  • February - 10 articles
  • January - 10 articles
  • 2009
  • December - 11 articles
  • November - 9 articles
  • October - 11 articles
  • September - 10 articles
  • August - 10 articles
  • July - 10 articles
  • June - 10 articles
  • May - 11 articles
  • April - 13 articles
  • March - 13 articles
  • February - 7 articles
  • January - 10 articles
  • 2008
  • December - 12 articles
  • November - 8 articles
  • October - 16 articles
  • September - 11 articles
  • August - 13 articles
  • July - 13 articles
  • June - 14 articles
  • May - 13 articles
  • April - 13 articles
  • March - 9 articles
  • February - 14 articles
  • January - 11 articles
  • 2007
  • December - 11 articles
  • November - 12 articles
  • October - 12 articles
  • September - 4 articles
  • August - 4 articles
  • July - 4 articles
  • June - 2 articles
  • May - 6 articles
  • April - 5 articles
  • March - 1 article
  • Friday, August 25, 2017

    New York enacts bold cybersecurity law

    Security guidelines, initially proposed by the New York State Department of Financial Services (DFS), will become law Aug. 28, 2017. This has sparked statewide audits and broad compliance measures among organizations deemed by the department to be "Covered Entities." These include banks, other financial institutions and insurance companies, according to the DFS.

    Security analysts see a fundamental shift in the new regulations, which require companies to treat cyber security as a risk management issue and hold senior executives accountable for their companies' security policies, procedures and collaborations with third-party service providers.

    Maria T. Vullo, DFS Superintendent of Financial Services, introduced the legislation, dubbed 23 NYCRR 500, in March 2017, which included a 180-day transitional period to give organizations time to become compliant. Vullo said she expects the new laws to address "the ever-growing threat posed to information and financial systems by nation-states, terrorist organizations and independent criminal actors."

    Steven Grossman, Vice President of Strategy at Bay Dynamics Inc., said the far-reaching initiative is the first state-sponsored regulation to prescribe a risk assessment model to security. The model is markedly different from previous compliance efforts, which tend to be restrictive, he noted. "There's a realistic expectation that if you try to protect everything equally, you'll do a poor job of protecting your organization," he said. "For example, you wouldn't want to lock up snacks in the same way that you'd lock up fine jewelry. Payment data, like fine jewelry, is an important asset to protect; different assets require different levels of protection."

    Assigning responsibility

    Grossman additionally noted the law's requirement for a Chief Information Security Officer (CISO), which the DFS defines as "a qualified individual responsible for overseeing and implementing the Covered Entity's cybersecurity program and enforcing its cybersecurity policy." CISOs, who may be employed by an organization, affiliate or third-party service provider, are required for any company with more than 10 employees and $10 million in total year-end assets, which includes a broad cross-section of New York companies, he stated.

    CISOs will be required to provide written reports at least once a year to their respective board of directors or governing body, detailing their cybersecurity programs' scope, effectiveness in protecting assets and nonpublic information, and perceived material threats, the DFS stated.

    "Many companies set and forget when they outsource back office procedures or other business-critical functions to a third-party service provider," Grossman stated. "Ongoing due diligence will ensure these companies are operating at the same level of requirements."

    Operations and scope

    Statewide cybersecurity laws require all New York State companies to implement a broad set of compliance measures in each of the following areas: information security, data governance and classification, asset inventory and device management, access controls and identity management, business continuity and disaster recovery planning and resources, systems operations and availability concerns, systems and network security, systems and network monitoring, systems and application development and quality assurance, physical security and environmental controls, customer data privacy, vendor and third-party service provider management, risk assessment, and incident response.

    Self-directed guidance

    Going forward, Covered Entities in the State of New York will be required to "implement and maintain a written policy or policies, approved by a Senior Officer or the Covered Entity's board of directors (or an appropriate committee thereof) or equivalent governing body, setting forth the Covered Entity's policies and procedures for the protection of its Information Systems and Nonpublic Information stored on those Information Systems," the DFS wrote.

    Participating organizations are free to interpret the guidelines as they see fit, based on their perception of risk and their unique approaches to implementation, Grossman stated. For example, the law mentions multifactor authentication as a possible approach, while allowing organizations to make their own choices. "The larger financial institutions are already moving in that direction, but further downstream, many midsize providers are finding two-factor authentication inconvenient and difficult to implement," he added. "And if you don't find ways to make security convenient, it will continue to be a challenge."

    Editorial Note:

    Whether you want to upgrade your POS offerings, find a payment gateway partner, bone up on fintech regs or PCI requirements, find an upcoming trade show, read about faster payments, or discover the latest innovations in merchant acquiring, The Green Sheet is the resource for you. Since 1983, we've helped empower and connect payments professionals, starting with the merchant level salespeople who bring tailored payment acceptance and digital commerce tools, along with a host of other business services to merchants across the globe. The Green Sheet Inc. is also a proud affiliate of Bankcard Life, a premier community that provides industry-leading training and resources for payment professionals.

    Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.

    skyscraper ad