Share on LinkedInShare on LinkedIn

ARTICLE · 30 MARCH 2016

New York Financial Regulator Proposes Cybersecurity Rules

Jones Day
Jones Day
Contributor
Jones Day

Jones Day

Jones Day is a global law firm with more than 2,400 lawyers in 40 offices across five continents....

View firm profile
Explore more from Jones Day

On November 9, 2015, former Acting New York Superintendent of Financial Services requested input from federal and state regulators on proposed rules from the New York State Department of Financial Services...

United StatesPrivacy
Daniel McLoon
Daniel McLoon
Mauricio Paez
Mauricio Paez
Jonathon Little
Jonathon Little
Kevin Lyles
Kevin Lyles
Adam Salter
Adam Salter
Michiru Takahashi
Michiru Takahashi
Undine Von Diemar
Undine Von Diemar
Olivier Haas
Olivier Haas
Richard Johnson
Richard Johnson
+2 more
Author LinkedIn connections

On November 9, 2015, former Acting New York Superintendent of Financial Services requested input from federal and state regulators on proposed rules from the New York State Department of Financial Services designed to protect customer account information and financial institutions' information technology systems. The rules would, among other things, require banks and insurers to conduct annual penetration testing and designate a qualified employee to serve as chief information security officer responsible for overseeing, implementing, and enforcing cybersecurity programs and policies. The rules also provide for additional notification requirements in the event of a cybersecurity incident that has a "reasonable likelihood of materially affecting the normal operation" of the company.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See more popular content from