New York’s Department of Financial Services said Wednesday it has issued the updated and strengthened cybersecurity regulation it first proposed in November.
The new regulation, which updates its 2017 cybersecurity regulation, introduces changes including the creation of three tiers of companies, with companies with fewer than 20 employees and less than $5 million in gross annual revenue in each of the last three years subject to fewer of its requirements.
Other changes include:
-Enhanced governance requirements
-Additional controls to prevent initial unauthorized access to systems and to prevent or mitigate the spread of an attack
-Requirements for more regular risk and vulnerability assessments and more robust incident response, business continuity and disaster recovery planning
-Updated notification requirements, including a new requirement to report ransomware payments
-Updated direction for companies to invest in at least annual training and cybersecurity awareness programs that anticipate social engineering attacks.
There are no substantive differences between the initial proposal and the final regulation, according to the department’s “notice of adoption.”
The new rules “raise the bar for cyber resilience,” New York State Chief Cyber Officer Colin Ahert said in a statement.
In its “Assessment of Public Comments” on the proposal, the department said it received a suggestion that the regulation address the cybersecurity risks associated with artificial intelligence, generative AI and large language models.
The department responded that while it agrees these risks are “concerning” and that it expects covered entities to take them into account in their risk assessments and address them in their cybersecurity programs, it “declines to add new sections regarding AI and large language models at this time.”