New DFS Cybersecurity Guidance Explained
Abstract: What the new DFS third-party service provider (TPSP) letter means and how your agency may respond Body: The New York State Department of Financial Services (DFS) issued new cybersecurity guidance for regulated entities, including insurance agencies, focused on third-party service provider (TPSP) oversight under the state's financial services cybersecurity regulation.The update doesn't add new requirements but clarifies how agencies may want to manage vendors with access to nonpublic information.What DFS Section 500.11 RequiresInsurance agencies and other covered entities must maintain written TPSP cybersecurity policies and procedures that address:Identifying your third-party service providersSetting minimum cybersecurity standardsPerforming due diligence on vendor securityPeriodically reassessing each TPSP's controlsThese…