Reporting Cybersecurity Incidents

Abstract: The New York financial services cybersecurity regulation requires you to notify the state Department of Financial Services if you are victimized by cyber criminals. Body: ​It is always possible that your agency – or one of the third-party service providers (TPSPs) the agency works with – will be victimized by cyber criminals. If that happens, the New York financial services cybersecurity regulation requires you to notify the state Department of Financial Services (DFS.) While you're attempting to limit and repair the damage, these are some questions that might come up:What is a “cybersecurity incident"?The regulation defines that term in two parts. The first is…

Continue ReadingReporting Cybersecurity Incidents

New: Cyber Reg FAQ Document

Abstract: We are happy to announce a new resource to help you comply with New York's financial services cybersecurity regulation - a "frequently asked questions" document. Body: ​ We are happy to announce a new resource to help you comply with New York's financial services cybersecurity regulation - a "frequently asked questions" document. The seven-page file​ provides answers to some of the questions Big I New York members ask most often about the regulation, including:Are licensed employees required to make the annual compliance filings?How do I get help completing the compliance filing?Does my agency have to submit the Notice of Exemption every year?Do agency employees have…

Continue ReadingNew: Cyber Reg FAQ Document

New Cybersecurity Reg Compliance Tool – Asset Inventory Workbook

Abstract: We have developed a Microsoft Excel workbook that will help you meet the requirement to maintain an inventory of your cyber assets. Body: ​As we mentioned last week, the New York financial services cybersecurity regulation requires all covered entities (including all insurance agencies) to create and maintain an inventory of their information system assets. Entities have until Nov. 1, 2025 to comply with this requirement.We have developed a Microsoft Excel workbook that will help you meet this requirement. For each listed device, it has fields for several pieces of information including those the regulation specifically mentions (owner, location, classification/sensitivity, support expiration date, recovery time…

Continue ReadingNew Cybersecurity Reg Compliance Tool – Asset Inventory Workbook