• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Search Results for: NYDFS

NYDFS Releases New Prescriptive FAQs on MFA

December 22, 2025 By Kim Peretti, Kate Hanniford, Lance Taubin and Carson Kuck

The New York Department of Financial Services (NYDFS) has released a new set of Frequently Asked Questions (FAQs 18–23) under 23 NYCRR Part 500, reinforcing its position that multifactor authentication (MFA) remains a critical component of a covered entity’s cybersecurity program. These FAQs provide highly prescriptive guidance, including clarifications on technical requirements for the “possession” […]

Filed Under: Privacy & Cyber Regulatory Enforcement

NYDFS Issues Guidance on Managing Risks Related to Third-Party Service Providers

October 27, 2025 By Kate Hanniford, Lance Taubin and Carson Kuck

On October 21, 2025, the New York Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) outlining guidance on managing risks related to third-party service providers (“TPSPs”). NYDFS recognizes that as covered entities become more reliant on TPSPs, managing TPSPs “remains a crucial element of a Covered Entity’s cybersecurity program.” The Letter outlines […]

Filed Under: Privacy & Cyber Regulatory Enforcement

NYDFS Issues Guidance on Heightened Cybersecurity and Sanctions Risk from Global Conflict

June 27, 2025 By Kim Peretti

Overview On June 23, 2025, the New York State Department of Financial Services (“NYDFS”) issued an industry letter encouraging all regulated entities to review their cybersecurity and sanctions compliance programs in light of heightened geopolitical tensions. The letter, titled “Impact of Global Conflict on Cybersecurity and Sanctions Risk,” emphasizes the elevated risk environment and reaffirms […]

Filed Under: Uncategorized

Additional Cybersecurity Requirements of NYDFS Part 500 Take Effect Today

May 1, 2025 By Kim Peretti, Kate Hanniford, Scott Hilsen, Lance Taubin and Andrew Rice

Today, on May 1, 2025, additional enhanced cybersecurity controls required by the Second Amendment to the New York Department of Financial Services (NYDFS) Cybersecurity Regulation (23 NYCRR Part 500) (the “Second Amendment”) take effect.  Although the Second Amendment was originally adopted in November of 2023, NYDFS established a multi-year rollout of the Second Amendment’s requirements, […]

Filed Under: Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Data Protection, NYDFS, Regulations

NYDFS Issues Guidance on Artificial Intelligence-related Cybersecurity Risks

October 17, 2024 By Kim Peretti, Kate Hanniford, Ashley Miller, Lance Taubin and Colton Jackson

On October 16, 2024, the New York Department of Financial Services (“NYDFS”) issued an industry letter covering Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks (the “Industry Letter”).  The Industry Letter contains guidance for entities regulated by NYDFS (“Covered Entities”) in assessing and responding to cybersecurity risks related to the use […]

Filed Under: AI Cybersecurity & Privacy, Artificial Intelligence (AI), Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 7
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • NYDFS Releases New Prescriptive FAQs on MFA
  • How to Comply with the EU AI Act: Guidance from the Spanish AI Regulator
  • New EU Regulation Clarifies Cybersecurity Rules for IoT Devices and Other ‘Products with Digital Elements’
  • California AG Announces $1.4 Million Settlement with Mobile App Provider for Alleged CCPA Violations
  • SEC Dismisses Remaining Claims Against SolarWinds
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.