logo

What NY's New Security Rules Mean for Finance Firms

ID: 400b11e8-2d3d-5a26-b1d4-262bf60f26ea

STIX ID: report--400b11e8-2d3d-5a26-b1d4-262bf60f26ea

Feed Name: Dark Reading

Date Published: 2025-05-02

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

This article summarizes 23 NYCRR Part 500 and recent compliance deadlines for finance companies operating in New York, highlighting requirements introduced through phased deadlines (reporting of material cybersecurity events, annual audits, employee training, penetration testing, privileged access management, EDR, vulnerability scanning, and an eventual full asset inventory and broad MFA by Nov 1, 2025). It also captures industry viewpoints on the regulation’s prescriptiveness and the expectation that financial firms should already be implementing these cybersecurity measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.