N.Y.: New cyber regulations on the horizon; certification of compliance due April 15

January 17, 2023

The New York State Department of Financial Services released the official proposed second amendment to the cyber security regulation (23 NYCRR 500) for public comment late last year. This follows an unofficial draft of the amendments that circulated this past August. The amendment would make multi-factor authentication mandatory for all covered entities, increase the thresholds for entities to qualify for the limited exemption, and create a category for larger corporations, Class A entities. PIA submitted comments on both the unofficial proposal and the official proposal.

The proposed amendment, which is likely to go into effect Spring 2023, would require at least an annual review of cyber security policies and the entity’s risk assessment, a more defined period than the current regulation’s “periodically” review requirement. PIA offers members a section-by-section breakdown with all the changes to the regulation and will continue to update members as the regulation goes through the rulemaking process and into effect.

Annual certification of compliance

Those that hold a New York state insurance license (covered entities), including nonresident licensees, have until Saturday, April 15, 2023, to certify their compliance with the requirements of New York’s cyber security regulation (23 NYCRR 500) for calendar-year 2022.

The filing is required for all those not covered by another covered entity’s information system. This certification, which is required annually, must be filed via the DFS web portal between Jan. 1, 2023, and April 15, 2023. PIA members are encouraged to complete their annual certification of compliance earlier rather than waiting for the April 15 deadline.

Still have questions? Check out PIA’s Certification of compliance: a guide for more details. For more information on the cyber security regulation, access the cyber security section of PIA’s Privacy Compliance Central tool kit, which contains numerous resources for association members.

Bradford J. Lachut, Esq.
PIA Northeast |  + posts

Bradford J. Lachut, Esq., joined PIA as government affairs counsel for the Government & Industry Affairs Department in 2012 and then, after a four-month leave, he returned to the association in 2018 as director of government & industry affairs responsible for all legal, government relations and insurance industry liaison programs for the five state associations. Prior to PIA, Brad worked as an attorney for Steven J. Baum PC, in Amherst, and as an associate attorney for the law office of James Morris in Buffalo. He also spent time serving as senior manager of government affairs as the Buffalo Niagara Partnership, a chamber of commerce serving the Buffalo, N.Y., region, his hometown. He received his juris doctorate from Buffalo Law School and his Bachelor of Science degree in Government and Politics from Utica College, Utica, N.Y. Brad is an active Mason and Shriner.

Your ad could be here. ads@pia.org

Related stories…

The top benefits to offer to retain talent

The top benefits to offer to retain talent

The war for talent isn’t slowing down. In fact, a recent Gallup study showed more than half of respondents are actively exploring new job opportunities. So, how do you retain top talent in a market in which employees are rethinking where, how and why they work? The answer lies in offering benefits that meet today’s expectations. Overall, employees tend to prioritize two things: health care and flexibility. However, a well-rounded benefits package also includes mental health, financial stability, time off and growth opportunities.

AI helps families plan for long-term care

AI helps families plan for long-term care

Planning for long-term care always has been one of the most emotionally complex and financially uncertain parts of preparing for retirement. Many families delay the conversation until they’re in crisis, often leaving limited options and a heavy burden on loved ones. But artificial intelligence is starting to change that, offering a smarter, more personalized way to think about long-term care planning, and providing independent agents with new tools to help their clients prepare with confidence.

Share This