| 1 minute read

NYDFS Amendment to Cybersecurity Regulation

nys dfs seal

Avalon previously reported on proposed changes that may have a significant impact on the current 23 NYCRR Part 500 – Cybersecurity Requirements for Financial Services Companies (the Cybersecurity Regulation or Part 500) released by the New York State Department of Financial Services (NYSDFS). 

Part 500, a regulation establishing cybersecurity requirements for financial services companies, was declared by the Superintendent of Financial Services, and has been in place since March 2017.

Since adoption, the cybersecurity landscape has changed, and attacks have become more sophisticated and more expensive. There are many additional controls to help mitigate these threats that should be implemented by organizations to help protect themselves and, as such, on November 1, 2023, Part 500 was amended to help align with these changes and push for better security for financial services companies.

Please go to https://www.dfs.ny.gov/industry_guidance/cybersecurity for more information on the updates and related resources including available training sessions and implementation timelines for small businesses, Class A businesses, and covered entities.

Avalon can assist your organization with staying or becoming compliant through many of our services, including vCISO, vendor management, policy creation, and risk assessment.

Blog Articles

The Cost of Cyberattacks: Financial & Reputational Risks for Law Firms

When attorneys think about cyberattacks, they often focus on the immediate crisis – encrypted files, compromised credentials, ransomware demands, or stolen client data. Yet the true impact of a law firm data breach extends far beyond the initial incident. Cybersecurity threats create a dual risk: 1) significant financial losses from downtime, recovery costs, regulatory exposure, and 2) potential malpractice claims, along with long-term reputational damage that can erode client trust, harm brand credibility, and affect future business development.

The Top 10 Cyber Gaps We See in Law Firms

Law firms and in-house legal departments possess some of the most sensitive and valuable data anywhere – from personally identifiable information (PII) and corporate deal terms to litigation strategies and privileged communications. This makes the legal sector a particularly attractive target for cybercriminals. Yet, across countless engagements, Avalon’s cyber experts continue to see recurring cybersecurity gaps in legal organizations of every size.

Employee Spotlight: Sarah Faherty

Every once in a while, we like to show off one of our hard-working, detail-oriented problem solvers. Take a moment to see who's in the spotlight today!