On March 1, 2017, the New York State Department of Financial Services’ (NYDFS) Cybersecurity Requirements for Financial Services Companies, 23 NYCRR 500 (Part 500), became effective. NYDFS describes Part 500 as a first-of-its-kind state regulation that created mandatory cybersecurity and risk management regulations for Covered Entities. Part 500 defines Covered Entities as persons operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law.

Since Part 500 became effective, NYDFS’ focus on cybersecurity has been robust. The NYDFS website includes a Cybersecurity Resource Center, which offers various cybersecurity-related information published by NYDFS over the years, such as cybersecurity guidance, alerts and reports. Perhaps most notably is the NYDFS’ Guidance on Ransomware Prevention.