NYDF Issues Cybersecurity Guidance for Financial Firms

NYDF issued guidance this week setting baseline cybersecurity controls, incident reporting and third-party risk expectations for banks, insurers, payment firms and fintechs.

NYDF published new cybersecurity guidance this week for banks, insurers, payment firms and fintechs, laying out baseline technical controls, incident-response requirements and third-party risk-management expectations to reduce disruptive cyber incidents.

The guidance lists specific measures firms should adopt to protect customer data and maintain service continuity. It covers governance and board oversight, regular risk assessments, network segmentation, multi-factor authentication, encryption of sensitive data and formalized incident response plans with communication protocols for regulators and law enforcement. The document advises firms to run tabletop exercises and to test recovery procedures on a regular schedule.

NYDF recommends a risk-based approach that aligns technical controls with business priorities. Firms are asked to keep current inventories of critical systems and third-party dependencies, perform continuous monitoring for anomalous activity, and enforce strict access controls and comprehensive logging to support timely detection and investigation. The guidance directs firms to include cyber risk in enterprise risk management and to provide regular briefings to senior management and boards while documenting decisions about residual risk and accepted exceptions.

The regulator places particular emphasis on third-party and cloud provider oversight. Expectations for vendor programs include security attestations, penetration-test results and contractual rights to audit and receive prompt incident notifications from service providers.

The guidance identifies ransomware, supply-chain intrusions and automated attacks as prominent threats. It also highlights agentic AI systems and automated payment agents as emerging technologies that can introduce new attack vectors if not assessed and governed before deployment.

NYDF sets out incident-reporting requirements that call for prompt notification of material cyber events and follow-up reports that describe root-cause analysis and remediation steps. Firms are encouraged to participate in information-sharing arrangements and to coordinate with other industry participants and authorities during complex incidents to limit systemic impact.

The regulator will review firms’ progress during routine examinations and indicated it will use supervisory exams and enforcement where necessary to ensure compliance. Background materials included with the guidance offer examples of control implementation, a template for board-level reporting and suggested timelines for short- and medium-term actions. According to a NYDF spokesperson, “We expect firms to translate these recommendations into concrete controls and to demonstrate clear governance over cyber risk.”

Articles by this author