NYDFS Issues Guidance on Cybersecurity Controls to Combat Ransomware and Clarifies Reporting Obligations

Lance Taubin, Kate Hanniford, and Kimberly Peretti of Alston & Bird write:

The New York Department of Financial Services (NYDFS) issued new guidance this week intended to assist organizations in thwarting ransomware attacks. The guidance clarifies the NYDFS’ expectation that NYDFS-regulated companies should “implement these controls whenever possible” and report any successful deployment of ransomware or unauthorized access to privilege accounts to the NYDFS under its established cybersecurity event reporting regulations.

Read more on Privacy, Cyber & Data Strategy Blog.

About the author: Dissent

Comments are closed.