NYDFS Publishes Revised Amendments to Its Cybersecurity Regulation – What Got Fixed, and What Still Needs Fixing
View Debevoise In Depth
Key Takeaways:
- Companies or trade groups considering making comments on the Revised Amendment have until August 14 to do so.
- NYDFS took the comments on the Initial Amendment very seriously and incorporated many of them into the Revised Amendment, including on topics such as Class A Companies, board expertise, the scope of business continuity planning, and a materiality threshold for certification.
- At the same time, NYDFS declined to address comments on certain areas, leaving room for further changes as it finalizes the Revised Amendment.
- We believe NYDFS should reconsider comments on the cadence of certain requirements, as well as maintaining backups offsite.