<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Harvard Law School Forum on Corporate Governance</title>
	<atom:link href="https://corpgov.law.harvard.edu/2017/03/25/new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect/feed/" rel="self" type="application/rss+xml" />
	<link>https://corpgov.law.harvard.edu</link>
	<description>The leading online blog in the fields of corporate governance and financial regulation.</description>
	<lastBuildDate>Mon, 10 Aug 2026 11:32:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.9</generator>

<image>
	<url>https://corpgov.law.harvard.edu/wp-content/uploads/2024/02/cropped-photography-4-e1706898544564-1-32x32.png</url>
	<title>New York Cybersecurity Regulations for Financial Institutions Enter Into Effect &#8211; The Harvard Law School Forum on Corporate Governance</title>
	<link>https://corpgov.law.harvard.edu</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>New York Cybersecurity Regulations for Financial Institutions Enter Into Effect</title>
		<link>https://corpgov.law.harvard.edu/2017/03/25/new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect</link>
		<comments>https://corpgov.law.harvard.edu/2017/03/25/new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect/#comments</comments>
		<pubDate>Sat, 25 Mar 2017 13:52:20 +0000</pubDate>
<!-- 		<dc:creator><![CDATA[]]></dc:creator> -->
				<category><![CDATA[Accounting & Disclosure]]></category>
		<category><![CDATA[Banking & Financial Institutions]]></category>
		<category><![CDATA[Financial Regulation]]></category>
		<category><![CDATA[Legislative & Regulatory Developments]]></category>
		<category><![CDATA[Practitioner Publications]]></category>
		<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Financial institutions]]></category>
		<category><![CDATA[Financial regulation]]></category>
		<category><![CDATA[New York]]></category>
		<category><![CDATA[Oversight]]></category>
		<category><![CDATA[State law]]></category>

		<guid isPermaLink="false">https://corpgov.law.harvard.edu/?p=80204?d=20170325095233EDT</guid>
		<description><![CDATA[While the New York Cybersecurity Regulations represent a softening in key respects from the requirements set forth in the initial proposal, the regulations impose minimum standards that exceed existing federal standards and introduce new requirements, including obligations to critically evaluate cybersecurity practices to ensure compliance, maintain detailed documentation demonstrating compliance and report cyber events to [&#8230;]]]></description>
				<content:encoded><![CDATA[<hgroup><em>Posted by Michael Krimminger, Cleary Gottlieb Steen & Hamilton LLP, on Saturday, March 25, 2017 </em><div class='e_n' style='background:#F8F8F8;padding:10px;margin-top:5px;margin-bottom:10px;text-indent:2.5em;'><strong style='margin-left:-2.5em;'>Editor's Note: </strong> <p style="margin:0; display:inline;"><a href="https://www.clearygottlieb.com/professionals/michael-h-krimminger">Michael Krimminger</a> is a partner at Cleary Gottlieb Steen &amp; Hamilton LLP. This post is based on a Cleary Gottlieb publication by Mr. Krimminger, <a href="https://www.clearygottlieb.com/professionals/jonathan-s-kolodner">Jonathan Kolodner</a>, <a href="https://www.clearygottlieb.com/professionals/daniel-ilan">Daniel Ilan</a> and <a href="https://www.clearygottlieb.com/professionals/katie-dunn">Katie Dunn</a>.</p>
</div></hgroup><p>While the New York Cybersecurity Regulations represent a softening in key respects from the requirements set forth in the initial proposal, the regulations impose minimum standards that exceed existing federal standards and introduce new requirements, including obligations to critically evaluate cybersecurity practices to ensure compliance, maintain detailed documentation demonstrating compliance and report cyber events to the New York Department of Financial Services.</p>
<h2>Overview</h2>
<p>On March 1, 2017, the New York Department of Financial Services’ (DFS) Cybersecurity Regulations (the Regulations) entered into effect. <a class="footnote" id="1b" href="https://corpgov.law.harvard.edu/2017/03/25/new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect/#1">[1]</a> Under the Regulations, any individual or non-governmental partnership, corporation, branch, agency, association or other entity operating under a license, registration, charter, certificate, permit, accreditation or similar authorization under New York banking, insurance or financial services laws (with narrow exceptions described below) (Covered Entities) is required to formally assess its cybersecurity risks and establish and maintain a cybersecurity program designed to address such risks in a “robust” fashion.</p>
<p> <a href="https://corpgov.law.harvard.edu/2017/03/25/new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect/#more-80204" class="more-link"><span aria-label="Continue reading New York Cybersecurity Regulations for Financial Institutions Enter Into Effect">(more&hellip;)</span></a></p>
]]></content:encoded>
			<wfw:commentRss>https://corpgov.law.harvard.edu/2017/03/25/new-york-cybersecurity-regulations-for-financial-institutions-enter-into-effect/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
