Published Invest3 min read
New York names a vendor's product, admits banks can't fix it, and hands the file to the board
NYDFS told every bank it supervises to hunt for N-able's N-central in their supply chains, conceded the exposure is probably not theirs, and cited the regulation that makes senior governing bodies answerable anyway.
Context for builders, not their beat.See today for builders

What happened
- On Tuesday, the New York State Department of Financial Services told every bank it oversees to determine "whether N-central is used within their environment or by any MSP or other Third-Party Service Provider that supports their information systems."
- The software named is N-central, sold by a company called N-able; IT firms use it to monitor, patch and remotely control the computers of the businesses that hire them.
- The NYDFS letter conceded the problem "is likely limited to MSPs," shorthand for managed service providers, which manage portions of their customers' businesses such as IT and network management, payroll and supply chains.
- The letter said the "senior governing bodies and senior officers" of regulated firms "must actively engage in cybersecurity risk management, including through monitoring and oversight of third-party service providers."
- Attackers have been breaking into N-central since July 31.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
New York's Department of Financial Services told every bank it oversees on Tuesday to determine whether a specific commercial product, N-able's N-central, is running in their environment or at any managed service provider or other third-party service provider that supports their information systems [1][2]. In the same letter the department conceded the problem "is likely limited to MSPs" and then assigned oversight of it to the "senior governing bodies and senior officers" of regulated firms [3][4].
N-central is remote monitoring and management software; IT firms use it to monitor, patch and remotely control the computers of the businesses that hire them [2]. Attackers have been breaking into it since July 31 [5]. According to the letter, an intruder in an N-central server can move into customer networks "with administrator network privileges" and can "create or register for new services, allowing continued access even after compromised N-central credentials are revoked" [6]. That persistence is the real hazard. The observed damage, though, is small: researchers at Sophos found "a single compromised organization" in the firm's customer data [7], and on public information no bank has been caught out by the vulnerability [8]. NYDFS has not said how many banks rely on providers that run N-central [9], and a department spokesperson did not immediately respond to questions about why it singled out the product [10].
Naming a flawed product is not new here. By American Banker's review of every cybersecurity industry letter NYDFS has published, Tuesday's was the eighth such naming since 2020 [11][12]. The break with the previous seven is mechanical: those flaws hit banks directly as well as their vendors, so a bank could respond by patching its own systems [13]. With N-central there is nothing to patch [14]. The only available response is to interrogate vendors, and vendors' vendors [15].
The load-bearing phrase is "senior governing bodies and senior officers," which matches text the department added to its cybersecurity regulation in a 2023 amendment [16]. American Banker did not find that phrase in any of the seven earlier product alerts [17]. The guidance letter itself is nonbinding, but it points to binding rules [18], which is how a housekeeping exercise becomes a governance obligation: boards must actively engage in cybersecurity risk management, including monitoring and oversight of third-party service providers [4]. American Banker describes Tuesday's letter as the first time NYDFS has told bank leaders to manage a specific third-party cybersecurity threat [19].
Lisa Sotto, chair of Hunton Andrews Kurth's global privacy and cybersecurity practice, framed the incentive: "Playing possum won't fly if there is a vendor issue brewing that is reasonably likely to impact the covered entity" [20].
For scale, more than 500,000 businesses worldwide use N-able's software, according to the company [21]. N-able filed a quarterly report and a current report with the SEC the day before the alert, and neither mentions the vulnerability or the break-ins [22]. The company did not immediately respond to a request for comment [23].
Watch whether the "senior governing bodies" formulation shows up in the next product-specific letter, which would make it the department's standing posture rather than a one-off; whether examiners start asking for documentary evidence that the vendor inquiry happened and reached the board; and whether N-able's SEC disclosure position moves.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On Tuesday, the New York State Department of Financial Services told every bank it oversees to determine "whether N-central is used within their environment or by any MSP or other Third-Party Service Provider that supports their information systems."
- [2]
The software named is N-central, sold by a company called N-able; IT firms use it to monitor, patch and remotely control the computers of the businesses that hire them.
ReportedView cited source - [3]
The NYDFS letter conceded the problem "is likely limited to MSPs," shorthand for managed service providers, which manage portions of their customers' businesses such as IT and network management, payroll and supply chains.
- [4]
The letter said the "senior governing bodies and senior officers" of regulated firms "must actively engage in cybersecurity risk management, including through monitoring and oversight of third-party service providers."
- [6]
Attackers who get into an N-central server can move into customers' networks "with administrator network privileges" and can "create or register for new services, allowing continued access even after compromised N-central credentials are revoked," according to the NYDFS letter.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- americanbanker.comCarter PapeAug 13New York puts bank boards on the hook for vendor tech
Additional citations
- American Banker, quoting the NYDFS industry letter
- NYDFS letter as quoted by American Banker
- Sophos, via American Banker
- American Banker
- American Banker review
- Lisa Sotto, Hunton Andrews Kurth, via American Banker
- N-able, via American Banker



