Skip to content

Invest1 publisher2 min readPublished

New York asks its licensees to model a failure at the provider they cannot leave

New York's regulator now expects supervised firms to identify where several critical operations run through one outside provider. Its enforcement record already includes a fine for an assessment that ignored the company's own cyber risk.

The Investor · Invest desk

Illustration accompanying New York asks its licensees to model a failure at the provider they cannot leave

What happened

  • New York's financial regulator told licensed firms to identify potential single points of failure, assess concentration risk and work out how an incident at one third party would reach other critical business functions.
  • The Thursday industry letter states that it does not create new obligations under Part 500, and the department presents it as a description of how examiners already read the regulation.
  • The guidance applies to every firm the department licenses, a set that includes banks, credit unions, insurers, mortgage brokers, money transmitters and virtual currency companies.
  • An Aug. 3 consent order fined the money transmitter Order Express $250,000 following a September 2022 ransomware attack that encrypted just over half of the company's servers.
  • The letter also tells firms to weigh emerging risks, naming artificial intelligence, quantum computing's eventual threat to encryption, software supply chain attacks, changing ransomware techniques and nation-state activity.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure A limited-revenue exemption spares a licensee parts of Part 500 but not the risk-assessment charge, so a small money transmitter's assessment is examinable on the same terms as a large bank's.
  • constraint No firm can model a third-party failure before it knows what it owns, and the department says incomplete asset visibility is one of the gaps it keeps finding on examination.
  • precedent Assessment findings already sit in the enforcement record, so the letter is notice of what examiners will read, and the next citation needs no rulemaking behind it.

NYDFS wants firms to add up dependencies that look harmless one at a time. Technologies, platforms or vendors "that present limited risk when evaluated independently may collectively create significant cyber risk when multiple critical systems or business functions rely on" shared dependencies, the guidance says, and it points to common infrastructure, cloud providers, software platforms and managed service providers [12]. Last year the department asked firms to document lock-in risk and put safeguards around it. The Thursday letter asks them to work out what a failure at one of those locked-in providers would do [13]. The list of common shortcomings published with it came out of examinations, investigations and interviews with employees at supervised firms [14].

The consent order shows what an examiner counts as a failure. Order Express had an annual risk assessment; the objection was to its contents. "Although Order Express's annual risk assessment considered operational and information technology risks, the risk assessment failed to consider cybersecurity risks and threats specific to the company," the order said [7]. The assessment also "did not consider the adequacy of the controls the company did have in place," according to the order [8]. That charge came first in the order's list of violations [6], and the company was exempt from parts of Part 500 because its revenue was limited [9].

I'd expect the marginal work to land unevenly. A large bank documents analysis its resilience staff already performs; a mortgage broker whose origination system, document storage and mail all sit behind one managed service provider would start by building the asset inventory, since the department's shortcomings list includes outdated inventories, no tracking of where customer data sits, and critical business processes left out altogether [15]. The department does not publish how many firms Part 500 reaches or how many hold the limited exemption, American Banker reported [17]. A NYDFS spokesperson did not immediately respond to a request for comment [18].

There is a counter-reading. Order Express was fined after a ransomware attack, and the assessment charge may be the paperwork finding attached to an incident the department was already writing up. If assessment penalties keep arriving only behind a breach, the letter is advice and the exam risk is small. If a limited-exemption licensee is cited for a concentration analysis it never ran, with nothing encrypted, the expectation is a rule in practice. "Risk assessments are the foundation of a strong cybersecurity program," said Kaitlin Asrow, the department's acting superintendent, in a Thursday release [10].

What to watch

  • Whether the next NYDFS enforcement action lists a risk-assessment failure with no breach attached to it.
  • Whether the department ever publishes a count of firms covered by Part 500 or holding the limited exemption.
  • Whether examiners begin citing the published shortcomings list in findings at limited-exemption licensees.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories