The New Vendor Management World Under NYDFS' New Cyber Regulation
To overcome the challenges in maintaining compliance after the deadline, covered entities must implement a highly structured and organized approach to vendor management, with consistent application of thoughtful, risk-based rules, all within a third-party ecosystem growing in size, complexity and risk.
March 28, 2019 at 07:00 AM
5 minute read
As of March 1, 2019, the New York State Department of Financial Services' (NYDFS) cybersecurity regulation, 23 NYCRR Part 500, requires financial services institutions regulated by NYDFS to implement policies and procedures to address the cybersecurity risks posed by third-party service providers to the institutions' nonpublic information (NPI).
While reaching the March 1 deadline has been a monumental task for many covered entities, it is only the first step in maintaining a compliant vendor management program in this new world of cybersecurity regulation. To manage the risks and potential liability that come with this “first of its kind” cyber regulation, covered entities must implement an ongoing program that in most cases will reflect a sea change from their prior practices. In particular, the required oversight and management of third-party service providers, or TPSPs, will expand well beyond traditional vendor management functions and deep into contracting, diligence and stakeholder review.
The Requirements of the NYDFS Regulation
The regulation requires covered entities to implement written, risk-based and consistently applied policies and procedures for managing the cybersecurity risks posed by TPSPs. In particular, the policies and procedures must:
- Describe how to identify relevant TPSPs, and assess their risks;
- Establish minimum cybersecurity standards for TPSPs;
- Define the entity's due diligence process for TPSP cybersecurity practices; and
- Provide for periodic risk reassessment of TPSPs and their cybersecurity practices.
In addition, the policies and procedures must include particular guidelines for due diligence and contracting relating to cybersecurity. These guidelines must address:
- The TPSP's access controls, including multifactor authentication;
- The TPSP's use of encryption to protect NPI both in transit and at rest;
- Notification from the TPSP of cybersecurity incidents impacting the covered entity's systems or information; and
- Contractual protections regarding the TPSP's cybersecurity practices
While the regulation establishes clear requirements for the policies and procedures and what issues must (at minimum) be addressed in those policies and procedures, the regulation offers considerable flexibility to covered entities in determining their own approach to managing the cybersecurity risks posed by TPSPs. Thus, the policies and procedures need not conform to any particular standard or approach so long as they are reasonable and appropriate to the covered entity's overall cybersecurity risk profile. And, importantly, so long as the covered entity follows these policies and procedures once implemented.
Maintaining Compliance Will Be Challenging
Number and Type of Vendors: A key challenge facing covered entities is the sheer number, diversity and complexity of applicable TPSPs. Specifically, the definition of a TPSP under the regulation is a “Person that (i) is not an Affiliate of the Covered Entity, (ii) provides services to the Covered Entity, and (iii) maintains, processes or otherwise is permitted access to Nonpublic Information through its provision of services to the Covered Entity.” 23 NYCRR § 500.01(n). For most covered entities, these TPSP relationships range from traditional vendors—such as IT and business process outsourcers, hosting providers, cloud and SaaS providers and application developers—to less apparent providers that are not part of traditional procurement processes, such as consultants, auditors, law firms and even independent agents. Further, with increased adoption of cloud computing and other innovations, the portfolio of vendors for most companies is expanding at an increasing rate.
Investment in Risk Management: As noted above, the NYDFS regulation places a significant emphasis on the contracting and diligence process, including to methodically and consistently evaluate and address the risks posed by TPSPs, with appropriate stakeholder involvement. These processes thus will require a large investment of time and process, applied to each TPSP relationship. Further, the new diligence requirements require periodic reviews throughout the term of the parties' relationship. Thus, most covered entities are required to establish not only a whole new management infrastructure but also a new way of doing business that allows for the time and effort to incorporate these activities into the vendor management process.
Applicable Data and Information: A further challenge is that the definition of “Nonpublic Information” under the regulation is broader than what is generally considered to constitute applicable information under established privacy and cybersecurity laws. Specifically, the NYDFS definition includes not only personal and health information but also “business related information … the tampering with which, or unauthorized disclosure, access or use of which, would cause a material adverse impact to the business, operations or security of the Covered Entity.” 23 NYCRR § 500.01(g). Thus, several vendor relationships that previously were not critical from a regulatory perspective—because, for example, no personal information was involved—may now be covered under the NYDFS regulation.
Not Just a Going-Forward Requirement: Covered entities must address not only new vendors and new services on a going-forward basis but also legacy vendors under legacy agreements. In many cases, these legacy agreements, and the programs in which the vendors were established and have been managed, will be inadequate under the new guidelines and changing market expectations of how financial institutions are to manage cybersecurity risks from third parties.
Summary
Achieving compliance by the March 1, 2019, deadline imposed by the NYDFS cybersecurity regulation was a crucial step for covered entities. But to overcome the challenges in maintaining compliance after the deadline, covered entities must implement a highly structured and organized approach to vendor management, with consistent application of thoughtful, risk-based rules, all within a third-party ecosystem growing in size, complexity and risk. This new approach to vendor management will mean not only a new level of focus and coordination for covered entities' business owners, procurement groups and vendor management departments, but also an increasingly important and central role for their legal departments.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Pro Hac Vice in Georgia: Rule Change for Nonresident Attorneys
- 2The Benefits of E-Filing for Affordable, Effortless and Equal Access to Justice
- 3AI and Social Media Fakes: Are You Protecting Your Brand?
- 4A Primer on Using Third-Party Depositions To Prove Your Case at Trial
- 5‘Catholic Charities v. Wisconsin Labor and Industry Review Commission’: Another Consequence of 'Hobby Lobby'?
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250