Credit reporting agencies will now be required to register with the state and comply with its cybersecurity regulations, the state Department of Financial Services announced Monday. The new rules are the state's response to last year's data breach at Equifax, a credit reporting agency, that exposed the personal information of 143 million people. If a credit reporting agency is found to have violated the new regulations, the DFS will now have the power to block them from serving New York state residents. Under the new rules, any credit reporting agency that ran more than 1,000 credit reports in New York state in the last year will have to register with the DFS by the beginning of September and then again at the beginning of February each year. Each credit agency will also be required to follow the state's new cybersecurity regulations, which until now only applied to banks, insurance companies and other financial institutions. Gov. Andrew Cuomo recommended that change after the breach in September. "The data breach at Equifax demonstrated the absolute necessity of strong state regulation, such as New York's first-in-the-nation cybersecurity regulation, to safeguard New York's markets, consumers and sensitive information from cyberattacks,” said Maria Vullo, superintendent of the DFS, in a statement. “DFS's oversight of credit reporting agencies will help to ensure that the personal data of New York consumers is less vulnerable to cyberattacks in this digital world, in order to prevent further breaches of consumer financial information,” Vullo said. The state's cybersecurity regulations , implemented in March 2017, were designed to prevent a massive data breach in the state's financial services industry. They require that each business have its own comprehensive cybersecurity protocol in place. That includes a program designed to protect consumer data from digital threats, a written policy about such a program that's approved by the board or a senior officer of the company, the appointment of a chief information security officer, and an incident response plan. Each company is required to assess its own risk to digital threats and establish a system to protect against those threats. If companies choose to contract their digital security through a third party, the contracted company must also develop a risk assessment plan for digital threats. Credit reporting agencies will now have to implement those changes by the beginning of November. The DFS will also be allowed to request information from those agencies at any time, but the companies will also have to submit annual reports to the department. If those agencies fail to provide information to the state, their license to serve New York state customers could be suspended or revoked. There are also practices that credit reporting agencies must avoid if they want to keep their license, the DFS said. Companies will not be allowed to engage in any schemes that might mislead or defraud a consumer and cannot hide information from consumers that was used to generate a credit report. Credit reporting agencies also risk losing their license if they ignore or report inaccurate information to a New York state consumer or state agency. A violation of any part of the federal Dodd-Frank Wall Street Reform and Consumer Protection Act could also be met with action from the DFS. The regulations were developed by the DFS with input during a public comment period held after last year's Equifax breach, the state agency said. The personal data of more than 8 million New York state residents was estimated to be involved in the breach. That included individuals' names, Social Security numbers, birth dates, addresses and driver's license numbers. Former state Attorney General Eric Schneiderman and the DFS opened their own investigations into the breach last year, with Schneiderman soon after recommending legislation to enhance data protection for state residents. State Sen. LeRoy Comrie, D-Queens, had also introduced legislation that would require credit reporting agencies to freeze consumer credit reports when a breach is detected. Neither bill passed the legislature. A spokeswoman for Equifax said the company was taking a look at the new regulations in an emailed statement Monday."Equifax is still reviewing the regulation in its entirety," the spokeswoman said. "We continue to actively engage with and be responsive to state and federal regulators, agencies, and legislators to help better protect consumers.”