Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

Family support and broker advice key to affording homeownership today: survey

July 17, 2025

Student loan changes under Trump and the ‘big beautiful bill’

July 17, 2025

Fee income growth drove strong Q2 for U.S. Bank

July 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»New York, California amp up bank cybersecurity scrutiny
Banking

New York, California amp up bank cybersecurity scrutiny

January 13, 2025No Comments5 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
New York, California amp up bank cybersecurity scrutiny
Share
Facebook Twitter LinkedIn Pinterest Email

Over the coming year, state financial regulators in New York are expected to ratchet up their enforcement of cybersecurity regulations as amendments to these rules take effect and examiners scrutinize the details of whether and how banks implement the rules.

Recent enforcement actions by the Department of Financial Services, or NYDFS, have signaled that banks operating in the state will need to pay close attention to what exactly they do to protect nonpublic information, according to Bess Hinson-Greenspan, a partner at law firm Holland & Knight who focuses on cybersecurity and privacy litigation. Hinson-Greenspan spoke about the outlook for state cyber enforcement actions during a Wednesday event put on by the law firm.

According to NYDFS regulations, nonpublic information includes consumers’ personal information such as Social Security numbers, but unlike some other regulatory definitions of similar terms, it also broadly covers any information that “would cause a material adverse impact to the business” in the case of a data breach.

Proper handling of nonpublic information played a role in a recent enforcement action by NYDFS against Genesis Global Trading, a cryptocurrency trading company that has since gone out of business. The case ended in an $8 million penalty over failures to comply with the state’s virtual currency and cybersecurity regulations, including failures to implement policies and procedures regarding the regular disposal of nonpublic information and failure to properly encrypt this information.

Relatedly, a slate of amendments made to the NYDFS cybersecurity regulations in 2023 went into effect in November. These amendments affect governance changes to banks’ cybersecurity risk management programs, written policies about industry-standard encryption practices and written incident response plans.

See also  Bank of America Business Advantage Customized Cash Rewards vs. Amex Blue Business Cash

The last of this set of amendments will also go into effect this year. In May 2025, policies pertaining to automated vulnerability scanning, controls against malicious code, and enhanced requirements to access controls — limitations to which employees and other users can take actions on a bank’s systems — will all take effect.

Finally, by November 2025, all banks operating in New York will need to implement multifactor authentication for every individual who can access the bank’s information systems. This means both bank employees and bank customers will need to use multifactor authentication. That month, banks will also need to have implemented written policies about IT system asset inventories.

Beyond the rules and regulations, the structure that the NYDFS superintendent Adrienne Harris has built around her department’s cybersecurity regulations and enforcement actions also suggest she is ready to act this year as the final amendments take effect. Harris said during a broadcast interview in December with American Banker that the department has a team of cybersecurity-specific examiners that supplement the business units on exams.

She also highlighted the $100 million in total fines her department has issued in response to cybersecurity regulation violations, adding that she was the first superintendent of the agency to impose such fines.

Harris also highlighted the importance of adequate cybersecurity risk governance for banks, a point she said the recent amendments emphasize.

“We really wanted to make sure our institutions were paying attention to the role of the executive suite, to the role of the board, how they should be thinking about CISOs, and making sure that expertise in those governance structures were in place,” Harris said.

See also  California wildfire relief: Where to give

On the opposite coast, banks operating in California will need to pay attention to potentially increased enforcement action by the California Privacy Protection Agency, or CPPA. Established in 2020, the agency is tasked with implementing the California Privacy Rights Act, or CPRA, and the California Consumer Privacy Act, or CCPA.

The CPPA has designated rigorous enforcement of the CCPA, passed in 2018, as a primary goal in its strategic plan for 2024 to 2027. As such, enforcement of the privacy law is expected to increase, according to Hinson-Greenspan.

Most state privacy laws create exemptions for companies covered by the Gramm-Leach-Bliley Act, a federal law that governs how banks and credit unions must handle and disclose their handling of consumer data. California instead exempts personal information covered by the Gramm-Leach-Bliley Act, meaning that banks that engage in nonfinancial activities — for example, using personal data for ad targeting — must comply with the state privacy law.

The most recent example of such an enforcement action was taken against a game publisher that, according to California Attorney General Rob Bonta and Los Angeles City Attorney Hydee Feldstein Soto, violated the CCPA and federal law by collecting and sharing children’s data without parental consent. The state has also pursued cases against financial companies, but not as recently; Equifax faced a privacy-related enforcement action in 2019, as did Wells Fargo in 2016 and Citibank in 2013.

According to Hinson-Greenspan, financial institutions are often the targets of class action lawsuits related to technologies used for digital marketing and surveillance. Potential lawsuits over technologies such as tracking pixels, which provide analytics to companies about who exactly is visiting their websites, will create precedents about whether and how California’s privacy laws govern their use, she said.

See also  Why this Minnesota bank dropped its overdraft fees

“Many financial institutions are leveraging digital technologies to reach customers,” Hinson-Greenspan said. “I am sure your business units or marketing teams are presenting such solutions to you on a daily, weekly, monthly basis, and they’re constantly evolving. We expect a continued push for certainty on whether the California Invasion of Privacy Act or CIPA applies to [technologies] such as tracking pixels, session replay software and chatbots.”

Source link

amp Bank California Cybersecurity scrutiny York
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleHow much is a gold bar worth?
Next Article How L.A. Businesses Can Get Help After the Fire

Related Posts

Fee income growth drove strong Q2 for U.S. Bank

July 17, 2025

How to break up with your bank (and take your money somewhere better)

July 17, 2025

Bank of America (BAC) earnings Q2 2025

July 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Best credit union savings account rates

April 4, 2025

Save Money with a Home Spa Day

February 14, 2025

Trump said tariff revenue could replace income tax. What economists say

April 23, 2025
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

Family support and broker advice key to affording homeownership today: survey

July 17, 2025

Student loan changes under Trump and the ‘big beautiful bill’

July 17, 2025

Fee income growth drove strong Q2 for U.S. Bank

July 17, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.