Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

Stocks making the biggest moves midday: MS, ASML, JNJ, SEDG

July 17, 2025

M&T Bank outperforms expectations in second quarter

July 17, 2025

Chase Sapphire Reserve vs. Venture X vs. Amex Platinum

July 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»New York, California amp up bank cybersecurity scrutiny
Banking

New York, California amp up bank cybersecurity scrutiny

January 13, 2025No Comments5 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
New York, California amp up bank cybersecurity scrutiny
Share
Facebook Twitter LinkedIn Pinterest Email

Over the coming year, state financial regulators in New York are expected to ratchet up their enforcement of cybersecurity regulations as amendments to these rules take effect and examiners scrutinize the details of whether and how banks implement the rules.

Recent enforcement actions by the Department of Financial Services, or NYDFS, have signaled that banks operating in the state will need to pay close attention to what exactly they do to protect nonpublic information, according to Bess Hinson-Greenspan, a partner at law firm Holland & Knight who focuses on cybersecurity and privacy litigation. Hinson-Greenspan spoke about the outlook for state cyber enforcement actions during a Wednesday event put on by the law firm.

According to NYDFS regulations, nonpublic information includes consumers’ personal information such as Social Security numbers, but unlike some other regulatory definitions of similar terms, it also broadly covers any information that “would cause a material adverse impact to the business” in the case of a data breach.

Proper handling of nonpublic information played a role in a recent enforcement action by NYDFS against Genesis Global Trading, a cryptocurrency trading company that has since gone out of business. The case ended in an $8 million penalty over failures to comply with the state’s virtual currency and cybersecurity regulations, including failures to implement policies and procedures regarding the regular disposal of nonpublic information and failure to properly encrypt this information.

Relatedly, a slate of amendments made to the NYDFS cybersecurity regulations in 2023 went into effect in November. These amendments affect governance changes to banks’ cybersecurity risk management programs, written policies about industry-standard encryption practices and written incident response plans.

See also  This week’s economic watchlist: CPI, home sales and the Bank of Canada

The last of this set of amendments will also go into effect this year. In May 2025, policies pertaining to automated vulnerability scanning, controls against malicious code, and enhanced requirements to access controls — limitations to which employees and other users can take actions on a bank’s systems — will all take effect.

Finally, by November 2025, all banks operating in New York will need to implement multifactor authentication for every individual who can access the bank’s information systems. This means both bank employees and bank customers will need to use multifactor authentication. That month, banks will also need to have implemented written policies about IT system asset inventories.

Beyond the rules and regulations, the structure that the NYDFS superintendent Adrienne Harris has built around her department’s cybersecurity regulations and enforcement actions also suggest she is ready to act this year as the final amendments take effect. Harris said during a broadcast interview in December with American Banker that the department has a team of cybersecurity-specific examiners that supplement the business units on exams.

She also highlighted the $100 million in total fines her department has issued in response to cybersecurity regulation violations, adding that she was the first superintendent of the agency to impose such fines.

Harris also highlighted the importance of adequate cybersecurity risk governance for banks, a point she said the recent amendments emphasize.

“We really wanted to make sure our institutions were paying attention to the role of the executive suite, to the role of the board, how they should be thinking about CISOs, and making sure that expertise in those governance structures were in place,” Harris said.

See also  Blue Ridge returns to community bank roots after failed fintech foray

On the opposite coast, banks operating in California will need to pay attention to potentially increased enforcement action by the California Privacy Protection Agency, or CPPA. Established in 2020, the agency is tasked with implementing the California Privacy Rights Act, or CPRA, and the California Consumer Privacy Act, or CCPA.

The CPPA has designated rigorous enforcement of the CCPA, passed in 2018, as a primary goal in its strategic plan for 2024 to 2027. As such, enforcement of the privacy law is expected to increase, according to Hinson-Greenspan.

Most state privacy laws create exemptions for companies covered by the Gramm-Leach-Bliley Act, a federal law that governs how banks and credit unions must handle and disclose their handling of consumer data. California instead exempts personal information covered by the Gramm-Leach-Bliley Act, meaning that banks that engage in nonfinancial activities — for example, using personal data for ad targeting — must comply with the state privacy law.

The most recent example of such an enforcement action was taken against a game publisher that, according to California Attorney General Rob Bonta and Los Angeles City Attorney Hydee Feldstein Soto, violated the CCPA and federal law by collecting and sharing children’s data without parental consent. The state has also pursued cases against financial companies, but not as recently; Equifax faced a privacy-related enforcement action in 2019, as did Wells Fargo in 2016 and Citibank in 2013.

According to Hinson-Greenspan, financial institutions are often the targets of class action lawsuits related to technologies used for digital marketing and surveillance. Potential lawsuits over technologies such as tracking pixels, which provide analytics to companies about who exactly is visiting their websites, will create precedents about whether and how California’s privacy laws govern their use, she said.

See also  Amid high tariff fallout, here’s how to earn more interest on your savings account

“Many financial institutions are leveraging digital technologies to reach customers,” Hinson-Greenspan said. “I am sure your business units or marketing teams are presenting such solutions to you on a daily, weekly, monthly basis, and they’re constantly evolving. We expect a continued push for certainty on whether the California Invasion of Privacy Act or CIPA applies to [technologies] such as tracking pixels, session replay software and chatbots.”

Source link

amp Bank California Cybersecurity scrutiny York
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleHow much is a gold bar worth?
Next Article How L.A. Businesses Can Get Help After the Fire

Related Posts

M&T Bank outperforms expectations in second quarter

July 17, 2025

Mastercard, JPMorganChase, Citigroup discuss stablecion plans | PaymentsSource

July 16, 2025

Fed’s Barr fears deregulation is a prelude to calamity

July 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

How to Pick Windows: 5 Factors to Consider

May 10, 2025

Fintech unicorns watch Klarna IPO for signs of when window will reopen

November 19, 2024

How Jenius Bank can afford to pay 4.8% on savings

January 4, 2025
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

Stocks making the biggest moves midday: MS, ASML, JNJ, SEDG

July 17, 2025

M&T Bank outperforms expectations in second quarter

July 17, 2025

Chase Sapphire Reserve vs. Venture X vs. Amex Platinum

July 17, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.