02.07.2017

Cyber-Security Re-Defines Business Structure

02.07.2017

bThe New York State Department of Financial Services’ new cyber-security regulations CC 23 NYCRR 500 takes effect on February 15, and financial institutions will need to change how they approach cyber-security.

After decades of outsourcing IT processes and staff, financial institutions will need to bring their information security responsibility back in-house.

Firms that fall under the regulation’s mandate will need to put a cyber-security program in place and name a chief information security officer who will take the ultimate responsibility of meeting the regulation’s requirements.

Josh Barons, Abacus Group

Josh Barons,
Abacus Group

“A lot of firms, however, are looking at the exceptions rather than what the best practices are and what the guidelines in the requirements would be,” said Josh Barons, director of information security at Abacus Group.

Financial firms that employ fewer than 10 people (including contractors), has less than $5,000,000 in annual revenue for the past three years, or have year-end assets of less than $10 million are exempt from a majority of NYSDFS’ cyber-security regulation.

Whether firms must comply with the full regulation or a portion of it, it is only a matter of time before financial regulators in other states write similar rules, said Barons.

“We saw the same sort of thing when Massachusetts worked on its privacy requirements and breach-notification laws,” he added. “Once one state does it, soon there is a flood of other states follow.”

The typical model of placing the responsibility for information security into the IT organization, will not hold up, according to Barons.

“I think it is going to be a lot harder to say that someone who already wears seven hats now has this responsibility too,” he said.

Barons views the responsibility for information security being a c-level position with access to the board, knowledge of the company products, and participates in day-to-day operations.

“It should not be stuck in a closet of a back room,” he said.

Overall, Barons grades the financial services vertical a ‘B’ in its overall preparedness for the new regulation but uses a curve, he admitted.

“You have banks that have a lot of funding, mature cyber-security programs, and full backing from the top down,” said Barons. “Then you have smaller firms where they do not have any of that.”

However, there are resources, such as the US Department of Commerce’s National Institute of Standards and Technology that can help firms implement the necessary best practices with its 800 series publications.

“Most of the regulatory requirements that we have seen over the past several years are based on NIST’s best practices, especially when it comes to Federal and other governmental regulations,” he said.

Pension funds, sovereign wealth funds, endowments and other institutional asset owners are sitting on vast troves of data -- but extracting value from that data is more challenging than ever.

#AssetOwners #DataQuality

Technology costs in asset management have grown disproportionately, but McKinsey research finds the increased spending hasn’t consistently translated into higher productivity.
#AI #Fiance

We're in the FINAL WEEK for the European Women in Finance Awards nominations – don't miss your chance to spotlight the incredible women driving change in finance!
#WomenInFinance #FinanceAwards #FinanceCommunity #EuropeanFinance @WomeninFinanceM

ICYMI: @marketsmedia sat down with EDXM CEO Tony Acuña-Rohter to discuss the launch of EDXM International’s perpetual futures platform in Singapore and what it means for institutional crypto trading.
Read the full interview: https://bit.ly/45xRUWh

Load More

Related articles

  1. The SEC erased nearly a year’s worth of text messages sent and received by former Chair Gary Gensler.

  2. Cyber-Criminals Target Wall Street

    The regulator's emails and email attachments were subject to unauthorized access.

  3. Cyber-Criminals Target Wall Street

    PQC aims to strengthen communication and data security as quantum computing advances.

  4. Wall Street Confronts Cyber Threats

    The DORA compliance deadline is just three months away.

  5. Quantum computing poses a major cybersecurity concern as it can break cryptography & encryption algorithms.

We're Enhancing Your Experience with Smart Technology

We've updated our Terms & Conditions and Privacy Policy to introduce AI tools that will personalize your content, improve our market analysis, and deliver more relevant insights.These changes take effect on Aug 25, 2025.
Your data remains protected—we're simply using smart technology to serve you better. [Review Full Terms] | [Review Privacy Policy] By continuing to use our services after Aug 25, 2025, you agree to these updates.

Close the CTA