02.07.2017

Cyber-Security Re-Defines Business Structure

02.07.2017

bThe New York State Department of Financial Services’ new cyber-security regulations CC 23 NYCRR 500 takes effect on February 15, and financial institutions will need to change how they approach cyber-security.

After decades of outsourcing IT processes and staff, financial institutions will need to bring their information security responsibility back in-house.

Firms that fall under the regulation’s mandate will need to put a cyber-security program in place and name a chief information security officer who will take the ultimate responsibility of meeting the regulation’s requirements.

Josh Barons, Abacus Group

Josh Barons,
Abacus Group

“A lot of firms, however, are looking at the exceptions rather than what the best practices are and what the guidelines in the requirements would be,” said Josh Barons, director of information security at Abacus Group.

Financial firms that employ fewer than 10 people (including contractors), has less than $5,000,000 in annual revenue for the past three years, or have year-end assets of less than $10 million are exempt from a majority of NYSDFS’ cyber-security regulation.

Whether firms must comply with the full regulation or a portion of it, it is only a matter of time before financial regulators in other states write similar rules, said Barons.

“We saw the same sort of thing when Massachusetts worked on its privacy requirements and breach-notification laws,” he added. “Once one state does it, soon there is a flood of other states follow.”

The typical model of placing the responsibility for information security into the IT organization, will not hold up, according to Barons.

“I think it is going to be a lot harder to say that someone who already wears seven hats now has this responsibility too,” he said.

Barons views the responsibility for information security being a c-level position with access to the board, knowledge of the company products, and participates in day-to-day operations.

“It should not be stuck in a closet of a back room,” he said.

Overall, Barons grades the financial services vertical a ‘B’ in its overall preparedness for the new regulation but uses a curve, he admitted.

“You have banks that have a lot of funding, mature cyber-security programs, and full backing from the top down,” said Barons. “Then you have smaller firms where they do not have any of that.”

However, there are resources, such as the US Department of Commerce’s National Institute of Standards and Technology that can help firms implement the necessary best practices with its 800 series publications.

“Most of the regulatory requirements that we have seen over the past several years are based on NIST’s best practices, especially when it comes to Federal and other governmental regulations,” he said.

Markets Media Group was pleased to host the 2025 European Women in Finance Awards last night at Claridge’s in London.
#WomeninFinance #WIF #EuropeanFinance #FinanceCommunity

See the full list of winners here: https://www.marketsmedia.com/2025-european-women-in-finance-awards-the-winners/

3

We are excited to announce the finalists for the 2025 U.S. Women in Finance Awards! Congratulations to all!

Check out the full list here:


#WomeninFinance #WIF #financeindustry

Nominations are NOW OPEN for the 2026 Women in Finance LatAm Awards! Do you know a standout leader, innovator, or rising star? Nominate her today!

Learn more & submit your nomination:

#WomeninFinance #Finance #WIF

HSBC AI Markets harnesses natural language processing to meet market participants’ trading and hedging needs, from pre-trade analysis, to execution, to post-trade. Markets Media caught up with Tom Croft to learn more about the platform.

#AIMarkets

Load More

Related articles

  1. The SEC erased nearly a year’s worth of text messages sent and received by former Chair Gary Gensler.

  2. Cyber-Criminals Target Wall Street

    The regulator's emails and email attachments were subject to unauthorized access.

  3. Cyber-Criminals Target Wall Street

    PQC aims to strengthen communication and data security as quantum computing advances.

  4. Wall Street Confronts Cyber Threats

    The DORA compliance deadline is just three months away.

  5. Quantum computing poses a major cybersecurity concern as it can break cryptography & encryption algorithms.

We're Enhancing Your Experience with Smart Technology

We've updated our Terms & Conditions and Privacy Policy to introduce AI tools that will personalize your content, improve our market analysis, and deliver more relevant insights.These changes take effect on Aug 25, 2025.
Your data remains protected—we're simply using smart technology to serve you better. [Review Full Terms] | [Review Privacy Policy] Please review our updated Terms & Conditions and Privacy Policy carefully. By continuing to use our services after Aug 25, 2025, you agree to these

Close the CTA