Cybersecurity requirements for financial services companies (23 NYCRR 500)

This state-level set of regulations focusing on cyber risk and cybersecurity became effective in 2017. Among other requirements, it asks covered financial services firms to perform risk assessments and due diligence on third-parties’ cybersecurity practices.