{"id":129,"date":"2018-07-02T10:20:40","date_gmt":"2018-07-02T14:20:40","guid":{"rendered":"https:\/\/pbacyber.com\/?p=129"},"modified":"2019-04-12T11:01:36","modified_gmt":"2019-04-12T15:01:36","slug":"new-yorks-cyber-regulations-now-apply-to-credit-reporting-agencies","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2018\/07\/02\/new-yorks-cyber-regulations-now-apply-to-credit-reporting-agencies\/","title":{"rendered":"New York\u2019s Cyber Regulations Now Apply to Credit Reporting Agencies"},"content":{"rendered":"<p>By\u00a0<a href=\"https:\/\/www.whiteandwilliams.com\/lawyers-JoshuaMooney.html\" target=\"_blank\" rel=\"noopener noreferrer\">Josh Mooney<\/a> and <a href=\"https:\/\/www.whiteandwilliams.com\/lawyers-EmmaBechara.html\" target=\"_blank\" rel=\"noopener noreferrer\">Emma Bechara<\/a>, <a href=\"https:\/\/www.whiteandwilliams.com\" target=\"_blank\" rel=\"noopener noreferrer\">White and Williams LLP<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>On June 25, 2018, the New York Department of Financial Services (NYDFS) issued a final regulation that requires any credit reporting agency (CRA) with \u201csignificant operations\u201d in New York to register with the NYDFS and comply with the NYDFS cyber regulations under Part 500. CRAs must register by September 15, 2018. Significantly, as outlined below, CRAs also must begin complying with New York\u2019s cyber regulations as early as November 1, 2018 \u2013 <em>i.e.<\/em>, in four months.<span id=\"more-523\"><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>By November 1, covered CRAs must have appointed a chief information security officer and have implemented a written cybersecurity program, including an incident response plan, that are designed to safeguard the confidentiality, integrity and availability of the organization\u2019s information systems. Further, the CRA must base its cybersecurity program upon a conducted risk assessment, and it must have designed the program to enable the CRA to identify, detect, respond to and recover from a reportable \u201ccybersecurity event.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>Under the regulations, CRAs will have a maximum of 72 hours to report a \u201ccybersecurity event\u201d to the NYDFS. This is a significant uptick from previous reporting requirements under New York law, which enabled CRAs to take weeks or even longer to report an event. Finally, and significantly, a member of the board of directors or a senior officer of each CRA now must certify annually to the NYDFS the agency\u2019s compliance with the regulations. The first certification is due on February 15, 2019.<\/p>\n<p>&nbsp;<\/p>\n<p>The new regulation also comes with teeth. Under Part 201.05, NYDFS has the authority to deny, suspend, or revoke a CRA\u2019s license and ability to conduct business in New York if the agency:<\/p>\n<ul>\n<li>violates \u201cany insurance, financial service, or banking laws\u201d;<\/li>\n<li>violates \u201cany regulation, subpoena or order of the superintendent\u201d; or<\/li>\n<li>fails \u201cto comply with the requirements of this Part, including but not limited to, section 201.07 of this Part concerning cybersecurity.\u201d<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Thus, the regulation enables the NYDFS to suspend or revoke a CRA\u2019s license if the CRA fails to comply with the NYDFS\u2019s cyber regulations, including a failure to certify annually its compliance under Part 500.17.<\/p>\n<p>&nbsp;<\/p>\n<p>A timeline of CRAs\u2019 compliance requirements under the cyber regulation is as follows:<\/p>\n<ul>\n<li><strong>November 1, 2018:<\/strong> Sections 500.02, 5000.3, 500.04(a), 500.07, 500.10, 500.14(b), 500.16, and 500.17;<\/li>\n<li><strong>February 29, 2019:<\/strong> Sections 500.4(b), 500.05, 500.09, 500.12, and 500.14(a)(2);<\/li>\n<li><strong>August 31, 2019:<\/strong> Sections 500.06, 500.08, 500.13, 500.14 (a)(1) and 500.15;<\/li>\n<li><strong>December 31, 2019:<\/strong> Section 500.11.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>By\u00a0Josh Mooney and Emma Bechara, White and Williams LLP &nbsp; On June 25, 2018, the New York Department of Financial Services (NYDFS) issued a final regulation that requires any credit reporting agency (CRA) with \u201csignificant operations\u201d in New York to register with the NYDFS and comply with the NYDFS cyber regulations under Part 500. CRAs <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2018\/07\/02\/new-yorks-cyber-regulations-now-apply-to-credit-reporting-agencies\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[11],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/129"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=129"}],"version-history":[{"count":4,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/129\/revisions"}],"predecessor-version":[{"id":269,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/129\/revisions\/269"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}