Via FinOps Report: Cathy Mulrow-Peattie Discusses NYDFS Cybersecurity Regulation Implications for the Financial Services C-Suite
In The News | 2 min read
Feb 15, 2024
Cathy Mulrow-Peattie was recently featured in FinOps Report, discussing New York State's amended cybersecurity regulation and its implications for C-level executives, particularly financial services company management. The regulation requires CEOs, CISOs, and boards of directors to take a more active role in overseeing cybersecurity by imposing deadlines for certification of compliance and additional requirements for covered entities, Class A companies, and small businesses.
Under the amended regulation, material compliance now does not mean an absolute 100 percent compliance, but it does require that organizations subject to the NYDFS cybersecurity regulations take the appropriate action; it is a risk-based determination.
Mulrow-Peattie explained in the article that the "best interpretation is that whatever is wrong with the firm's cybersecurity program won't be enough to harm the covered firm in the event of a cybersecurity incident."
Covered firms are required to certify compliance with cybersecurity regulations for each of their affiliates separately. If an affiliate has a cybersecurity program that meets all relevant requirements, the covered firm can choose to adopt it either in full or in part. However, each covered entity remains responsible for its own compliance and annual certification.
What Deadlines Are Companies Facing Now?
- As of December 1, 2023, Covered Entities, Class A companies, and small businesses must report cyber incidents, including ransomware attacks, to NYDFS.
- On April 15, 2024, Covered Entities and Class A companies must submit an annual certification of compliance of their material compliance with the NYDFS cybersecurity regulations to the NYDFS.
- By April 29, 2024, Covered Entities and Class A companies are required to have in place revised cyber risk assessments informing revised cyber security policies to meet the new regulatory requirements.
The NYDFS has expanded the factors to be considered in evaluating risk beyond network hacking to reputational and customer risks.
Mulrow-Peattie added that "[p]art of the CISO's risk assessment should be an understanding of the risks to an organization's reputation and customers if there are insufficient cyber controls and a subsequent incident occurs." Noting that cybersecurity is a team sport, she recommended that covered firms include their finance, marketing, compliance, and legal teams when conducting a risk assessment.
The NYDFS and the SEC cyber incident reporting and disclosure requirements have different purposes; one is focused on cybersecurity compliance, and the other is focused on the disclosure of material information for investment decisions. "Regardless of the distinctions between the NYDFS and the SEC's rules, covered firms making any disclosures of cybersecurity events to both agencies should ensure that the information given to regulators is consistent," said Mulrow-Peattie.
Learn more about the updated NYDFS cybersecurity regulations in our recent Privacy, Cyber & AI Decoded alert.
"NY's New Cyber Law Shines Stronger Light on C-Level" was published by FinOps Report on February 11, 2024.
Related People
Related Capabilities
Related Locations
Featured Insights

Event
Apr 23, 2026
Driving Ahead: Insights from Industry Leaders Auto Finance Seminar

Consumer Crossroads: Where Financial Services and Litigation Intersect
Mar 13, 2026
DOJ Settlement with Car Retailer Highlights SCRA Repossession Risks

Privacy, Cyber & AI Decoded Alert
Mar 11, 2026
Compliance Considerations for GDPR Consent in Biotech Clinical Research

Press Release
Mar 4, 2026
Marcia Mueller Named the 2026 Mentorship Award Winner by YWCA Northwestern Illinois

Press Release
Mar 3, 2026
Hinshaw Announces New Administrative Leadership Appointments

In The News
Feb 27, 2026
Hinshaw Partners Examine Implications for Nursing Homes of New Illinois Aid-in-Dying Law

In The News
Feb 24, 2026
Lucy Wang Authors Law360 “Expert Analysis” on Why Attorney Civility Means More in 2026

Press Release
Feb 13, 2026
Hinshaw Team Wins Appeal in Criminal Indictment of Waukegan City Clerk Janet Kilkelly

Press Release
Feb 10, 2026
Hinshaw Trial Team Secures $0 Defense Verdict in $15 Million Auto Accident Trial

Press Release
Feb 5, 2026
Hinshaw Legal Team Secures Directed Verdict in Florida Equine Fraud Case

Press Release
Feb 4, 2026
Hinshaw Celebrates 17 Consecutive Years of Being Named an Equality 100 Award Winner

![[Video] New Regulatory Priorities Under Mayor Mamdani’s NYC Department of Consumer and Worker Protection](/a/web/oHiTWa7kRy3Ht1brq6k4BT/bkMx39/new-york-city-skyline.jpg)
