The New York Department of Financial Services published an industry guidance to all regulated entities, including insurers, clarifying the requirements under the DFS Cybersecurity Regulation.

The regulation, also referred to as Part 500, requires insurers to understand and address cybersecurity risks and maintain cybersecurity programs designed to protect confidential data.

The program should have robust risk assessments, defined in Part 500 as, " the process of identifying, estimating and prioritizing cybersecurity risks to organizational operations (including mission, functions, image and reputation), organizational assets, individuals, customers, consumers, other organizations and critical infrastructure resulting from the operation of an information system. Risk assessments incorporate threat and vulnerability analyses and consider mitigations provided by security controls planned or in place."

Risk assessments should identify and analyze cybersecurity risks, while taking into account the insurer's size, complexity, and risk profile. Risk assessments should be updated annually and whenever there is a material change in the technology used by the insurer. Risk assessments should also consider third-party risks and emerging risks, including those involved with the use of AI.

The guidance addressed common gaps found in risk assessment programs including incomplete asset inventories, inconsistent methodologies that fail to distinguish between inherent and residual risk, and failure to account for emerging or interconnected risks.

The industry guidance can be found here.

Ray Sugrim

Ray Sugrim

Ray Sugrim is an Insurance Editor with FC&S Expert Coverage Interpretation, a division of National Underwriter Company and Arc Network. Ray is responsible for helping develop and edit content for subscribers. Ray is a St John’s University graduate with a degree in Risk Management & Insurance and is a CPCU candidate.

More from this author ⟶