Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Senate Intelligence Bill Would Encourage Prerelease Testing of AI Hacking Capabilities
    • CISA Restarts Stakeholder Engagement on Cyber Incident Reporting Rules
    • Florida Governor Signs Law Creating Cybersecurity Grant Program
    • Input Sought on FCC’s Trusted Labs Priority Review Process
    • Irish High Court Upholds Fine Against Meta Over GDPR Violations
    • Louisiana Data Privacy Legislation Sent to Governor
    • New York DFS issues guidance for organizations, individuals facing cyber threats
    • Refusal to Allow ‘Rip-and-Replace’ Inspections Leads to Fine
    • Responses Sought on Brazil’s Age Verification Mechanisms
    • South Korea to Introduce Risk-Based Inspection Framework for Data Processing
    • Texas AG Sues WhatsApp Over ‘Inaccurate’ Privacy Policies
    • Two Privacy Bills Advance in Delaware House
    • U.K. Agency Fines Energy Company Over Solicitation Calls
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, New York DFS issues guidance for organizations, individuals facing cyber threats, (May 26, 2026)

    By Nora Macaluso

    The department issued recommendations on containing attacks, improving threat detection and readiness, and ensuring resilience.

    The New York State Department of Financial Services (DFS) issued guidance it said regulated entities should consider ȁ ...

    By Nora Macaluso

    The department issued recommendations on containing attacks, improving threat detection and readiness, and ensuring resilience.

    The New York State Department of Financial Services (DFS) issued guidance it said regulated entities should consider “when facing a heightened threat environment.”

    Factors such as geopolitical events and technological developments like “frontier AI models” may increase the risk of cyberattacks or raise security risk, the department said.

    “This guidance gives our regulated entities actionable steps that can be taken when the threat environment intensifies,” said Acting Superintendent Kaitlin Asrow. "Each entity should assess their unique circumstances and operations to identify which steps are warranted.”

    The guidance does not establish new legal requirements, the department said, but rather “provides a framework of best practices” for organizations and individuals to consider.

    “A heightened threat environment exists when cybersecurity risks are significantly elevated and therefore have a high likelihood of impacting Information Systems, Nonpublic Information or operations,” the department said.

    The guidance, in the form of an industry letter, includes what the department called a “non-exhaustive list” of recommendations in three areas: reducing the attack surface, improving threat detection and readiness, and strengthening resilience and response.

    Recommendations for reducing the attack surface include “expeditiously” identifying and mediating known exploited vulnerabilities in firmware, hardware, and software; disabling the use of inactive or unnecessary ports and protocols where possible; and restricting and validating inputs prior to generating outputs or executing other commands.

    To improve threat detection and readiness, entities should confirm that intrusion prevention detection, and response controls are in use, up to date, and appropriately deployed; confirm that alerting data are captured and anomalous or suspicious activity are identified; and third-party service providers are monitored and made aware of risks.

    Resilience and response measures include testing the integrity and restorability of backups; preparing for a heightened threat environment by reviewing and testing procedures; and monitoring financial transactions, including virtual currency business activity, to ensure compliance with applicable orders and guidance on sanctions and money laundering.

    “As frontier AI models rapidly evolve, New York remains committed to safeguarding our digital landscape,” said New York State Acting Chief Cyber Officer Michaela Lee. “Under Governor Hochul’s leadership, we are ensuring that our cybersecurity defenses are as dynamic as the technologies threat actors seek to exploit.”

    “This proactive guidance from DFS provides a blueprint to strengthen financial resilience, reinforcing New York's national leadership in innovation and security,” Lee said.

    RegulatoryActivity: CyberPrivacyFeed DataSecurity FinancialStability FinTech GCNNews NewYorkNews StateBankingLaws DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use