Just in:
Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Abu Dhabi Environment Agency Endorses ADNOC’s Decarbonization Push // Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // Czar Workspace: a Modern Workspace Solutions in Dubai // Boeing Eyes 2030 Launch for Electric Flying Cars // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // AI Race Heats Up: Meta Unveils Powerful New Llama // Tech Giant Discharges Workers Following Disruptive Protest // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field // A Bridge Between Deserts and Rainforests: UAE and Costa Rica Forge Economic Ties // Petrochemical Storm Clouds Gather Over Saudi Arabia // Gunfire exchange near Manipur polling booth // The International Exhibition of Inventions in Geneva Reveals More than 40 Scientific and Technological Innovation Achievements from Hong Kong // Andertoons by Mark Anderson for Fri, 19 Apr 2024 // Emirates Offer Support as Wildfires Ravage Greece // UAE Delegation Engages in Arab Parliament Committee Discussions // Moomoo and Nasdaq Announce Global Strategic Partnership // I’m still learning how to answer this question. In the meantime, try Google Search. // On Its 100 Years Anniversary, LUX Aims to Change Feminine Identity With ‘In Her Name’ //

Bank executives required to vouch for cyber defences

c45388ea cdb4 11e6 b8ce b9c03770f8b1

Top executives at some of the world’s biggest banks and insurers will have to vouch for their companies’ resilience to cyber attacks, under tough rules laid down by New York’s state regulator.

A new regulation, which takes effect on March 1, requires companies supervised by New York’s Department of Financial Services to establish and maintain a cyber security programme that can protect consumers’ private data and “ensure the safety and soundness” of the state’s financial services industry.

ADVERTISEMENT

Executives will be made to submit an annual certification that the company is complying with the various requirements, and agree to notify the DFS of any serious breaches within 72 hours of their discovery.

“This has gone further than any other regulation I’ve seen, and is the most prescriptive,” said Joe Nocera, Chicago-based leader of PwC’s cyber security practice.

The new regime comes as financial institutions are under near-constant bombardment from criminals, “hacktivists” and disaffected insiders, all trying to breach their defences. Attempts range from “watering hole” attacks, where employees gather at spoofed websites that implant malware, to more complex schemes led by state-linked groups.

North Korea, for example, was thought to be behind last year’s $101m heist at the Bank of Bangladesh, carried out via an account at the Federal Reserve Bank of New York. The sum could have been much higher, were it not for a typo in the routing instructions.

More attacks from Pyongyang’s army of hackers could be in the offing this year, say experts, as China’s ban on coal imports exacerbates a shortage of foreign exchange in the country.

You jiggle enough door handles, you find one that opens

Banks will need to stay on high alert to threats from other nation-state actors such as China, Russia and Iran, said security experts.

“You jiggle enough door handles, you find one that opens,” said one.

The DFS’s regulation affects financial institutions that operate through a New York state charter — a list that includes Goldman Sachs, BNP Paribas, Deutsche Bank, AIG and MetLife.

Analysts say the protocols are mostly in line with those adopted by the Federal Financial Institutions Examination Council, an inter-agency body that sets uniform standards for examinations by regulators including the Federal Reserve and the Office of the Comptroller of the Currency.

But the requirement for an executive to testify that the company’s systems are up to scratch, could expose that individual to liability if the company’s cyber security programme is later found to be non-compliant.

The regulation also says that companies should flag incidents to the DFS which “have a reasonable likelihood of materially harming” the company.

That could be a “tall order,” said Aleksandr Yampolskiy, chief executive of SecurityScorecard, a risk benchmarking company. “Banks have all kinds of systems gathering data. Sometimes there’s so much of it they don’t know what they have.”

For now, no other US state “comes anywhere close” to New York’s level of scrutiny, said Jim Halpert, Washington-based co-chair of the cyber security practice at DLA Piper, a law firm.

He noted that Andrew Cuomo, the Democratic state governor nearing the end of a second four-year term, appears to be eyeing a run for president in 2020.

“He doesn’t want to be accused of being asleep at the switch,” he said.

Via FT

ADVERTISEMENT

ADVERTISEMENT
Just in:
Saadiyat Grove Set for Smart Transformation Through Aldar-Siemens Alliance // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Bitcoin Halving: Bitcoin Nears Block Reward Reduction // The International Exhibition of Inventions in Geneva Reveals More than 40 Scientific and Technological Innovation Achievements from Hong Kong // Takeoff After Turbulence: Flydubai Restarts Operations at Dubai International Airport // VT Markets Releases Study on Upcoming Bitcoin Halving and Market Implications // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // Emirates Offer Support as Wildfires Ravage Greece // Czar Workspace: a Modern Workspace Solutions in Dubai // Gunfire exchange near Manipur polling booth // Gen Zs Trust User and Expert Insights on Shopee // KL Home Care Commits To Excellence Professional Maid Services For The Residents Of Hong Kong // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // Electric Cars Get Refueled, Not Charged: Obrist HyperHybrid Ready for Production // On Its 100 Years Anniversary, LUX Aims to Change Feminine Identity With ‘In Her Name’ // Keung To Trams Return! “KeungShow HKFanClub” Sponsor Free Tram Rides for All on 30 April to Celebrate Keung To’s 25th Birthday // AI Race Heats Up: Meta Unveils Powerful New Llama // I’m still learning how to answer this question. In the meantime, try Google Search. // Petrochemical Storm Clouds Gather Over Saudi Arabia //