On November 1, 2023, the New York Department of Financial Services (NYDFS) introduced its second amended Cybersecurity Regulation (23 NYCRR Part 500). The amendments, influenced by extensive public feedback, introduce several significant changes, including heightened cybersecurity requirements for large licensees known as “Class A Companies.” Compliance with these new requirements is mandated by April 29, 2024, with certain provisions having extended transition dates.
One notable requirement is the implementation of an automated method to block commonly used passwords for all accounts on information systems owned or controlled by Class A Companies, and wherever feasible, for all other accounts. This measure is designed to enhance security by preventing the use of weak passwords that are easily exploitable by cyber attackers.
“Each class A company shall monitor privileged access activity and shall implement an automated method of blocking commonly used passwords for all accounts on information systems owned or controlled by the class A company and wherever feasible for all other accounts.”
The automated password blocking requirement applies specifically to “Class A Companies.” According to the regulation, a Class A Company is a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from all business operations and either:
Over 2,000 employees on average over the last two fiscal years, including affiliates; or over $1 billion in gross annual revenue in each of the last two fiscal years from all business operations of the entity and its affiliates.
The requirement for automated password blocking became enforceable on April 29, 2024. Organizations who do not yet meet this requirement are encouraged to implement these measures as soon as possible to avoid penalties and make their environment secure.
The NYDFS has established stringent enforcement provisions for non-compliance with the cybersecurity regulation. Covered entities found to be non-compliant may face significant punishment, including financial fines. The exact amount of the fines can vary based on the severity of the non-compliance and the potential impact on the entity’s cybersecurity posture.
Each Class A Company must:
To fulfill this requirement in the simplest, most secure, and cost-effective manner, Class A Companies should focus on protecting both employee and customer accounts.
Enzoic offers two solutions that make NYDFS compliance straightforward and automated for both employee and customer/member accounts.
Enzoic for Active Directory is an easy-to-install plugin that provides a frictionless way to identify, monitor, and remediate unsafe passwords. It offers a comprehensive solution for ensuring password security and compliance with the NYDFS regulation.
Get Started with Enzoic for Active Directory
Try Now: Eliminate commonly used and compromised passwords in your environment. Download and try free for up to 20 users.
Product Demo: Watch a full product demo to understand how Enzoic for Active Directory can help enhance security, save time, and reduce administrative costs.
While securing internal accounts is crucial, extending password security measures to customer-facing applications is equally important. Enzoic’s Passwords API provides a powerful solution for ensuring users create secure passwords upon account creation and protecting customer and member accounts at each login, helping organizations comply with the NYDFS Cybersecurity Regulation by preventing the use of compromised or commonly used passwords.
Enzoic offers RESTful APIs that enable real-time password and credential screening and continuous monitoring for customer accounts. By integrating these APIs into your applications, you can:
By implementing Enzoic’s Passwords API for customer account protection, organizations can meet the NYDFS’s requirement to block commonly used passwords wherever feasible, not just for internal accounts but also for customer-facing systems. This proactive approach demonstrates a commitment to cybersecurity best practices and regulatory compliance.
Get Started
Explore the Documentation: Learn more about Enzoic’s APIs and how they can be integrated into your systems.
Contact Us: For personalized guidance on incorporating Enzoic’s Dark Web monitoring into your login flows, submit the form, and a technical resource will be in touch.
Interactive Demo: Try our online interactive demo to see how Enzoic’s APIs work in real-time (pictured below). The API will flag a password at login if it’s found in Enzoic’s database of weak, commonly used, and compromised passwords.
Compliance with the NYDFS Cybersecurity Regulation is now mandatory for Class A Companies. Implementing automated methods to block commonly used passwords is essential not only to meet regulatory obligations but also to secure the accounts of your employees and customers/members. Enzoic’s solutions for both employee and customer account protection offer an effective and automated way to achieve compliance. If your organization hasn’t yet adopted these measures, it’s important to act immediately to avoid penalties and protect your environment.
AUTHOR
Josh Parsons
Josh is the Product Marketing Manager at Enzoic, where he leads the development and execution of strategies to bring innovative threat intelligence solutions to market. Outside of work, he can be found at the nearest bookstore or exploring the city’s local coffee scene.
Prevent the use of weak passwords that are easily exploitable by cyber attackers.