NY DFS Issues Industry Letter Regarding Heightened AI-Related Cybersecurity Risks and Guidance on Heightened Threat Environments
The New York Department of Financial Services (DFS) recently issued an advisory letter to chief information security officers of regulated entities addressing heightened cybersecurity risks from frontier AI models.
DFS is urging regulated entities to review and update their cybersecurity programs, risk assessments, and controls in anticipation of broader availability of frontier AI models, which DFS believes have the ability to significantly “amplify the potency, scale, and speed of identifying vulnerabilities and developing exploits in information systems.”
DFS recommends that regulated entities should:
- Increase operational resilience by replacing outdated information systems;
- Review their cybersecurity programs to ensure compliance with the Department’s cybersecurity regulation, 23 NYCRR Part 500; and
- Consider whether additional measures are necessary to address the heightened risks presented by frontier AI models.
DFS also issued accompanying guidance that provides an overview of best practices for regulated entities to consider when adopting and implementing their cybersecurity programs. In its advisory letter, DFS called special attention to topics in the accompanying guidance that outline:
- Expedited vulnerability management;
- Coordination with third-party service providers on downstream dependencies;
- Strengthened secure coding practices (including human oversight); and
- Heightened monitoring and prompt reporting.
The letter and guidance underscore that DFS expects regulated entities to maintain heightened vigilance in an environment of significantly elevated cybersecurity risks, and to leverage the Department’s best practices to strengthen defensive measures.
