NYDFS issues guidance on cybersecurity practices with AI

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

Recently, NYDFS issued guidance on cybersecurity risks with AI and strategies to combat these risks. The guidance helps entities understand and mitigate AI-related cybersecurity threats but does not impose new requirements beyond those in the existing cybersecurity regulations (23 NYCRR Part 500). NYDFS’s guidance highlighted several key risks, including AI-enabled social engineering, AI-enhanced cyberattacks, and vulnerabilities due to third-party dependencies.

Among other suggested cyber defense strategies, the guidance emphasized the importance of implementing multifactor authentication (MFA) to enhance security. By November 2025, MFA will be required for all authorized users accessing information systems. NYDFS recommended using authentication factors resistant to AI-manipulated deepfakes, such as digital-based certificates and physical security keys and moving away from less secure methods like SMS text.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide