Gibson Dunn discusses Cybersecurity Regulation in the Financial Sector

In response to a string of publicly disclosed cyberattacks against financial institutions in recent months, New York and federal regulators are pushing the financial sector to better protect itself and, notably, are seeking additional information about banks’ cybersecurity efforts.  Benjamin Lawsky, the Superintendent of the New York State Department of Financial Services (“DFS”) has been at the forefront of this increased regulatory focus.

New York State

On October 21, 2014, Superintendent Lawsky reportedly sent a letter to dozens of banks that not only urges them to address the cybersecurity of their third-party service providers but also requests detailed information about their cybersecurity practices.  Noting that “a firm’s level of cybersecurity is only as good as the cybersecurity of its vendors,” Superintendent  Lawsky’s letter asks banks to disclose “any policies and procedures governing relationships with third-party service providers,” including an outline of methods for safeguarding data that is sent to or received from third-party vendors.[1]  The letter also asks banks to provide “any due diligence processes used to evaluate” the adequacy of security procedures of third-party providers and any protections, such as insurance, in place to guard against potential losses incurred from the security failure of a third-party.[2]  The banks have been asked to provide this information by November 4, 2014.

Superintendent Lawsky’s latest request for information builds on a series of requests and actions taken by DFS in recent years concerning cybersecurity.  These requests have allowed DFS to acquire detailed information about the cybersecurity practices of banks.  For instance, last year, DFS asked more than 150 banking institutions about their cybersecurity programs, including corporate governance practices, frequency and response to cybersecurity breaches, budget and costs associated with cybersecurity and future plans on cybersecurity.[3]  This information was used to produce a comprehensive report published in May 2014 on cybersecurity practices and incidents in the banking sector.  The information collection and resulting report was designed in part to facilitate information sharing between banks and to enable benchmarking that might not otherwise occur in a competitive marketplace.[4]

The approach taken by DFS regarding cybersecurity in the financial sector likely will not be limited to information collection and the publication of reports.  In an indication of the seriousness in which DFS is viewing the issue, last month, Superintendent Lawsky highlighted his belief that cyberterrorism is “the most significant issue DFS will work on in the next year,” commenting that the possibility of an organized attack on the financial system is the one thing that keeps him awake at night.[5] Superintendent Lawsky’s recent letter to the banks describes one potential future requirement, that “regulated financial institutions obtain representations and warranties from their third-party service providers” regarding those vendors’ cybersecurity standards and policies.[6]

The Federal Government

The federal government is also increasingly focusing on the risk of cyberattacks in the financial sector.  Over the last several years, Thomas J. Curry, Comptroller of the Currency and current Chair of the Federal Financial Institutions Examination Council (“FFIEC”), has repeatedly emphasized the importance of addressing the risks posed by cyberattacks on U.S. banks, explaining that such emerging threats “have the potential to be as destructive of the financial system as the excesses of the mortgage and securitization markets.”[7] Curry has stated on multiple occasions that cybersecurity is one of the top priorities of the Office of the Comptroller of the Currency and FFIEC.[8]  And, the FFIEC issued an advisory letter this spring, which included joint statements by the FFIEC’s members[9] regarding (i) cyber-attacks on financial institutions’ ATM and card authorization systems and (ii) distributed denial-of-service (“DDoS”) cyber-attacks, risk mitigation, and additional resources.[10]  The purpose of the advisory letter and joint statements is to notify the financial institutions regulated by the FFIEC members of risks associated with cyberattacks.

Members of the Board of Governors of the Federal Reserve System have also emphasized the risk from cyberattacks in recent months.  In testimony before the Senate Banking Committee, Governor Daniel K. Tarullo discussed the Federal Reserve’s expectations regarding information security, noting that cyberattacks on financial institutions “pose significant risks to the economy and to national security more broadly.”[11]  Cybersecurity continues to be a focus of both the federal banking regulators and Congress, as evidenced by questions at a recent Senate Banking Committee hearing on the implementation of the Dodd-Frank Act.[12]

Similarly, the Securities and Exchange Commission (“SEC”) has been focused on cybersecurity, particularly as it relates to public company disclosures and financial sector practices.  The SEC published interpretive guidance in 2011 regarding disclosure obligations relating to cybersecurity risks and cyber incidents.[13]  And, more recently, the SEC hosted a roundtable discussion in the spring of 2014 to discuss the challenges raised by cybersecurity.  As a result of that discussion, the SEC announced plans to review the defenses of 50 broker-dealers and investment advisors to assess their preparedness for cyber threats as well as their relationships with vendors.[14]

Almost simultaneously, the Federal Trade Commission (“FTC”) and the Department of Justice issued a policy statement on the importance of sharing cybersecurity information.  FTC Chairwomen Ramirez acknowledged the “serious threat posed by cyberattacks,” and “ma[de] it clear that antitrust laws do not stand in the way of legitimate sharing of cybersecurity threat information.”[15]  Similarly, Deputy Attorney General James Cole highlighted that policies “should encourage [private parties] to share cybersecurity information.”[16]  This summer, Treasury Secretary Jacob Lew emphasized the importance of cybersecurity to the global financial system and noted that his deputy would be working with federal and state agencies to address cyber threats to the financial system.[17]


While New York state and federal regulators have produced limited regulatory guidance on cybersecurity practices thus far, it is clear that they are increasing their focus on the topic and are building momentum with their growing knowledge of the cybersecurity landscape in the financial sector.  Financial institutions should expect more examinations and supervisory scrutiny in this fast-paced and ever-changing area.  With that increased regulatory attention, there is also the prospect of increased investigations and enforcement activity.  We will continue to monitor developments at both the state and federal levels.


The full and original memorandum was published by Gibson, Dunn & Crutcher LLP on October 27, 2014, and is available here.