logo
x
  • RADAR™ Testing
  • About Us
    Leadership Partner Program
  • Blog
  • Resources
    Attack Round-ups Case Studies Data Sheets eBook FAQs Infographics Knowledge Base Reports Ultimate DDoS Protection Whitepapers
  • Contact Us
    Careers
  • My Account
  • GET A DEMO

← Back to blogs

Eitan Gafny | December 08, 2022

Part500 2nd Amendment Updated

Cybersecurity Regulations’ Second Amendment: Important Update

As we are coming to the end of 2022, it’s important to stay updated with potential changes to our ever-evolving market of cybersecurity. In late July of 2022, the New York Department of Financial Services (NYDFS) published the pre-proposed second amendment to its Cybersecurity Regulations, 23 NYCRR 500. The state regulation is publicly referred to as “Part 500” and it was introduced in 2017, with new mandatory cybersecurity and risk management regulations for sensitive organizations such as banking, law, insurance and more. In its original version, Part 500 introduced new rigorous principles and regulations to enhance cybersecurity procedures in such sensitive organizations. Such principles demanded higher maintenance of security policies and the eventual creation of the new industry role, the Chief Information Security Officer (CISO).  

Expected changes in security protocols

Should the second amendment of part 500 go into effect, we expect several key updates and even changes to the cybersecurity market. Since DDoS mitigation has become the most talked about field in the market, due to the rising number of worldwide DDoS attacks, we expect a drastic change in protocols and regulations regarding DDoS mitigation. It’s important to note that these regulations, if and when they come into effect, will only be implemented in the US. But one can assume that if a drastic change in the cyber industry is successful in the US, the global market standard regarding increasing visibility into critical vulnerabilities might see a shift.   

Some of the most notable updates and changes in the second amendment are the updated definition for “Class A” companies, detailing new standards for executive management involvement, expanding on third-party service providers, defining security policies for mutual work, and more. What is very relevant in the amendment, in terms of DDoS mitigation for financial services companies, are articles that discuss the responsibilities of the CISO, and updated protocols for an overall cybersecurity program and monitoring.  

Additional reporting, better DDoS awareness

According to the second amendment of part 500, the CISO would be obligated to report about remediation efforts and update on their organization's mitigation protocols. These reports would be annual, with the possibility of reporting twice a year. The CISO would need to detail information that is considered nonpublic, and also provide extensive details regarding the organization’s security program’s effectiveness, efforts, protocols and mitigation results. As the number of successful DDoS attacks increases, one might imagine that reporting about weak mitigation and a vulnerable attack surface may result in harsh consequences.  

The second amendment of part 500 details new policies for cybersecurity programs, monitoring and training. An organization in the specific fields mentioned would be required to maintain an updated mitigation plan, that includes industry-standard encryption, mitigation effectiveness reports, and go through an annual review on said reports. In addition to the overall security program, organizations must increase employee training and monitoring of the attack surface and environments. These efforts should set a collective standard for the industry in the US, and should the amendment go into effect, the entire DDoS mitigation market.  

What can you do to be prepared against a DDoS attack? 

At MazeBolt, we see the evolution of DDoS attacks in the fields of banking, financial services, gaming, and insurance, not just in the US, but worldwide. The updated second amendment’s recommendations are natural, as networks become more complex on the one hand, and on the other, DDoS attacks are evolving to become more sophisticated and severe in the damage they cause enterprises. Digital environments are evolving at a rapid pace. There are assets in many organizations’ networks that are not properly configured, managed, or even up to date. If traditional mitigation vendors are not updated on these changes, they cannot effectively protect such networks. The lack of adequate offensive testing results offers limited protection and zero visibility into the organization’s true DDoS readiness. Thus, there indeed needs to be an updated protocol for cybersecurity, that should be effective for the industry, the market, and the vendors. We will continue to update about Part 500 in the US, as we find their recommendations to be important. Stay tuned!  

 

Read The Second Amendment Here  

DDoS Attacks ddos protection
Picture of Eitan Gafny
About Eitan Gafny

View all posts by Eitan Gafny →
← Understanding DDoS Attacks: The CISA and FBI Guidelines
You Are Not Protected Against DDoS Attacks: Top 10 Reasons Why →

    Recent posts

    Archives

    • January 2023 (3)
    • December 2022 (5)
    • November 2022 (1)
    • October 2022 (3)
    • September 2022 (2)
    • August 2022 (2)
    • July 2022 (1)
    • June 2022 (1)
    • May 2022 (1)
    • April 2022 (1)
    • March 2022 (1)
    • February 2022 (3)
    • January 2022 (1)
    • December 2021 (4)
    • November 2021 (5)
    • October 2021 (2)
    • September 2021 (4)
    • August 2021 (3)
    • July 2021 (2)
    • June 2021 (2)
    • May 2021 (3)
    • April 2021 (2)
    • March 2021 (4)
    • February 2021 (3)
    • January 2021 (2)
    • December 2020 (2)
    • November 2020 (2)
    • October 2020 (4)
    • September 2020 (2)
    • August 2020 (4)
    • July 2020 (3)
    • June 2020 (4)
    • May 2020 (2)
    • March 2020 (5)
    • February 2020 (5)
    • January 2020 (3)
    • December 2019 (1)
    • September 2019 (3)
    • July 2019 (1)
    • May 2019 (3)
    • April 2019 (2)
    • December 2018 (7)
    • November 2018 (1)
    • October 2018 (2)
    • September 2018 (3)
    • July 2018 (1)
    • June 2018 (5)
    • May 2018 (3)
    • April 2018 (2)
    • December 2017 (1)
    • November 2017 (1)
    • September 2017 (2)
    • June 2017 (1)
    • May 2017 (2)
    • October 2016 (1)
    • May 2016 (1)
    • April 2016 (1)
    • December 2015 (1)
    • November 2015 (1)
    • August 2015 (2)
    • June 2015 (1)
    • May 2015 (2)
    • April 2015 (3)
    • March 2015 (1)
    • December 2014 (1)
    • November 2014 (1)
    • June 2014 (1)
    • April 2014 (3)
    • February 2014 (1)
    • November 2013 (1)
    See all →
    logo
    • linkedin
    • twitter

    MazeBolt Technologies |
    Moshe Aviv Towers, 46th floor
    Jabotinsky 7, Ramat Gan,
    Israel 5252007
    email info@mazebolt.com

    US : +1 253-372-8800
    CH: +41 21-560-61-50
    UK: +44 20-3314-1339
    IL: +972 3-309-6045

    • Request Demo
    • Become a Partner
    • Careers
    • Privacy Policy
    • Terms
    • About Us
    • Knowledge Base
    • Blog
    • Content Center