Why CUs Are Watching Empire State

Feature NY Cybersecurity

By Ray Birch

SCHENECTADY, N.Y.—Credit unions across the country should pay close attention to how CUs in this state manage under the new, tough, cyber security regulation that began taking effect March 1.

That is advice from the New York CU Association, which believes more states will follow suit with their own data security guidelines as Washington moves slowly on national legislation. The regulation—believed to be the first of its kind adopted by a U.S. state—is simply one more onerous compliance burden already time- and resource-strapped CUs will have to shoulder, and may lead to more mergers, says the Association.

In addition, the NYCUA said it believes the new regulation makes the state charter less attractive, since the rule applies only to state-chartered FIs and those federally chartered that have state ties, such as CUSOs.

“New York and other states are understandably frustrated by what they see in the lack of federal movement on this issue, and over time other states will take action,” said Henry Meier, NYCUA general counsel. “For better or for worse, the rules in New York will be a model, a baseline, as other states look to see what they can do to protect against data breaches.”

The controversial new cybersecurity regulation requires FIs to retain a chief information security officer (CISO), report cybersecurity incidents within 72 hours, and use multifactor authentication. The Association said financial institutions do not have to hire a CISO, only show that someone in the organization has that level of skill.

Cybersecurity Program

The rule also calls for FIs to develop a cybersecurity program, including a written policy that addresses aspects such as access controls, business continuity, asset inventory and data governance. The cybersecurity program must include a periodic risk assessment plus annual penetration tests. Encryption must be used for data in transit and at rest. Organizations also must develop a written incident response plan. 

While reports indicate that New York State backed off of even tougher rules, analysts agree that the rule is one of the most comprehensive cybersecurity regulations in the financial sector.

Meier also said the state has indicated it will provide “some flexibility” with how FIs comply with the regulation, allowing banks and credit unions to apply for exemptions based on their size and sophistication.

“That said, there are HR requirements and baseline expense requirements regarding equipment etc. that are going to be onerous for small financial institutions to absorb,” said Meier. “The exact impact of the rule is not yet clear. But we are concerned.”

Meier noted that the rule may likely force CUs to hire more staff, either to fill more cyber security roles or other jobs, since the regulation places demands on the time of current staff.

The league also believes it could lead to more third-party agreements to help manage the rules—yet another vendor management responsibility.

Organizations have 180 days to comply with the regulation that took effect March 1. But Michael Lieberman, VP of governmental affairs at the league, said there are grace periods built into the rule that give organizations up to two years to come into full compliance.

“The basic idea is that the rule will be phased in within six months to two years,” said Lieberman. “The reality is that nothing in this regulation will really start biting until six months, and the more complicated aspects of the law taking effect in two years.”

National Legislation

As CUToday.info reported earlier, Jason Kratovil, VP of government affairs for the Financial Services Roundtable, said that for the first time in a while he is hopeful national data security legislation may take shape, saying that committees typically at loggerheads may now be ready to move.

Lieberman said that would be welcomed by New York CUs.

“We are hopeful that strong national data security laws can be passed this year,” said Lieberman. “In our meetings with the New York delegation we got lot of good feedback for a national bill that would preempt any existing state laws.”

Lieberman emphasized that the Association appreciates what the New York State Department of Financial Services is trying to accomplish with the regulation.

“But at the end of the day, we don’t support a state-by-state approach to cybersecurity. We advocate a strong national law that preempts state law and holds merchants that accept payment card data to the same standards as financial institutions,” said Lieberman. “Credit unions and banks already put a tremendous amount of effort and resources toward protecting themselves from cyber attacks and data breaches. Currently, there is little incentive for merchants to do the same.”

NYCUA does not believe the new cyber rule will prompt state charters to jump to federal, since the New York state charter has become attractive, particularly around field of membership expansion. However, he does think it will impact decisions of federally chartered CUs in the Empire State.

“It won’t be enough to move state charted credit unions, but the regulation makes it less desirable now for a federal charter to convert to state,” concluded Lieberman.

Section: Standard
Word Count: 974
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Why-CUs-Are-Watching-Empire-State