Skip Ribbon Commands
Skip to main content
Dec 22
You Must Notify the DFS if your Agency Has Been Directly Impacted by the SolarWinds Espionage Attack

​On Friday, 12/18, the New York Department of Financial Services published an industry alert ​on the recently revealed SolarWinds/supply chain cyber espionage attack.  ​

You should notify the Department if your institution was directly impacted by any of the affected SolarWinds Orion products or if your institution has been notified of an impact by any affiliate who has access to your network or your nonpublic information. 

The Department's cybersecurity regulation requires notice of any Cybersecurity Event that has “a reasonable likelihood of materially harming any material part of the normal operation(s)."  23 NYCRR 500.17(a)(2). Given the sophistication and persistence of the malware and the adversary, DFS asks any affected institution to file a notice immediately. 

Instructions on how to file notice of a Cybersecurity Event and specific information requested as part of this incident are detailed here: https://www.dfs.ny.gov/industry_guidance/industry_letters/il20201218_supply_chain_compromise_alert

Please contact CyberAlert@dfs.ny.gov for any questions or comments.


Comments

There are no comments for this post.

 ‭(Hidden)‬ Blog Tools