DFS Cybersecurity Risk Assessment Letter Explained
The New York State Department of Financial Services (DFS) has issued new guidance on how the businesses it regulates should conduct cybersecurity risk assessments. Though much of the document applies to organizations much larger than most Big I New York members, insurance agencies and brokerages of all sizes should consider its suggestions.
The department published the letter on September 10 with two purposes in mind:
- To clarify what it requires businesses to do when they assess their risks
- To suggest “best practices” for them to follow.
Cybersecurity Risk Assessments
A cybersecurity risk (or cyber risk) assessment is a loss control survey of a business’s computer technology operations. Virtually every agency uses computer and Internet technology in its business, and most collect at least some private information from clients and claimants The New York financial services cybersecurity regulation (and sound business practice) require agencies to protect their systems and data.
When an agency performs its risk assessment (which it must do at least annually,) it is asking three questions:
- What do we have to worry about?
- How worried should we be about it compared to the other cyber risks we face
- Is what we’re doing about it right now enough?
The answers to those questions dictate the pieces of the agency’s cybersecurity program. Give top priority to the risks you’re most concerned about.
The DFS letter states at the beginning that it’s not creating any new obligations and the department isn’t requiring you to do anything today that you didn’t have to do on September 9. The letter also states, “(A) Risk Assessment is an evaluation that identifies, analyzes, and prioritizes cybersecurity risks taking into account the Covered Entity’s size, complexity, and risk profile.” The department does not expect a five-person agency in Yonkers to perform the same assessment that it expects from an insurance carrier that operates countrywide or a bank with 25 branches.
The letter reminds all “covered entities” that they must perform the assessment at least annually and more often as business operations and threats change. For example, assume you hire a company that will handle all your social media posting. Now is the time to ask the three questions listed above. If they can’t log into your computer system or access your private data, the answer to the first question might be “not much.” If they will have that access, things may go wrong – a thief could steal passwords or an employee or vendor could try to access data they shouldn’t and so on. That changes the answer to the first question and likely answers the second – you might have a lot to worry about.
Some kind of controls to minimize the risk – passwords coupled with two-factor authentication or similar controls – appear to be called for. That solution should make its way into your written cybersecurity program. Repeat this thought exercise for every person, organization, and device that can access your system.
When you have completed the assessment, you should have a clear idea of the threats you are facing, what you can do on your own to defend against them, and what you might need outside help with.
The procedures for conducting the risk assessment must be in writing so that everyone in the agency can refer to them.
Common cybersecurity risk assessment mistakes
The DFS letter notes several shortcomings in entities’ risk assessments:
They don’t know what they have. Their equipment inventories are outdated, they don’t know where private data is stored or who it goes to, and they haven’t identified everyone who can access the system and data.
Their assessments are inconsistent or not thorough. If an assessment is not done regularly and does not answer the three questions for every cyber exposure, it’s not as helpful as it should be.
They haven’t kept up with changes. Technology and cyber threats seem to evolve by the hour. Is your agency using artificial intelligence (AI) tools today that it wasn’t using last September? Have you been following DFS alerts about new threats? If not, get up to speed and ask the three questions.
Everyone is responsible for cybersecurity so no one is. There isn’t a single person responsible for performing the assessments, documenting the results, and updating them as circumstances change.
They don’t do anything with the information. The point of the assessment is to design a cybersecurity program that is effective for the agency. If you perform an assessment and don’t modify your program, you’ve wasted your time and left your business potentially at risk.
DFS best practices for stronger risk assessments
To make the most of your assessment, the letter suggests:
The person in charge of cybersecurity (probably the principal in a small agency) should review and approve the written assessment procedures each year.
Use defined and repeatable methods for the assessment. This helps you set benchmarks that allow you to measure your progress in minimizing the risk.
Look at all your networked devices – workstations, laptops, tablets, phone systems, anything that allows access to your network – along with employees, vendors, business partners, and anyone else you depend on to do business.
Document your findings. This will help you create your program and allow you to retrace your steps should a problem arise later.
Make the risk assessment a standard part of your overall cybersecurity program. The order should be: Perform risk assessment, create a program based on the assessment, implement the program, observe the results, perform an assessment based on the results, revise the program, and so on indefinitely.
Three cybersecurity reminders for insurance agencies
Remember three things:
Business runs on technology. Risk assessments and cybersecurity programs are just as necessary in states that have no insurance data security laws and regulations as they are in those that do. It’s part of the world we do business in.
You will never have the perfect cybersecurity program but you should make it a hassle for the criminals. Remember the adage that you don’t have to be faster than the bear chasing you, you need only be faster than the other person the bear is chasing. That adage applies to cybersecurity. Make it difficult for hackers to break in so they will look for easier targets to pick on.
Finally, remember that the DFS does not expect you to have a sophisticated, elaborate cybersecurity program like a major carrier would have. They do expect you to do what is reasonably possible given your size, complexity, and resources. Don’t bankrupt your agency on security measures. Do what you can to protect yourself, keep an eye on the threats, and focus on helping your clients.