Key Point: All businesses struggle with cybersecurity risks presented by their service providers. New guidance from the NY DFS applies to all DFS regulated entities, but the guidance would assist any business in any industry in addressing these risks.

On October 21, 2025, the New York Department of Financial Services (the “DFS”) issued important guidance for covered entities (including all DFS licensees) for managing their cybersecurity risk related to third-party service providers (“TPSPs”). Industry Letter – October 21, 2025: Guidance on Managing Risks Related to Third-Party Service Providers | Department of Financial Services specifically includes the covered entity’s use of cloud, file transfer, AI and fintech providers (“Guidance”). According to the DFS, the “Guidance does not impose new requirements or obligations . . ..” Rather, “it is intended to clarify regulatory requirements, recommend industry best practices . . ., and promote compliance . . ..” The Guidance highlights that managing the cybersecurity risk presented by TPSPs “remains a crucial element of a Covered Entity’s cybersecurity program,” and notes that it applies to all covered entities, regardless of size.Read More Important Guidance on Third-Party Service Provider Cyber Risk

2024 Insurance Forum
October 30, 2024 / 9:00 AM -3:30 PM
Offices of Locke Lord LLP, 111 S. Wacker Drive, 41st Floor, Chicago, IL 60606
In Person Only

Locke Lord is proud to sponsor and host the 2024 Insurance Forum in the Chicago office on October 30. Paige Waters will
Read More You’re Invited: Complimentary 2024 Insurance Forum

Organizations continue to face new issues, regulations and threats relating to privacy and cybersecurity. Over the next few months, Locke Lord lawyers will tackle some of your most pressing concerns in a series of complimentary webinars discussing practical, real-world challenges facing organizations, including compliance, business operations, data incidents, and investigations, litigation and enforcement. Sign up below for each program that interests you or sign up for the entire series.
Read More Join Us for a Complimentary Webinar: Gearing up for Privacy & Cybersecurity in 2021