NYDFS Tells Companies to Address AI Security Threats
Time 2 Minute Read

On October 16, 2024, the New York Department of Financial Services (“NYDFS”) issued an Industry Letter (the “Guidance”) warning companies to update their AI security procedures around multifactor authentication (“MFA”), which are potentially vulnerable to deepfakes and AI-supplemented social engineering attacks. The Guidance is intended to explain the application of the NYDFS Cybersecurity Regulation at 23 NYCRR Part 500 to cybersecurity risks arising from AI.

The Guidance, aimed at NYDFS-regulated entities such as banks, insurers and money transmitters, highlights risks associated with certain MFA tools. Risks include the use of AI by threat actors to increase the effectiveness, scale, and speed of cyberattacks, and to create deepfakes to trick employees and customers into disclosing passwords, sensitive data, and funds. NYDFS also highlights risks related to covered entities’ own use of AI and MFA products, such as exposing substantial amounts of nonpublic information (“NPI”) or biometrics, or increased vulnerability due to third party, vendor, and other supply chain issues.  

The use of MFA for NPI will be mandatory in 2025, and NYDFS recommends that companies use authentication methods that can’t be faked using AI, including digital-based certificates and physical security keys. Companies should also consider using an authentication factor that employs “liveness” detection or texture analysis to verify that a biometric factor comes from a live person, or using multiple biometric modalities at the same time, such as a fingerprint in combination with iris recognition, or fingerprint in combination with user keystrokes and navigational patterns. NYDFS also expects companies to increase cybersecurity protocols and third-party oversight, all of which is based on entities’ required cybersecurity risk assessments and detailed further in the Guidance.

The Guidance highlights the importance of ongoing risk assessments and vendor diligence in the rapidly evolving AI-related threat environment.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page