On October 16, 2024, the New York Department of Financial Services (DFS) released an Industry Letter addressing the growing cybersecurity risks associated with the use of artificial intelligence (AI). This communication, titled "Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks," aims to aid entities regulated by the DFS in identifying and managing potential threats linked to AI technologies.
The letter is a supplementary tool designed to enhance understanding and application of existing cybersecurity regulations without imposing additional compliance demands beyond those already established under the DFS Cybersecurity Regulation. It seeks to guide Covered Entities in applying the regulatory framework to specifically assess and address AI-related risks.
The guidance highlights several significant risks posed by AI, including the potential for AI-enabled social engineering, AI-augmented cybersecurity attacks, and the theft or exposure of substantial amounts of nonpublic information. Additionally, it points to increased vulnerabilities that might arise from dependencies on third-party vendors and supply chain networks.
To counter these threats, the Industry Letter suggests a series of risk mitigation strategies. These include conducting comprehensive risk assessments and developing risk-based programmes, establishing and maintaining robust policies and procedures, and instituting thorough plans related to cybersecurity. It also underlines the importance of managing third-party service providers and vendors effectively, implementing stringent access controls, and ensuring that cybersecurity training, monitoring, and data management protocols are in place.
DFS underscores the evolving nature of AI threats, emphasising the necessity for organisations to consistently review and update their cybersecurity measures, as mandated by Part 500 of the regulation. While this guidance is primarily directed at entities under DFS oversight, the outlined measures represent fundamental cybersecurity practices applicable to any organisation aiming to protect itself against AI-related risks.
As the landscape of AI continues to advance and intertwine with various aspects of business and technology, the DFS's proactive approach with this guidance aims to reinforce the resilience of financial institutions and other Covered Entities. By addressing these dynamic challenges head-on, the DFS is seeking to ensure the ongoing security and integrity of sensitive information within its regulated sectors.
Source: Noah Wire Services