Fraud Management & Cybercrime , Governance & Risk Management

Impact of N.Y. Agency Head's Departure

Sizing Up the Fate of Planned Cybersecurity Initiatives
Impact of N.Y. Agency Head's Departure
Benjamin M. Lawsky

Will the upcoming departure of Benjamin M. Lawsky, superintendent of the New York State Department of Financial Services, slow down recently announced plans for new cybersecurity initiatives?

See Also: Webinar | The Cost of Convenience: Exploring the Risks of Password Reuse

On May 20, Lawsky said he was moving on, just a week after announcing plans to push for new cybersecurity regulations aimed at addressing third-party risks and beefing up user authentication (see N.Y. to Propose Cybersecurity Regulations).

Financial fraud expert Avivah Litan, an analyst for the consultancy Gartner, says the cybersecurity regulatory plans Lawsky initiated could be set back by at least a year or two.

"Lawsky set the tone for the office," she says. "The problem is that any successor is very likely to be less versant in cybersecurity issues, given that most regulators and policymakers are just beginning to understand what they need to do in this realm."

That's unfortunate, she contends, because many of Lawsky's proposals have helped to push New York banks to get ahead of looming cybersecurity issues.

Like Litan, Shirley Inscoe, a financial fraud analyst for consultancy Aite, says Lawsky's successor will need to focus on cybersecurity and financial fraud. But she says more emphasis needs to be placed on enhancing cybersecurity throughout the financial and payments infrastructure.

"All financial institutions should be more concerned about cybersecurity, and regulatory exams should focus on this issue, since it is one of the greatest threats against the U.S. economy," Inscoe says. "The problem is that retailers, merchants, universities, hospitals, governmental agencies and many others do not focus on adequate security, and settlements of massive data breaches are negligible."

Financial services regulators and politicians should not "expect financial services to provide all the protection needed in an environment where other parties are not investing appropriately," she contends. Placing all of the burden on the shoulders of the banking industry, she says, "is the equivalent to expecting a security guard to protect a building with both hands tied behind his back. Investments need to be made by all types of entities for adequate security to be achieved."

Lawsky's Legacy

Lawsky has been at the helm of the New York State Department of Financial Services since its inception four years ago. Over the course of his career with the department, he has built a reputation for being critical of banks that have inadequate fraud prevention and weak cyber-risk mitigation practices.

While the state agency has not named Lawsky's successor, nor publicly said what Lawsky plans to do next, various media reports claim he plans to open a private legal and consulting practice. The agency did not respond to Information Security Media Group's request for comment about Lawsky's departure and candidates being considered for his replacement.

Earlier this month, Lawsky said he planned by the end of the year to propose new regulations for New York banks to address significant gaps in cybersecurity risks identified by the agency in April.

Lawsky said that the poor marks banks gave themselves earlier this year in a survey of cybersecurity practices conducted by his agency spurred the proposal for new regulations.

Two new cyber-related regulations were being considered, Lawsky said. One would be aimed at ensuring banks require vendors to provide warranties of cybersecurity protection in the event they are breached. The other would require banks to adopt multiple-step authentication processes for employees and customers that log into their systems.


About the Author

Tracy Kitten

Tracy Kitten

Former Director of Global Events Content and Executive Editor, BankInfoSecurity & CUInfoSecurity

Kitten was director of global events content and an executive editor at ISMG. A veteran journalist with more than 20 years of experience, she covered the financial sector for over 10 years. Before joining Information Security Media Group in 2010, she covered the financial self-service industry as the senior editor of ATMmarketplace, part of Networld Media. Kitten has been a regular speaker at domestic and international conferences, and was the keynote at ATMIA's U.S. and Canadian conferences in 2009. She has been quoted by CNN.com, ABC News, Bankrate.com and MSN Money.




Around the Network

Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing bankinfosecurity.com, you agree to our use of cookies.