Why Financial Services Is the Highest-Priority Target

Financial institutions hold the most valuable data in the economy: account credentials, wire transfer capabilities, personal financial information, and access to payment systems. Banks, investment advisors, insurance companies, and lending firms are targeted by sophisticated threat actors — including nation-states — at a frequency and sophistication that exceeds most other industries. According to multiple industry reports, financial services consistently ranks as the top or second-highest targeted sector for cyberattacks.

The Regulatory Landscape for New York Financial Firms

Financial services firms operating in New York face an unusually dense regulatory environment:

  • NYDFS 23 NYCRR 500 — Annual penetration testing, comprehensive cybersecurity program, CISO designation, annual CEO/CISO certification. The most prescriptive state-level cybersecurity regulation in the US. Full NYDFS guide →
  • FINRA — FINRA Rule 4370 (business continuity) and related guidance require broker-dealers to address cybersecurity risk management. FINRA examinations increasingly include cybersecurity review.
  • FFIEC — Federal Financial Institutions Examination Council guidelines require bank examiners to assess cybersecurity maturity. The FFIEC Cybersecurity Assessment Tool provides a framework for self-assessment.
  • Gramm-Leach-Bliley Act (GLBA) — The FTC Safeguards Rule requires financial institutions to implement a written information security plan addressing access controls, risk assessment, and testing.
  • NY SHIELD Act — New York's data breach notification law applies broadly and has been strengthened in recent years.

Key Threats Targeting Financial Services

  • Business Email Compromise — Wire fraud through email compromise is the most financially damaging crime category targeting financial firms. Law firms and real estate companies in their deal flow are also targeted.
  • Ransomware — Financial firms face significant ransomware targeting due to the perceived ability and regulatory pressure to pay.
  • Third-party risk — Fintech integrations, MSPs, and data processors create supply chain exposure. NYDFS specifically requires third-party risk management.
  • Insider threats — The financial sector has elevated insider threat risk due to access to valuable data and monetary systems.

What an Annual Security Testing Program Looks Like

For a typical New York financial services firm subject to NYDFS, an annual testing program includes: an external network penetration test of internet-facing infrastructure, an internal network penetration test validating lateral movement controls and access management, and a phishing assessment validating employee resistance to social engineering. For firms with web-facing customer portals or APIs, web application testing is added to scope. The testing produces documentation satisfying NYDFS Section 500.5 requirements.

Grid32 has served New York financial institutions since 2009.

We understand NYDFS, FINRA, and FFIEC requirements and structure every engagement to produce the documentation your regulators require.

Talk to an Expert →