Curated coverage· general

NYDF issues cybersecurity guidance

New York's DFS issues strict new cybersecurity risk assessment rules that will impact how lenders and merchants handle consumer data.

Curated by Financing Your Way from original reporting by Finextra — Lending. Summary is AI-assisted and editorially reviewed — see our editorial standards.

FYWBy Financing Your Way EditorialSeptember 10, 2026

New York regulators are tightening the screws on how financial companies protect customer data. The Department of Financial Services (DFS) has issued new guidance focused on risk assessments. If you offer consumer financing or work with third-party lenders in New York, this affects your operational security standards. The state now expects a much more granular approach to identifying vulnerabilities before they are exploited. For retailers and operators, this means the lenders you partner with will likely be updating their data sharing protocols. You may see more rigorous security requirements in your merchant agreements. The guidance emphasizes that risk assessments cannot be a 'one and done' annual checklist. They must be continuous and respond to new threats like AI-driven fraud and sophisticated phishing. If your financing partners don't meet these standards, they face significant regulatory heat in one of the country's most important financial markets. Use this as an opportunity to audit your own internal data handling. Ensure your team isn't the weak link in the chain when processing customer applications.

Source: Finextra — Lending

Who else is covering this

Related coverage from across the industry

← Return to the library· Submit a correction