New York State Department of Financial Services · NY
Log4j Vulnerability
December 17, 2021
Summary
The New York State Department of Financial Services mandates that all regulated entities assess their vulnerability to the Apache Log4j remote code execution flaw. Entities must actively mitigate risks in their internal systems and third-party software while ensuring compliance with mandatory 72-hour cybersecurity event reporting requirements under 23 NYCRR Section 500.17(a).
December 17, 2021
To: All Regulated Entities
From: New York Department of Financial Services
Re: Log4j Vulnerability
On December 10, 2021, the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (“CISA”), the National Security Agency, and others announced a critical remote code execution vulnerability in many versions of Apache’s Log4j software. Log4j is a java-based logging utility incorporated in frameworks, websites, and applications, and is widely used by major cloud services and well-known software vendors and manufacturers. According to senior cybersecurity professionals, this vulnerability is among the most serious seen to date.
Threat actors are actively exploiting Log4j vulnerabilities. Successful exploitation of the vulnerability can be used to deploy ransomware, steal data, and disrupt operations.
All regulated entities should promptly assess risk to their organization, customers, consumers, and third party service providers based upon the evolving information and take action to mitigate risk. CISA is maintaining and regularly updating a webpage dedicated to Log4j vulnerability guidance. Regulated entities should consult the CISA guidance and implement it wherever appropriate.
Regulated entities are reminded to report cybersecurity events that meet the criteria of 23 NYCRR Section 500.17(a) as promptly as possible and within 72 hours at the latest via the secure DFS Portal, which can be accessed from DFS’s Cybersecurity Resource Center.
Source: https://www.dfs.ny.gov/industry_guidance/industry_letters/il20211217_cyber_log4j_vulnerability
Common questions
- What does "Log4j Vulnerability" cover?
- The New York State Department of Financial Services mandates that all regulated entities assess their vulnerability to the Apache Log4j remote code…
- Which agency issued this update?
- This update was issued by New York State Department of Financial Services.
- When was it published?
- It was published on December 17, 2021.
Related updates
- ACI Payments, Inc. Settlement Agreement and Consent Order issued by the Division of Banking
- Ransomware Self-Assessment Tool (R-SAT) (October 23, 2023, Version 2.0 Release)
- Updated Nonbank Ransomware Self-Assessment Tool (R-SAT)
- Lakeview Loan Servicing, LLC, Pingora Loan Servicing, LLC, Community Loan Servicing, LLC, and Bayview Asset Management, LLC Multistate Settlement Agreement and Consent Order issued by the Division of Banking
- Pionex, Inc. Consent Order issued by the Division of Banking
- Cybersecurity Advisory - Heightened Cybersecurity Risks Associated with Frontier AI Models