← All regulatory updates

New York State Department of Financial Services · NY

Log4j Vulnerability

December 17, 2021

Summary

The New York State Department of Financial Services mandates that all regulated entities assess their vulnerability to the Apache Log4j remote code execution flaw. Entities must actively mitigate risks in their internal systems and third-party software while ensuring compliance with mandatory 72-hour cybersecurity event reporting requirements under 23 NYCRR Section 500.17(a).

December 17, 2021

To:      All Regulated Entities

From:  New York Department of Financial Services

Re:      Log4j Vulnerability

On December 10, 2021, the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (“CISA”), the National Security Agency, and others announced a critical remote code execution vulnerability in many versions of Apache’s Log4j software.  Log4j is a java-based logging utility incorporated in frameworks, websites, and applications, and is widely used by major cloud services and well-known software vendors and manufacturers.  According to senior cybersecurity professionals, this vulnerability is among the most serious seen to date.  

Threat actors are actively exploiting Log4j vulnerabilities.  Successful exploitation of the vulnerability can be used to deploy ransomware, steal data, and disrupt operations.

All regulated entities should promptly assess risk to their organization, customers, consumers, and third party service providers based upon the evolving information and take action to mitigate risk.  CISA is maintaining and regularly updating a webpage dedicated to Log4j vulnerability guidance.  Regulated entities should consult the CISA guidance and implement it wherever appropriate.

Regulated entities are reminded to report cybersecurity events that meet the criteria of 23 NYCRR Section 500.17(a) as promptly as possible and within 72 hours at the latest via the secure DFS Portal, which can be accessed from DFS’s Cybersecurity Resource Center.

Source: https://www.dfs.ny.gov/industry_guidance/industry_letters/il20211217_cyber_log4j_vulnerability

Common questions

What does "Log4j Vulnerability" cover?
The New York State Department of Financial Services mandates that all regulated entities assess their vulnerability to the Apache Log4j remote code…
Which agency issued this update?
This update was issued by New York State Department of Financial Services.
When was it published?
It was published on December 17, 2021.

Get the free weekly digest

Every mortgage regulatory change, summarized, in your inbox. No account needed.

Related updates