The New York State Department of Financial Services (NYDFS) has issued new guidance describing best practices for reducing the risk of a ransomware attack.
Following an examination of ransomware instances reported by regulated entities over the past 18 months, the NYDFS observed these incidents all followed a similar pattern: “Hackers enter a victim’s network, obtain administrator privileges once inside, and then use those elevated privileges to deploy ransomware, avoid security controls, steal data, and disable backups.”



