NYDFS Announces Statement of Charges Hearing against First American Financial

Subsequent to the first ever cybersecurity enforcement action filed by The New York State Department of Financial Services (NYDFS) on July 22, 2020, a Statement of Charges Hearing will be held on January 21, 2022, to determine whether First American Title Insurance Company has committed violations of §§ 500.02, 500.03, 500.04, 500.07, 500.09, 500.10, 500.14, 500.15 and 500.17 of Part 500 of Title 23 of the New York Codes, Rules, and Regulations, also referred to as the Department’s “Cybersecurity Requirements for Financial Services Companies” and if civil monetary penalties shall be imposed.

First American faces alleged charges for deficient cybersecurity controls; failure to follow cybersecurity policies; neglect to conduct security risk assessment; and failure to remedy security vulnerabilities and practices that led to mass exposure of client non-public information including bank account numbers, mortgage and tax records, Social Security Numbers, wire transaction receipts, and drivers’ license images from October 2014 through May 2019. 

Charges brought against First American by NYDFS are the first to be filed violations of NYDFS’ Cybersecurity Regulation Part 500 of Title 23 of the New York Codes, Rules, and Regulations since made effective March 1, 2017.   

In a related matter, on June 15, 2021, First American was charged by the SEC for Cybersecurity Disclosure Controls Failures resulting in being ordered to pay $487,616 penalty. First American was found to be in violation of Exchange Act Rule 13a-15 given that as of May 24, 2019, First American did not have any disclosure controls and procedures related to cybersecurity, including incidents involving potential breaches of that data. The SEC’s ruling underscores the importance of leadership involvement in a firm’s cybersecurity program.  

Enforcement actions by the SEC and NYDFS signals increasing risk of penalty for financial services firms that do not meet cybersecurity requirements.  

For more information about NYDFS first cybersecurity enforcement action: https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202007221  

For more information about NYDFS Statement of Charges and Notice of Hearing: https://www.dfs.ny.gov/reports_and_publications/public_hearings