Mark RadarMARK RADAR
About
EN
Sign in
Event File FINTECH Financial Regulation

New York Holds Bank Boards Accountable for Vendor Cyber Risk

1 reports · First detected 2026-08-14 · Last active 2026-08-14

N-central, developed by N-able, is a remote monitoring and management platform used by managed service providers to patch, monitor and remotely access customers’ systems. A breach of that control layer can give attackers privileged access across multiple client networks, making vendor software a systemic risk for banks. Under New York’s 23 NYCRR Part 500 cybersecurity rules, boards and senior officers are expected to oversee third-party risk rather than leave it solely to technology teams.

On Aug. 11, 2026, the New York State Department of Financial Services told regulated entities to determine promptly whether N-central is used internally or by an MSP or other vendor, review unauthorized access and confirm patches. N-able detected exploitation on July 31, released Hotfix 1 on Aug. 2 and Hotfix 2, version 2026.3.1.10, on Aug. 6 after finding another attack path. The company said a limited number of customers were affected but disclosed no total or financial loss.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)