New York Holds Bank Boards Accountable for Vendor Cyber Risk
N-central, developed by N-able, is a remote monitoring and management platform used by managed service providers to patch, monitor and remotely access customers’ systems. A breach of that control layer can give attackers privileged access across multiple client networks, making vendor software a systemic risk for banks. Under New York’s 23 NYCRR Part 500 cybersecurity rules, boards and senior officers are expected to oversee third-party risk rather than leave it solely to technology teams.
On Aug. 11, 2026, the New York State Department of Financial Services told regulated entities to determine promptly whether N-central is used internally or by an MSP or other vendor, review unauthorized access and confirm patches. N-able detected exploitation on July 31, released Hotfix 1 on Aug. 2 and Hotfix 2, version 2026.3.1.10, on Aug. 6 after finding another attack path. The company said a limited number of customers were affected but disclosed no total or financial loss.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.