TITLE: Minnesota Department of Commerce Money Transmitter Publishes Non-Depository Information Security Guidance
BODY:
The Minnesota Department of Commerce (DOC) Money Transmitter division has published guidance on non-depository information security and incident notification requirements for financial institutions operating in the state. The guidance implements Minnesota's Nonbank Data Security Law (Minnesota Statutes Chapter 46A), which the 2024 Minnesota Legislature passed to align state requirements with a model law proposed by the Conference of State Bank Supervisors (CSBS) and the updated federal Safeguards Rule.
The DOC Money Transmitter division has compiled a comprehensive resource page addressing cybersecurity requirements for nonbank financial institutions. The guidance includes the full text of Minnesota Statutes Chapter 46A and directives on reporting cybersecurity events to Nicholas Jenson, Senior Examiner, at Nicholas.Jenson@State.MN.US or 651-539-1712. The DOC Money Transmitter division has curated resources from the CSBS Cyber Hygiene Awareness Campaign, which comprises six series of communications covering critical security topics: cyber hygiene actions, end-of-life management and multi-factor authentication, vulnerability and patch management, cybersecurity awareness training, data backup and threat intelligence, and third-party risk management and incident response. Additionally, the DOC Money Transmitter division has made available the updated Nonbank Ransomware Self-Assessment Tool (R-SAT), developed collaboratively by CSBS, state bank examiners, the Bankers Electronic Task Force, and the U.S. Secret Service. The R-SAT enables nonbank companies of all sizes to evaluate their cybersecurity readiness against ransomware threats. The DOC Money Transmitter division has also compiled links to resources from the Cybersecurity and Infrastructure Security Agency (CISA), the Financial Services Information Sharing and Analysis Center (FS-ISAC), and the FFIEC Cybersecurity Awareness programme.
Nonbank financial institutions should review Minnesota Statutes Chapter 46A and utilise the available assessment tools and guidance materials to ensure compliance with state data security requirements and to strengthen their cybersecurity posture.