- Key insight: New York named a commercial software product, conceded the flaw probably isn't at the banks receiving the alert, and made their boards answerable for it anyway.
- Expert quote: "Playing possum won't fly if there is a vendor issue brewing that is reasonably likely to impact the covered entity," said Lisa Sotto, chair of Hunton Andrews Kurth's global privacy and cybersecurity practice.
- Forward look: N-able filed a quarterly report and a current report with the SEC the day before the alert, and neither mentions the vulnerability or the break-ins.
Overview bullets generated by AI with editorial review.
On Tuesday, New York's financial regulator told every bank it oversees to go find out whether a piece of software they almost certainly do not own is running somewhere in their supply chain.
The software is N-central, sold by a company called N-able. IT firms use it to monitor, patch and remotely control the computers of the businesses that hire them. Attackers have been breaking into it since July 31,
The alert highlights the growing responsibility New York places on banks, and sometimes their boards, for security flaws anywhere in their supply chains, including in software they never bought, cannot patch and might not know their IT providers use.
The New York State Department of Financial Services, or NYDFS, named the product in
It told those firms to determine "whether N-central is used within their environment or by any MSP or other Third-Party Service Provider that supports their information systems."
The letter conceded the problem "is likely limited to MSPs," using the shorthand for managed service providers, which manage portions of their customers' businesses (such as IT and network management, payroll and supply chains).
NYDFS assigned the problem to bank leadership anyway. The "senior governing bodies and senior officers" of regulated firms "must actively engage in cybersecurity risk management, including through monitoring and oversight of third-party service providers," the letter said.
The nonbinding guidance letter points to binding rules; the
The phrase "senior governing bodies and senior officers" matches text the department added to that regulation in a 2023 amendment, and American Banker did not find the phrase in any of the seven earlier alerts in which NYDFS named a flawed product.
In other words, the Tuesday letter appears to be the first time NYDFS has told bank leaders to manage a specific third-party cybersecurity threat.
The vulnerability appears contained; the mandate is still broad
Attackers who get into an N-central server can move into customers' networks "with administrator network privileges" and can "create or register for new services, allowing continued access even after compromised N-central credentials are revoked," according to the letter.
More than 500,000 businesses worldwide use N-able's software, according to the company's most recent
Likewise, NYDFS has not said how many banks rely on providers that run N-central.
Based on public information, no bank has been caught out by the vulnerability, and the total reach of the problems appears to be limited. A spokesperson for the New York Department of Financial Services did not immediately respond to questions about why the department singled out N-central.
Researchers at the security firm Sophos found "a single compromised organization" in the company's customer data, according to
N-able filed
N-able did not immediately respond to a request for comment.
The silence suggests calm. Rules the Securities and Exchange Commission
Nonetheless, NYDFS wants banks to make sure their vendors and their vendors' vendors are in the clear.
Why NYDFS would name a product banks don't own
Naming a product with a security flaw is not new for the department, which has done it eight times since 2020, according to an American Banker review of every cybersecurity industry letter NYDFS has published.
The seven before Tuesday's covered
All of those flaws affected banks' vendors and third parties, but they also affected banks directly. In other words, banks had an opportunity to patch their own systems in response to those letters.
In the case of N-central, banks cannot respond by applying patches. The letter instead calls out banks' leaders as needing to engage their vendors actively in identifying N-central in their IT supply chains.
Read more:
The top-performing 20 public banks with under $2B of assets in 2025 The top-performing banks with $2B to $10B of assets in 2025 'The data has to be perfect': BofA CEO Moynihan on AI Should a bank ever be liable when a customer gets scammed?
By one measure, the letter is a year late. Two earlier N-central flaws entered a
The current flaw put the product in the vulnerability catalog for a second consecutive August. This time, the department responded.
In the 12 months between N-central vulnerability disclosures, the department's
The letter's demand on boards restates a duty they already carried, according to Lisa Sotto, who chairs the global privacy and cybersecurity practice at the law firm Hunton Andrews Kurth.
Boards oversee the cybersecurity program but "don't have day-to-day operational responsibilities so would not be expected to raise their hand when new vulnerabilities are announced," Sotto told American Banker.
The board's job is to ensure "an appropriate cybersecurity framework is in place" and to leave operations to management, she said.
Many banks lack the visibility NYDFS wants them to exercise
The letter's first instruction assumes a bank can find out what software its IT provider runs. A bank can always ask, and a provider that wants to keep its business will often answer; what many banks lack is a way to compel a complete response.
Nearly all banks (99%) rely at least partly on outside firms for cybersecurity work, according to
Of that nearly universal share,
"Banks are highly regulated, but many third-party vendors are not," Rob Carothers, a Jones Walker partner and co-author of the survey, said in the
How much a bank can demand comes down to its contract. A bank's ability to monitor the software its vendors run is "almost totally dependent upon any monitoring and audit rights it negotiates through its agreement with the vendor," Thomas Walker Jr., a Jones Walker partner who co-authored the survey, told American Banker on Thursday.
Community banks typically spend too little time negotiating those rights, Walker said, and some have little leverage to demand them because few vendors offer the service at a price the bank can afford.
A bank that lacks both security staff and those contract provisions has limited options when an alert like New York's arrives, according to Walker. It will need outside professionals to assess the threat, and "that will be very expensive without support from the vendor impacted," he said.
The outsourcing is growing; more of Walker's bank clients are handing important parts of their IT operations to managed service providers as cybersecurity costs rise and talent, particularly in rural areas, grows scarcer.
That blindness collides with a reporting deadline. A
A bank that cannot see what its provider runs cannot make that determination on its own. If intruders reach the bank's systems through its IT firm's copy of N-central, the bank might learn of it only when the provider says so.
Public reports about a flaw do not start the clock either. The rule's criteria refer to an impact on the bank itself "rather than mere knowledge that a vendor's tools have an issue," Sotto said.
A bank may not go willfully blind to cyber issues. NYDFS rules require a bank's cybersecurity program to be able to detect and respond to cybersecurity events, Sotto said; a bank cannot dodge the reporting duty by declining to investigate whether a vendor's problem reached it.
"Playing possum won't fly if there is a vendor issue brewing that is reasonably likely to impact the covered entity," she said.
Walker pointed to possible help from Washington; the Federal Deposit Insurance Corp. is
That could be "an important development" for community banks, he said, because it may allow them to rely on regulators' expertise to vet the security of vendors they cannot inspect themselves.












