New York Policy Statement 103 (NPS 103) is a set of guidelines issued by the New York State Department of Financial Services (DFS) that govern the cybersecurity programs of banking and financial services institutions operating in New York State. NPS 103 sets forth minimum requirements for the development, implementation, and maintenance of effective cybersecurity programs designed to protect consumers’ private data. It requires that institutions develop, implement, and maintain a cybersecurity program that meets or exceeds the minimum standards set forth in the statement. NPS 103 also requires institutions to conduct periodic risk assessments, implement security-related personnel policies and procedures, and provide regular cybersecurity awareness training for employees and contractors. There are two main types of NPS 103. The first, NPS 103-A, applies to all banking and financial services institutions licensed or chartered in New York State. The second, NPS 103-B, applies to all third-party service providers that work with these institutions.