Reference · LeakTrace Intelligence Team
NYDFS Part 500.
23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies
At a glance
- Jurisdiction
- New York
- Breach reporting deadline
- 72 hours
- Applies to
- Financial
- Authoritative source
- https://www.dfs.ny.gov/industry_guidance/cybersecurity
- Last updated
- August 5, 2026
## What it is
23 NYCRR Part 500 is the New York Department of Financial Services (NYDFS) cybersecurity regulation, originally effective March 1, 2017 and substantially amended November 1, 2023 (Second Amendment). It applies to any person or entity operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization from NYDFS — including banks, insurance companies, mortgage brokers, virtual currency businesses, and consumer lenders.
## Who it applies to
Covered entities as defined in section 500.1(e). Small businesses may qualify for limited exemptions under section 500.19 (fewer than 20 employees, less than $7.5M revenue, less than $15M in assets — [VERIFY current thresholds]), but even exempted entities must implement core security requirements.
Class A Companies (added in the 2023 amendment) — entities with over $20M in NY revenue over the past three fiscal years and either 2,000+ employees or over $1B in revenue — face heightened requirements including endpoint detection and response, independent audits, and privileged access management controls.
## Key cybersecurity program requirements
- **Written cybersecurity program** (section 500.2) based on a risk assessment (section 500.9)
- **Written cybersecurity policy** approved annually by the senior governing body (section 500.3)
- **CISO designation** (section 500.4) with annual written report to the senior governing body
- **Penetration testing** (annual) and **vulnerability assessments** (bi-monthly)
- **Multi-factor authentication** for all remote access and privileged accounts
- **Encryption** of nonpublic information in transit and at rest
- **Written incident response plan** including business continuity and disaster recovery
- **Training and monitoring** — annual cybersecurity awareness training; monitoring authorized users
- **Third-party service provider security policy** (section 500.11)
## Cybersecurity event notification
Section 500.17 requires notification to the Superintendent within 72 hours from determination that a cybersecurity event has occurred if either:
1. Notice is required to be provided to any government body, self-regulatory agency, or supervisory body, OR
2. There is a reasonable likelihood of materially harming any material part of the normal operations of the covered entity, OR
3. (Second Amendment addition) A cybersecurity event involves ransomware payment or an extortion payment was made
Ransomware payments require 24-hour separate notice of the payment (section 500.17(c)).
## Annual compliance certification
Section 500.17(b) requires covered entities to file an annual Notice of Compliance or Notice of Acknowledgment of Non-Compliance by April 15 for the prior calendar year. Filing a false certification can support enforcement action.
## Penalties
NYDFS enforcement powers include monetary penalties, license revocation, and consent orders. Notable enforcement includes First American Title Insurance ($1M — 2023), OneMain Financial ($4.5M — 2023), Genesis Global Trading ($8M — 2023) [VERIFY figures]. NYDFS pursues violations of Part 500 as violations of the underlying Banking Law, Insurance Law, or Financial Services Law with corresponding penalty schedules.
## How LeakTrace aligns
LeakTrace's continuous external-surface monitoring supports the NYDFS third-party risk management requirements under section 500.11 and surfaces the credential and infrastructure exposures that most often trigger 500.17 notification obligations. Documentation is prepared to feed directly into the annual compliance certification and to demonstrate reasonable security controls to NYDFS examiners.
Key provisions
- § 500.2 — Cybersecurity program
- Establish and maintain a cybersecurity program designed to protect the confidentiality, integrity, and availability of the information systems.
- § 500.4 — Chief Information Security Officer
- Designate a qualified CISO; annual written report to the senior governing body on the state of the cybersecurity program.
- § 500.9 — Risk assessment
- Periodic risk assessments informing design of the cybersecurity program; reviewed and updated as necessary.
- § 500.11 — Third-party service provider security policy
- Written policy addressing the identification and risk assessment of third-party providers with access to information systems or nonpublic information.
- § 500.12 — Multi-factor authentication
- MFA required for remote access, privileged accounts, and all individuals accessing nonpublic information.
- § 500.17 — Notice of cybersecurity event
- 72 hours to notify the Superintendent; 24 hours for ransomware payments.
Recent amendments & guidance
2023-11-01
Second Amendment effective — introduced Class A Company category, ransomware payment reporting, enhanced governance requirements, phased through November 2025.
2024-05-01
Phased Second Amendment provisions effective — incident response and business continuity plans, encryption controls.
2024-11-01
Additional Second Amendment provisions — automated blocking of commonly used passwords, additional risk assessments.
2025-11-01
Final Second Amendment provisions effective — asset inventory, additional access privilege controls. [VERIFY implementation status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs