Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · NYDFS Part 500
Reference · LeakTrace Intelligence Team

NYDFS Part 500.

23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies
At a glance
Jurisdiction
New York
Breach reporting deadline
72 hours
Applies to
Financial
Authoritative source
https://www.dfs.ny.gov/industry_guidance/cybersecurity
Last updated
August 5, 2026
## What it is 23 NYCRR Part 500 is the New York Department of Financial Services (NYDFS) cybersecurity regulation, originally effective March 1, 2017 and substantially amended November 1, 2023 (Second Amendment). It applies to any person or entity operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization from NYDFS — including banks, insurance companies, mortgage brokers, virtual currency businesses, and consumer lenders. ## Who it applies to Covered entities as defined in section 500.1(e). Small businesses may qualify for limited exemptions under section 500.19 (fewer than 20 employees, less than $7.5M revenue, less than $15M in assets — [VERIFY current thresholds]), but even exempted entities must implement core security requirements. Class A Companies (added in the 2023 amendment) — entities with over $20M in NY revenue over the past three fiscal years and either 2,000+ employees or over $1B in revenue — face heightened requirements including endpoint detection and response, independent audits, and privileged access management controls. ## Key cybersecurity program requirements - **Written cybersecurity program** (section 500.2) based on a risk assessment (section 500.9) - **Written cybersecurity policy** approved annually by the senior governing body (section 500.3) - **CISO designation** (section 500.4) with annual written report to the senior governing body - **Penetration testing** (annual) and **vulnerability assessments** (bi-monthly) - **Multi-factor authentication** for all remote access and privileged accounts - **Encryption** of nonpublic information in transit and at rest - **Written incident response plan** including business continuity and disaster recovery - **Training and monitoring** — annual cybersecurity awareness training; monitoring authorized users - **Third-party service provider security policy** (section 500.11) ## Cybersecurity event notification Section 500.17 requires notification to the Superintendent within 72 hours from determination that a cybersecurity event has occurred if either: 1. Notice is required to be provided to any government body, self-regulatory agency, or supervisory body, OR 2. There is a reasonable likelihood of materially harming any material part of the normal operations of the covered entity, OR 3. (Second Amendment addition) A cybersecurity event involves ransomware payment or an extortion payment was made Ransomware payments require 24-hour separate notice of the payment (section 500.17(c)). ## Annual compliance certification Section 500.17(b) requires covered entities to file an annual Notice of Compliance or Notice of Acknowledgment of Non-Compliance by April 15 for the prior calendar year. Filing a false certification can support enforcement action. ## Penalties NYDFS enforcement powers include monetary penalties, license revocation, and consent orders. Notable enforcement includes First American Title Insurance ($1M — 2023), OneMain Financial ($4.5M — 2023), Genesis Global Trading ($8M — 2023) [VERIFY figures]. NYDFS pursues violations of Part 500 as violations of the underlying Banking Law, Insurance Law, or Financial Services Law with corresponding penalty schedules. ## How LeakTrace aligns LeakTrace's continuous external-surface monitoring supports the NYDFS third-party risk management requirements under section 500.11 and surfaces the credential and infrastructure exposures that most often trigger 500.17 notification obligations. Documentation is prepared to feed directly into the annual compliance certification and to demonstrate reasonable security controls to NYDFS examiners.
Key provisions
§ 500.2 — Cybersecurity program
Establish and maintain a cybersecurity program designed to protect the confidentiality, integrity, and availability of the information systems.
§ 500.4 — Chief Information Security Officer
Designate a qualified CISO; annual written report to the senior governing body on the state of the cybersecurity program.
§ 500.9 — Risk assessment
Periodic risk assessments informing design of the cybersecurity program; reviewed and updated as necessary.
§ 500.11 — Third-party service provider security policy
Written policy addressing the identification and risk assessment of third-party providers with access to information systems or nonpublic information.
§ 500.12 — Multi-factor authentication
MFA required for remote access, privileged accounts, and all individuals accessing nonpublic information.
§ 500.17 — Notice of cybersecurity event
72 hours to notify the Superintendent; 24 hours for ransomware payments.
Recent amendments & guidance
2023-11-01
Second Amendment effective — introduced Class A Company category, ransomware payment reporting, enhanced governance requirements, phased through November 2025.
2024-05-01
Phased Second Amendment provisions effective — incident response and business continuity plans, encryption controls.
2024-11-01
Additional Second Amendment provisions — automated blocking of commonly used passwords, additional risk assessments.
2025-11-01
Final Second Amendment provisions effective — asset inventory, additional access privilege controls. [VERIFY implementation status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs