Secure Controls Framework
Download The SCF

New York DFS Cybersecurity Regulation (23 NYCRR Part 500)

23 NYCRR Part 500 sets the cybersecurity requirements for banks, insurance companies and other financial services companies regulated by the New York State Department of Financial Services (NYDFS). It names specific controls, requires incident reporting to DFS and requires an annual compliance filing signed by the company's highest-ranking executive and its CISO.

REGULATION OVERVIEW

From A GRC Perspective, What Is NY DFS 23 NYCRR Part 500?

In March 2017, the New York State Department of Financial Services (NYDFS) issued 23 NYCRR Part 500, which DFS calls its "first-in-the-nation" cybersecurity regulation. Every covered entity must maintain a cybersecurity program based on its risk assessment, keep written cybersecurity policies approved at least annually by a senior officer or its senior governing body, designate a Chief Information Security Officer (CISO) and notify DFS of cybersecurity incidents.

Part 500 is prescriptive. Instead of general principles, it lists controls a covered entity must have in place, such as multi-factor authentication, a documented asset inventory, encryption of nonpublic information in transit and at rest, and incident response and business continuity plans that are tested at least annually. For GRC teams, each requirement needs a control, an owner and evidence that can support the annual compliance filing.

Name

Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500)

Type

Regulatory (State Regulation, New York)

Authoritative
Source

New York State Department of Financial Services (NYDFS)

Part 500 Effective

March 1, 2017

Second Amendment

Effective November 1, 2023; phased in through November 1, 2025

Enforced By

Superintendent of Financial Services (NYDFS)

Applies To

Any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the New York Banking Law, Insurance Law or Financial Services Law

Certification
Available

No official government certification. Each covered entity must submit an annual certification of material compliance, or an acknowledgment of noncompliance, to DFS by April 15. The SCR Conformity Assessment Program (SCR CAP) can provide a third-party conformity assessment against Part 500 requirements.

TL/DR: Too Long, Didn't Read

23 NYCRR Part 500 applies to the banks, insurance companies and other financial services companies that NYDFS licenses or charters. It requires a cybersecurity program based on a risk assessment, written policies, a CISO, specific technical controls and notice to DFS within 72 hours after determining that a cybersecurity incident has occurred.

The Second Amendment took effect November 1, 2023 and phased in new requirements through November 1, 2025, including multi-factor authentication for anyone accessing the company's information systems, a documented asset inventory and added controls for larger "Class A" companies. Every April 15, the highest-ranking executive and the CISO sign a filing that either certifies material compliance for the prior calendar year or acknowledges noncompliance, and the supporting records must be kept for five years.

BACKGROUND

From The 2017 Regulation To The Second Amendment

DFS issued 23 NYCRR Part 500 on March 1, 2017. Covered entities had 180 days to meet most requirements, and one to two years for others, including penetration testing and vulnerability assessments, risk assessments, multi-factor authentication, audit trails, encryption and third-party service provider security. The first annual compliance certifications were due February 15, 2018.

Part 500 reaches any person or organization that DFS licenses, charters or otherwise authorizes under the Banking Law, the Insurance Law or the Financial Services Law. That includes state-chartered banks, insurance companies, mortgage companies, money transmitters and virtual currency businesses, among others.

The Second Amendment (November 2023)

DFS finalized the Second Amendment on November 1, 2023. Among other changes, it defined a category of larger "Class A" companies, required the senior governing body to oversee the company's cybersecurity risk management, added a notice to DFS within 24 hours of any extortion payment made in connection with a cybersecurity event, required the annual filing to be signed by the highest-ranking executive and the CISO, and expanded multi-factor authentication. Requirements were phased in, with the last ones, multi-factor authentication for all access to information systems and the asset inventory, due November 1, 2025.

Class A Companies

A Class A company is a covered entity with at least $20 million in gross annual revenue in each of the last two fiscal years from its own business operations and its affiliates' New York operations, plus either more than 2,000 employees averaged over the last two fiscal years or more than $1 billion in gross annual revenue in each of the last two fiscal years, counting affiliates. Class A companies must also conduct independent audits of their cybersecurity programs, use a privileged access management solution, automatically block commonly used passwords, and run endpoint detection and response with centralized logging and security event alerting. For some of these controls, the regulation allows CISO-approved compensating controls.

Limited Exemptions

A covered entity qualifies for a limited exemption if it has fewer than 20 employees and independent contractors (including affiliates), less than $7.5 million in gross annual revenue in each of the last three fiscal years from its business operations and its affiliates' New York operations, or less than $15 million in year-end total assets, including affiliates. The exemption removes some requirements, such as the CISO, penetration testing, audit trails and incident response plans. The entity must still maintain a cybersecurity program, written policies, risk assessments, multi-factor authentication for remote and privileged access, and incident notification, and it must file a Notice of Exemption with DFS.

PENALTIES & ENFORCEMENT

Consequences of Non-Compliance

DFS enforces Part 500 under the superintendent's authority in the Banking Law, the Insurance Law and the Financial Services Law. Enforcement actions are made public through consent orders, which can include a civil monetary penalty and required remediation.

How Violations Are Counted

Under section 500.20, committing a single act prohibited by Part 500, or failing to meet a single obligation, is a violation. That includes failing to secure or prevent unauthorized access to nonpublic information because of noncompliance with any section, and the material failure to comply with any section for any 24-hour period. When setting a penalty, DFS considers factors such as cooperation, good faith, prior violations, the extent of harm to consumers, the number and gravity of the violations, and whether the company's policies and procedures are consistent with nationally recognized cybersecurity frameworks such as NIST.

Public Enforcement Actions

DFS publishes its cybersecurity consent orders. In October 2022, EyeMed Vision Care settled with DFS for $4.5 million after a phishing attack gave a bad actor access to a shared email mailbox holding more than six years of consumer nonpublic information. In November 2023, First American Title Insurance Company settled with DFS for $1 million after DFS found it failed to maintain effective governance and classification, access controls and identity management, and risk assessment policies and procedures.

Improper Compliance Certifications

The annual certification has to be based on data and documentation sufficient to demonstrate material compliance. In the EyeMed settlement, DFS found that the company had not conducted an adequate risk assessment, and that its cybersecurity certifications for calendar years 2018 through 2021 were improper as a result. A covered entity that did not materially comply files an acknowledgment of noncompliance instead, which identifies each section not met, describes the gap and gives a remediation timeline.

DOCUMENTATION VALUE

How the SCF Maps to NY DFS 23 NYCRR Part 500

As a Common Controls Framework® (CCF), the Secure Controls Framework® maps 23 NYCRR Part 500 requirements to its 1,500+ controls across 34 domains via Set Theory Relationship Mapping (STRM). This mapping is documented with transparency in NIST IR 8477, enabling organizations to address their NYDFS obligations using a single, integrated control set.

The SCF is a Living Control Set (LCS), continuously updated by volunteer cybersecurity and GRC experts. It is available at no cost under a Creative Commons license and is importable into GRC platforms via .csv or NIST OSCAL JSON.

Cybersecurity Policies

Section 500.3 requires written policies, approved at least annually by a senior officer or the senior governing body, covering 15 topics that range from information security and data governance to vendor management, incident response and vulnerability management. Approval records and version history show that the policies are current.

Risk Assessment

Section 500.9 requires the risk assessment to be reviewed and updated at least annually, and again whenever a change in the business or technology causes a material change. The cybersecurity program and policies are based on it. In the EyeMed matter, an inadequate risk assessment is what made four years of compliance certifications improper.

Incident Response and BCDR Plans

Section 500.16 requires written incident response and business continuity and disaster recovery (BCDR) plans. At least annually, the covered entity must test those plans with the staff and management critical to the response, and test its ability to restore critical data and information systems from backups. Test records show the plans were exercised and revised as needed.

Annual Filing Evidence

Section 500.17(b) requires covered entities to keep all records, schedules, documentation and data supporting the April 15 certification or acknowledgment for five years. That includes the areas, systems and processes that needed material improvement, the remedial efforts taken, and remediation plans and timelines.