Part 500 was the first American cybersecurity regulation with teeth, and its Second Amendment made it the strictest general-purpose one: named accountability (a CISO with board reporting), prescriptive controls (universal MFA, asset inventories, EDR for the largest), a 72-hour clock that beats most breach statutes, and a certification signed annually by your highest-ranking officers. DFS enforces through examinations and settlements that name the exact control that failed, its consent orders are the syllabus.
| Regulation | 23 NYCRR Part 500 |
|---|---|
| Covered | NY-licensed banking, insurance, financial services (~3,000 entities) |
| Key clocks | 72h event notice; 24h extortion payment + 30d explanation |
| Recent penalties | OneMain $4.25M; Carnival $5M; PayPal $2M; First American $1M |
| Second Amendment | Phased Nov 2023 - Nov 2025 |
The program DFS examines
Governance with names on it. A qualified CISO (in-house or third-party with internal oversight), annual board reporting, material-issue escalation, and board-level cyber competence. Examiners interview these people; org-chart compliance fails fast.
Controls in the amendment’s order. Universal MFA (the single most-cited gap, OneMain and PayPal both involved access-control failures), asset inventory, encryption of nonpublic information, vulnerability management with documented remediation, monitoring proportionate to class, and tested incident response including backup restoration. Class A adds independent audits and PAM.
Third parties as a regulated surface. Written policies for vendor access, minimum-control contract terms, and periodic assessment, detailed in our third-party requirements guide, and increasingly the root cause in DFS actions (First American’s exposure ran through an unauthenticated document URL; Genesis’s through service configurations).
The certification discipline. Every April 15, either certify material compliance or acknowledge non-compliance with remediation plans, signed by the CISO and CEO (or equivalents). The annual certification guide covers the evidence file that should stand behind the signature.
Coordinate the stack. Deemed compliance flows to the SHIELD Act’s safeguards duty, control mappings to the FTC Safeguards Rule and NIST CSF serve multi-regulator institutions, and consumer-facing web properties still need ordinary privacy hygiene, check yours with a free scan.