US State Law New York, USA

NYDFS 23 NYCRR 500: Cybersecurity Regulation Guide

New York's financial-services cybersecurity regulation after the Second Amendment: who is covered, CISO and MFA duties, 72-hour reporting, class rules, and enforcement.

Regulation

23 NYCRR Part 500 (NYDFS Cybersecurity Regulation, 2017, amended November 2023)

Max Penalty

Civil penalties under Banking, Insurance, and Financial Services Laws; settlements have reached $3M-$4.25M per institution

Enforcing Authority

New York State Department of Financial Services (NYDFS)

Official Source

www.dfs.ny.gov

Executive Summary

  • Part 500 applies to entities operating under New York banking, insurance, or financial services licenses, roughly 3,000 covered entities including out-of-state insurers and money transmitters licensed in New York.
  • The Second Amendment (November 2023, phased through November 2025) raised the bar: expanded governance duties, mandatory MFA for all remote and privileged access, asset inventories, enhanced monitoring, and a new 'Class A' tier with independent audits and tailored controls for the largest companies.
  • Core architecture: a written cybersecurity program based on risk assessment, a CISO reporting to the board, encryption, access controls, penetration testing, vendor security policies, and incident response.
  • Notification is fast and broad: 72 hours to notify NYDFS of cybersecurity events (including ransomware deployment), 24 hours for extortion payments with a 30-day written explanation.
  • Enforcement is real: First American ($1M, 2023), Carnival ($5M, 2022), Genesis ($8M with related actions), OneMain Financial ($4.25M, 2023), and PayPal ($2M, 2025) settlements, plus the annual certification's personal-accountability pressure.

Part 500 was the first American cybersecurity regulation with teeth, and its Second Amendment made it the strictest general-purpose one: named accountability (a CISO with board reporting), prescriptive controls (universal MFA, asset inventories, EDR for the largest), a 72-hour clock that beats most breach statutes, and a certification signed annually by your highest-ranking officers. DFS enforces through examinations and settlements that name the exact control that failed, its consent orders are the syllabus.

Regulation23 NYCRR Part 500
CoveredNY-licensed banking, insurance, financial services (~3,000 entities)
Key clocks72h event notice; 24h extortion payment + 30d explanation
Recent penaltiesOneMain $4.25M; Carnival $5M; PayPal $2M; First American $1M
Second AmendmentPhased Nov 2023 - Nov 2025

The program DFS examines

Governance with names on it. A qualified CISO (in-house or third-party with internal oversight), annual board reporting, material-issue escalation, and board-level cyber competence. Examiners interview these people; org-chart compliance fails fast.

Controls in the amendment’s order. Universal MFA (the single most-cited gap, OneMain and PayPal both involved access-control failures), asset inventory, encryption of nonpublic information, vulnerability management with documented remediation, monitoring proportionate to class, and tested incident response including backup restoration. Class A adds independent audits and PAM.

Third parties as a regulated surface. Written policies for vendor access, minimum-control contract terms, and periodic assessment, detailed in our third-party requirements guide, and increasingly the root cause in DFS actions (First American’s exposure ran through an unauthenticated document URL; Genesis’s through service configurations).

The certification discipline. Every April 15, either certify material compliance or acknowledge non-compliance with remediation plans, signed by the CISO and CEO (or equivalents). The annual certification guide covers the evidence file that should stand behind the signature.

Coordinate the stack. Deemed compliance flows to the SHIELD Act’s safeguards duty, control mappings to the FTC Safeguards Rule and NIST CSF serve multi-regulator institutions, and consumer-facing web properties still need ordinary privacy hygiene, check yours with a free scan.

Frequently Asked Questions

Who is a 'covered entity' under Part 500?

Any person operating under or required to operate under a license, registration, charter, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law: banks, insurers, agents and brokers, mortgage lenders and servicers, money transmitters, and virtual-currency licensees. Location is irrelevant, an Iowa insurer licensed in New York is covered. Limited exemptions scale duties for the smallest entities (under 20 employees, under $7.5M revenue, or under $15M assets), and covered entities must still file exemption notices.

What did the Second Amendment actually change?

Phased November 2023 through November 2025: governance (CISO reports material issues to the board; the board must have or access cyber expertise); universal MFA for remote access, privileged accounts, and third-party access to nonpublic information; asset inventory requirements; enhanced vulnerability management and monitoring (EDR, centralized logging for Class A); annual independent audits for Class A companies; stricter incident-response and BCDR testing including backups; and the split certification option (full compliance or documented remediation plans).

What is a Class A company?

A covered entity with at least $20M in New York gross revenue that has either 2,000+ employees or $1B+ in global revenue (calculated with affiliates). Class A duties add independent audits of the cybersecurity program, external expert risk assessments at defined intervals, privileged access management solutions, and automated blocking of common passwords, the regulation's enterprise tier.

What must be reported, and how fast?

Within 72 hours: cybersecurity events with a reasonable likelihood of materially harming normal operations, events requiring notice to any other regulator, and ransomware deployed within a material part of systems. Within 24 hours: any extortion payment, followed within 30 days by a written explanation of why payment was necessary and what alternatives were considered. Reporting runs through the DFS portal, and under-reporting features in nearly every enforcement action.

How does Part 500 relate to SHIELD and other regimes?

Part 500 compliance gives deemed-compliance under the SHIELD Act's safeguards requirement, but SHIELD's breach-notification duties (to consumers and the AG) still apply separately. The FTC Safeguards Rule governs non-bank financial institutions federally with overlapping controls, and NIST CSF mapping satisfies examiners' expectations for risk-assessment structure. Multi-regulator institutions typically maintain one control set mapped to all four.

Regulatory Crosswalk

NY SHIELD ActFTC Safeguards RuleNIST CSF

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.