Cybersecurity threats continue to grow, and financial services firms are paying the price more than most. In 2024, the average cost of a data breach in the financial industry rose to $6.08 million—over 20% higher than the global average, according to IBM’s annual report.
To help reduce risk and protect customer data, the New York Department of Financial Services (NYDFS) introduced the cybersecurity regulation known as 23 NYCRR Part 500. This New York cybersecurity law sets clear standards for licensed financial and insurance businesses operating in the state.
Part 500 became law in 2017 and was updated in 2023 to address today’s more complex and costly cyber risks. The regulation outlines what a strong cybersecurity program should include, such as written policies, access controls, risk assessments, vendor oversight, employee training, and incident reporting. It also requires companies to file an annual cybersecurity certificate of compliance.
At its core, this regulation is about raising the baseline of cybersecurity for the financial services sector and making sure organizations are prepared to act when something goes wrong.
There’s a lot of legal and technical language surrounding the NYDFS Cybersecurity Regulation. We’ve created this guide to make it easier to understand, so you can focus on keeping your business secure and compliant.
Inside, you’ll find:

If your business holds a license or certificate from the New York Department of Financial Services, you may be required to comply with 23 NYCRR Part 500.
The regulation uses the term “covered entity” to describe organizations and individuals that fall under NYDFS oversight. This includes a range of financial and insurance providers, such as:
Health insurers.
It also applies to some solo practitioners and small firms.
The deciding factor isn’t just size or structure. If your business is authorized by NYDFS and uses technology to operate or manage non-public information, you are likely within scope.
Understanding whether you qualify as a covered entity is the first step toward meeting the regulation’s requirements. It also allows you to confirm whether you’re eligible for an exemption under section 500.19, which we’ll cover next.

Just because your business is regulated by NYDFS doesn’t mean you have to follow every single part of 23 NYCRR Part 500. Section 500.19 outlines a few ways businesses can qualify for exemptions.
These are usually based on your size, the type of license you hold, or whether you actually work with non-public information.
They fall into two main categories: full exemptions and limited exemptions.
A full exemption means you’re not required to comply with most of the regulation. These apply in cases like:
You’re a qualifying reinsurer or annuity society with limited data exposure.
A limited exemption allows smaller businesses to follow only certain parts of the regulation. You may qualify if your organization meets any of the following:
Less than $15 million in total year-end assets.
Even if you qualify for a limited exemption, you’re still required to:
Submit annual filings and incident reports.
NYDFS provides an exemption flowchart to help you determine your status. If you qualify, you must file a notice of exemption within 30 days of becoming eligible.
If you’re not sure which category applies to your business or how to file for a notice of exemption, it may help to speak with a cybersecurity partner who understands the NYDFS Cybersecurity Regulation and can guide you through the technical and operational requirements.

A Chief Information Security Officer (CISO) is the person responsible for managing a company’s cybersecurity program. Under the NYDFS Cybersecurity Regulation, every covered entity must designate a qualified individual to oversee its cybersecurity policies, systems, and risk management practices.
This doesn’t mean you need to hire a full-time executive. For smaller businesses, you can assign the role to someone internal or contract it out to a third party. What matters is that the person in this role is experienced, has the authority to enforce security practices, and reports regularly to senior leadership or the board.
The CISO is also responsible for reviewing key policies, approving exceptions to technical requirements, and filing an annual cybersecurity report with leadership.

The NYDFS Cybersecurity Regulation outlines specific actions that covered entities must take to protect their systems and data. These requirements apply unless you’re fully exempt and are designed to reflect the level of risk your organization faces.
Here’s what those requirements look like in practice:
Every covered entity must implement a written cybersecurity program that’s tailored to its specific risks. This program should be able to detect, respond to, and recover from cybersecurity events. It also must protect both your information systems and any non-public information you store or transmit. It forms the foundation of your NYDFS cybersecurity compliance.
You’re required to adopt and implement a set of formal, written cybersecurity policies that align with your program and address areas such as:
Application development and vulnerability management.
These policies must be approved by a senior officer or the board of directors and reviewed annually.
Your designated CISO must oversee the cybersecurity program and provide a written annual report to executive leadership or the board. The report should highlight program effectiveness, key risks, and any changes made during the year.
You’re expected to test your defenses. This includes:
Regular vulnerability assessments to catch weak spots before attackers do.
Your systems must be able to log and recreate material transactions and security events. Audit trails must be preserved for at least five years and must support both internal reviews and regulatory investigations.
Only the right people should have access to sensitive data. This section requires that access rights be based on job duties and reviewed regularly, especially for users with administrative or privileged access.
If you develop software in-house or use third-party applications, they must be built and tested with security in mind. That means secure coding practices, software reviews, and vulnerability testing before deployment.
You’re required to conduct periodic risk assessments to identify vulnerabilities in your systems and processes. These assessments should guide how you design and update your cybersecurity program.
Whether your cybersecurity team is internal or outsourced, you need qualified people managing it. You’re also expected to stay informed about new and evolving threats by using up-to-date threat intelligence or working with knowledgeable partners.
Vendors and partners can introduce risk. That’s why covered entities are required to implement a third-party security policy that includes:
Ongoing monitoring of vendor access and behavior.
Vendor integrations are common in the financial services space, which makes this especially critical.
You must use multi-factor authentication for remote access and for any system that contains non-public information. An alternative can be approved in writing by your CISO, but it must offer comparable protection.
Don’t keep sensitive data longer than you need to. This section requires that non-public information be securely disposed of once it’s no longer needed for business or legal reasons.
Employees must receive cybersecurity awareness training at least once a year. You’re also required to monitor systems and user activity to detect unauthorized access.
Data must be encrypted in transit and at rest. If that’s not possible, your CISO must approve alternative control. Those controls must be documented and reviewed regularly.
You’re required to maintain a cybersecurity incident response plan that outlines:
How incidents will be reported to regulators and stakeholders.
This plan should be tested and updated regularly.
Two key obligations fall under this section:
NYDFS 72-Hour Reporting Rule – Certain types of cybersecurity events must be reported to the Superintendent within 72 hours of discovery
Timely reporting and accurate documentation are critical parts of your compliance obligations.
You must maintain detailed records of your cybersecurity program, risk assessments, incident response activities, training logs, and other compliance efforts. These records must be retained for at least five years and made available to NYDFS upon request.

In late 2023, the NYDFS made important updates to 23 NYCRR Part 500. These changes reflect how fast cybersecurity risks are advancing and how much more is expected of regulated businesses today.
Here’s what’s new:
The NYDFS Cybersecurity Regulation now requires more direct involvement from company leadership:
Boards of directors must have enough cybersecurity knowledge to understand what’s being reported and ask informed questions.
This reinforces that cybersecurity is a shared responsibility, from the IT department to the boardroom.
If your organization has over 2,000 employees or more than $1 billion in annual gross revenue across all affiliates, it’s now classified as a Class A company. This comes with added compliance requirements, including:
Additional documentation and review obligations for senior leadership.
Several technical requirements under 23 NYCRR Part 500 have been tightened or clarified:
Encryption requirements are more explicit. If encryption at rest or in transit isn’t feasible, compensating controls must be documented and approved by the CISO.
Even if your business qualifies for a limited exemption under Section 500.19(a), you’re still expected to maintain a baseline level of cybersecurity. That includes:
Filing an annual cybersecurity certificate of compliance.
Failure to meet these obligations can still result in enforcement action, even if you’re partially exempt.
One of the most important changes involves the cybersecurity certificate of compliance due each April. Previously, the filing confirmed your organization was compliant at the time of submission.
Now, you’re certifying that you were materially compliant throughout the entire prior calendar year. If your organization was not fully compliant, you’re required to file an Acknowledgment of Noncompliance. This must include an explanation of what was missed and your remediation plan.
Several new deadlines were introduced as part of the 2023 updates to 23 NYCRR Part 500. These apply to all covered entities, including those with a Section 500.19 exemption:
Starting November 1, 2025, you must maintain a current inventory of your information systems.
Staying ahead of these deadlines is critical not just for compliance, but for protecting your business and building trust with regulators and customers alike.

The requirements in the NYDFS Cybersecurity Regulation are meant to scale with your business, but that doesn’t always make them easy to manage, especially for smaller teams or businesses without in-house cybersecurity staff.
You may want to bring in outside help if:
You want help reviewing your compliance posture before the next annual certification.
Support can come from many places: internal IT teams, legal counsel, or a managed service provider (MSP) that understands both the technical side of cybersecurity and the expectations of NYDFS cybersecurity compliance.
Even if you’re confident in your day-to-day operations, working with an experienced partner can help you stay ahead of deadlines, avoid blind spots, and focus on what you do best.
Cybersecurity expectations are higher than ever, and the NYDFS cybersecurity regulations continue to evolve to meet the risks. Whether you’re reviewing your current program, filing for a Section 500.19 exemption, or preparing your next cybersecurity certificate of compliance, the key is staying organized, informed, and proactive.
This guide gave you the essentials; what the regulation covers, who it applies to, and what steps to take. From here, the next move is making sure your cybersecurity program not only checks the boxes but protects your business.
Section 500.15 requires companies to protect non-public information by using encryption, which means turning data into a code so only authorized people can read it. This applies to data that’s stored and data that’s being sent. If encryption isn’t possible, another strong method can be used, but it must be approved by the CISO.
The 72-hour rule means that covered entities must notify NYDFS within 72 hours after determining a cybersecurity event must be reported. This includes incidents that impact business operations, expose non-public information, or require notice to another regulator. The clock starts when the organization confirms the event is reportable, not when the breach occurs.
Penalties for noncompliance can include fines, public enforcement actions, and ongoing regulatory oversight. NYDFS has the authority to investigate cybersecurity failures and issue penalties if a company fails to meet the regulation’s requirements, delays reporting an incident, or files inaccurate certifications.
Non-public information includes data that could cause harm if exposed—like Social Security numbers, driver’s license details, account numbers, or health information. “Material” refers to data that is especially sensitive or essential to customers or the business. Protecting this information is a core goal of the regulation.
Under 23 NYCRR Part 500, multi-factor authentication (MFA) is required for remote access and sensitive systems. MFA adds a second layer of security, like a code sent to your phone or a fingerprint, on top of a password. The 2023 update expanded this requirement to cover more use cases, including access to cloud apps and administrative accounts.
Expert services to help you meet every requirement accurately, on time, and with less effort from your team.
Contact us to learn more.
At SOHO Solutions, we build and maintain cybersecurity programs that align with 23 NYCRR Part 500, including the documentation, policies, and processes you need to stay compliant.
Our team supports financial and insurance organizations with practical services and expert guidance, so you can meet requirements with confidence.
Fill out the form and we’ll get back to you to talk through how we can support your team.
Fill out the form and we’ll get back to you to talk through how we can support your team.