Back to Blog
Compliance & Risk Cybersecurity

NYDFS Cybersecurity Regulation: What New York Businesses Need to Know

✍️ Eugene Moore · 📅 September 2026 · ⏱ 7 min read

If you do business in New York, NYDFS 23 NYCRR 500 probably applies to you — and the deadline already passed.

New York's cybersecurity regulation was written for financial services companies. But "financial services" in New York covers a much wider range of businesses than most people realize. If you hold a license from the New York State Department of Financial Services, you're a covered entity with active compliance obligations — and the 2024 amendments significantly raised the requirements for everyone.

Who Is Actually Covered

The regulation applies to any entity operating under or required to operate under a license, registration, charter, certificate, permit, accreditation, or similar authorization issued by the New York Department of Financial Services. That includes:

Insurance companies & agents

Any insurer or licensed insurance agent doing business in New York — including those headquartered elsewhere.

Mortgage brokers & servicers

Any entity licensed to originate, broker, or service mortgage loans in New York State.

Money transmitters

Businesses licensed to transmit money or sell payment instruments in New York.

Premium finance companies

Entities that finance insurance premiums for New York policyholders.

Budget planners & debt collectors

Licensed debt collection and budget planning firms operating in New York.

Cryptocurrency businesses

Entities holding a BitLicense or limited purpose trust company charter from NYDFS.

There are limited exemptions for very small companies — fewer than 10 employees, under $5M in gross revenue, or under $10M in year-end total assets. But these are narrow. If you've ever assumed you're too small to be covered, it's worth verifying.

What Most Covered Businesses Are Still Missing

In our experience working with financial services firms in Westchester and Fairfield County, these are the gaps we find most consistently:

📋

No written cybersecurity policy approved by senior leadership

The regulation requires a written cybersecurity policy reviewed and approved by a senior officer or the board at least annually. Most firms have informal practices but nothing documented and signed off.

👤

No designated CISO or qualified equivalent

A qualified Chief Information Security Officer must be designated — in-house or through a service provider. Smaller firms can outsource this, but someone must be named and accountable.

🔒

MFA not enforced on all systems touching nonpublic information

Multi-factor authentication is required on any system that accesses nonpublic information — not just remote access or email. This includes internal applications, cloud platforms, and admin interfaces.

🔍

No annual penetration testing

Annual penetration testing by a qualified internal or external party is required, plus bi-annual vulnerability assessments. Most firms have never had a formal pen test.

🗂️

No asset inventory of systems that touch NPI

You can't protect what you can't see. A comprehensive inventory of all information systems is required — including hardware, software, and data flows involving nonpublic information.

📞

No incident response plan

A written, tested incident response plan is required — covering detection, response, recovery, and notification. NYDFS now requires written notification within 72 hours of a material cybersecurity event.

What the 2024 Amendments Added

The second amendment to 23 NYCRR 500, effective November 2023 with phased compliance deadlines through 2025, added significant new requirements — particularly for larger firms and elevated the stakes for everyone:

1

Stricter requirements for Class A companies

Entities with over 2,000 employees or $1B in gross revenue face additional requirements including independent audits, endpoint detection and response, and privileged access management controls.

2

72-hour notification requirement

Material cybersecurity incidents must be reported to NYDFS within 72 hours — down from the prior 3-business-day window and with a broader definition of what constitutes a reportable event.

3

Ransom payment notifications

If you make a ransomware payment, you must notify NYDFS within 24 hours of the payment — regardless of whether the incident itself meets the threshold for a material cybersecurity event report.

4

Encryption requirements expanded

Encryption of nonpublic information in transit and at rest is now required, with documented compensating controls required where full encryption isn't implemented.

5

Senior officer annual certification

A senior officer or board member must certify annually to NYDFS that the entity is in compliance. This is a personal attestation — not a checkbox.

Enforcement Is Real

NYDFS issued its first major enforcement action under 23 NYCRR 500 in 2023 — a $4.5M penalty against a mortgage servicer for multiple violations including failure to implement MFA and inadequate access controls. Since then, enforcement activity has increased steadily.

The regulation has teeth, and the department has made clear it intends to use them. The window for "we're working on it" compliance is effectively closed for most requirements. If you're covered and materially out of compliance, the risk of an enforcement action in the event of a breach is significant.

Where to Start

If you're not sure whether you're covered or what your current compliance posture looks like, the first step is a gap assessment — mapping your current controls against the regulation's requirements to identify what's in place, what's missing, and what needs to be prioritized.

Moore Technology Consulting works with financial services firms across Westchester and Fairfield County on NYDFS compliance — including gap assessments, policy development, MFA implementation, and pen test coordination. We can tell you exactly where you stand.

Free NYDFS Gap Assessment

Not sure whether your current posture meets the NYDFS requirements? We'll map your controls against 23 NYCRR 500 and tell you exactly what's open — no charge, no obligation.

DM us "COMPLY" or schedule a free consultation · (646) 791-2137

← Cyber Insurance: What It Covers CT SHIELD: What CT Businesses Need to Know →
Free NYDFS Gap Assessment

Are you covered — and are you compliant?

We'll map your controls against NYDFS 23 NYCRR 500 and tell you exactly where the gaps are — no charge, no obligation.