Cyber Insurance Subjectivity Tracker

Rules

Add-on: United States

NY DFS 23 NYCRR 500

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

edition 23 NYCRR Part 500, section level as held (our copy carries no version string). 12 requirements cited here. Every 23 NYCRR 500 clause we hold.

Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
500.12
23 NYCRR 500
Multi-Factor Authentication

MFA required for any individual accessing the Covered Entity's information systems. Specifically required for remote access to information systems, remote access to third-party applications including cloud-based, and all privileged accounts other than service accounts that prohibit interactive login. Reasonably equivalent or more secure controls require CISO written approval and annual review.

evidence an assessor asks for MFA architecture diagram; Coverage report by user population (employees, contractors, customers, privileged); VPN and SSO MFA configuration screenshots; Cloud application MFA enforcement evidence; CISO-approved compensating controls register with annual review; Service account inventory with interactive login disabled; Phishing-resistant MFA roadmap (Second Amendment alignment)

Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
500.12
23 NYCRR 500
Multi-Factor Authentication

MFA required for any individual accessing the Covered Entity's information systems. Specifically required for remote access to information systems, remote access to third-party applications including cloud-based, and all privileged accounts other than service accounts that prohibit interactive login. Reasonably equivalent or more secure controls require CISO written approval and annual review.

evidence an assessor asks for MFA architecture diagram; Coverage report by user population (employees, contractors, customers, privileged); VPN and SSO MFA configuration screenshots; Cloud application MFA enforcement evidence; CISO-approved compensating controls register with annual review; Service account inventory with interactive login disabled; Phishing-resistant MFA roadmap (Second Amendment alignment)

Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
500.5
23 NYCRR 500
Vulnerability Management

Conduct penetration testing at least annually by qualified internal or external party, automated scans of information systems and manual reviews of systems not covered by scans, document and report material issues, prioritize and remediate. Class A must use external experts at least every three years.

evidence an assessor asks for Annual penetration test report from qualified party; Automated vulnerability scan schedule and outputs; Manual review records for non-scannable systems; Remediation tickets with SLAs and closure evidence; Risk-based prioritization methodology; Class A external expert engagement letter (triennial); Monitoring of publicly disclosed vulnerabilities and CISA KEV tracking

Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements

ClauseThe held text, and the evidence an assessor asks for
500.5
23 NYCRR 500
Vulnerability Management

Conduct penetration testing at least annually by qualified internal or external party, automated scans of information systems and manual reviews of systems not covered by scans, document and report material issues, prioritize and remediate. Class A must use external experts at least every three years.

evidence an assessor asks for Annual penetration test report from qualified party; Automated vulnerability scan schedule and outputs; Manual review records for non-scannable systems; Remediation tickets with SLAs and closure evidence; Risk-based prioritization methodology; Class A external expert engagement letter (triennial); Monitoring of publicly disclosed vulnerabilities and CISA KEV tracking

Administrators use a separate privileged account and environment for admin work only, with no internet or email on it

ClauseThe held text, and the evidence an assessor asks for
500.7
23 NYCRR 500
Access Privileges and Management

Limit user access privileges to Nonpublic Information based on least privilege, limit privileged accounts, periodically review access (at least annually), promptly terminate access on role change or separation, disable or securely configure remote access, implement password policy aligned with industry standards. Class A must implement privileged access management and prohibit commonly used passwords.

evidence an assessor asks for Access control policy with least privilege standard; Privileged account inventory and PAM tooling for Class A; Annual user access reviews with attestations; Joiners movers leavers process with timing metrics; Password policy aligned to NIST or equivalent; Banned password list enforcement (Class A); Remote access architecture and MFA evidence

Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated

ClauseThe held text, and the evidence an assessor asks for
500.7
23 NYCRR 500
Access Privileges and Management

Limit user access privileges to Nonpublic Information based on least privilege, limit privileged accounts, periodically review access (at least annually), promptly terminate access on role change or separation, disable or securely configure remote access, implement password policy aligned with industry standards. Class A must implement privileged access management and prohibit commonly used passwords.

evidence an assessor asks for Access control policy with least privilege standard; Privileged account inventory and PAM tooling for Class A; Annual user access reviews with attestations; Joiners movers leavers process with timing metrics; Password policy aligned to NIST or equivalent; Banned password list enforcement (Class A); Remote access architecture and MFA evidence

Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner

ClauseThe held text, and the evidence an assessor asks for
500.6
23 NYCRR 500
Audit Trail

Securely maintain systems that, based on Risk Assessment, are designed to reconstruct material financial transactions and include audit trails to detect and respond to cybersecurity events that have material likelihood of harming operations. Retain transaction records five years and audit trails three years.

evidence an assessor asks for Logging and SIEM design document; List of in-scope financial systems and event logs; Five-year transaction record retention proof; Three-year audit trail retention proof; Log integrity protection controls (WORM, hashing); Log review and alerting procedures; Risk Assessment driving logging scope

There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names

ClauseThe held text, and the evidence an assessor asks for
500.16
23 NYCRR 500
Incident Response and Business Continuity Management

Establish written Incident Response Plan and Business Continuity and Disaster Recovery Plan reasonably designed to respond to and recover from material cybersecurity events. Plans must address specified elements (internal processes, goals, roles, communications, remediation, documentation, evaluation). Test plans annually with all critical staff and proactively maintain backups isolated from network connections.

evidence an assessor asks for Incident Response Plan addressing all required §500.16(a)(1) elements; BCDR plan including ransomware scenarios; Annual tabletop and technical test results with lessons learned; Backup architecture demonstrating isolation (immutable, offline, or air-gapped); Backup restore test evidence; Communication plan including regulator and customer notifications; Post-incident review and improvement records

Staff are trained to recognise phishing and other social engineering, and to report a suspected incident

ClauseThe held text, and the evidence an assessor asks for
500.14
23 NYCRR 500
Monitoring and Training

Implement risk-based controls including monitoring of authorized user activity and detection of unauthorized access or tampering, malware protection, annual cybersecurity awareness training including social engineering. Class A must implement endpoint detection and response solution and centralized logging.

evidence an assessor asks for UEBA or user activity monitoring outputs; Anti-malware deployment coverage report; Annual training completion records with phishing simulation results; Class A EDR coverage dashboard; Class A centralized SIEM logging design and coverage; CISO-approved compensating control register if EDR/SIEM not implemented (Class A); Training content review covering social engineering

Laptops, phones and removable media that hold sensitive data are encrypted

ClauseThe held text, and the evidence an assessor asks for
500.15
23 NYCRR 500
Encryption of Nonpublic Information

Implement controls including encryption to protect Nonpublic Information held or transmitted by the Covered Entity in transit over external networks and at rest. Where encryption at rest is infeasible, CISO may approve effective alternative compensating controls, reviewed at least annually.

evidence an assessor asks for Encryption standards and approved algorithms list; TLS configuration scans for external endpoints; At-rest encryption coverage report by data store; Key management procedures and HSM evidence; CISO-approved compensating control register for at-rest exceptions with annual review; Discovery scans for unencrypted Nonpublic Information; Email and file transfer encryption configuration

IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements

ClauseThe held text, and the evidence an assessor asks for
500.11
23 NYCRR 500
Third Party Service Provider Security Policy

Implement written policies and procedures for security of information systems and Nonpublic Information accessible to or held by Third Party Service Providers. Address identification and risk assessment, minimum cybersecurity practices, due diligence, periodic reassessment, and contractual representations on MFA, encryption, breach notice, and representations.

evidence an assessor asks for Third Party Service Provider policy; Vendor inventory with risk tiering; Due diligence questionnaires and evidence; Contract clauses for MFA, encryption, breach notice, and representations; Periodic vendor reassessment schedule and outputs; Termination and offboarding procedures; Subcontractor (fourth party) review evidence

A written information security program exists, owned by a named qualified individual or officer

ClauseThe held text, and the evidence an assessor asks for
500.2
23 NYCRR 500
Cybersecurity Program

Maintain a written cybersecurity program based on the Risk Assessment that performs the core functions: identify, protect, detect, respond, recover, and fulfill reporting obligations.

evidence an assessor asks for Written cybersecurity program document; Mapping of program elements to identify/protect/detect/respond/recover functions; Risk Assessment linkage matrix; Board or Senior Governing Body approval record; Annual program review minutes; Program scope statement including affiliates; Evidence of integration with enterprise risk

500.4
23 NYCRR 500
Cybersecurity Governance (CISO)

Designate a qualified CISO responsible for overseeing and implementing the program and enforcing policy. CISO reports in writing at least annually to Senior Governing Body on program status, risks, and material events. Senior Governing Body must exercise oversight and have sufficient cybersecurity expertise.

evidence an assessor asks for CISO appointment letter with qualifications; Annual CISO written report to Senior Governing Body; Board or committee minutes evidencing oversight; Material event notifications to governing body; Evidence of cybersecurity expertise on governing body (training, advisors); CISO independence and reporting line diagram; Third-party CISO arrangement and oversight if applicable

A written risk assessment of the information systems is done and repeated periodically

ClauseThe held text, and the evidence an assessor asks for
500.9
23 NYCRR 500
Risk Assessment

Conduct a written Risk Assessment of the Covered Entity's information systems, reviewed and updated at least annually and whenever a change in business or technology causes material change to risk. Assessment must follow written policies and procedures and account for emerging technologies and changes in nonpublic information.

evidence an assessor asks for Written Risk Assessment methodology; Current annual Risk Assessment report; Risk register with treatments and owners; Change-triggered reassessments log; Inventory of information systems and data flows feeding the assessment; Linkage of Risk Assessment to controls in §500.2 program; Board or governing body briefing on top risks

The business knows the notice its rule requires after an incident or a data breach, to whom and by when

ClauseThe held text, and the evidence an assessor asks for
500.17
23 NYCRR 500
Notices to Superintendent

Notify the Superintendent within 72 hours of a Cybersecurity Incident affecting the Covered Entity. Provide notice of extortion payment within 24 hours, with detailed explanation within 30 days. File annual Notice of Compliance or Acknowledgment of Noncompliance by April 15 signed by highest-ranking executive and CISO. Maintain supporting records for five years.

The requirement's own words: within 72 hours of a Cybersecurity Incident; within 24 hours; within 30 days

evidence an assessor asks for Incident notification SOP with §500.17(a) criteria; Sample submitted 72-hour notices through the Department's portal; 24-hour ransom payment notice procedure and 30-day explanation template; Signed annual Notice of Compliance covering prior calendar year; Acknowledgment of Noncompliance with remediation plan if applicable; Five-year retention of supporting records and schedules; Internal escalation runbook ensuring CISO and CEO sign-off

Questions

When does 23 NYCRR 500 apply here?
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
Which edition is held?
23 NYCRR Part 500, section level as held (our copy carries no version string)
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.