Parameter

What is NYDFS Part 500?

NYDFS Cybersecurity Regulation (23 NYCRR 500)

What 23 NYCRR 500 requires of New York financial services firms, including annual penetration testing, scanning and 72-hour notification.

01Introduction

Banks, insurers and other firms licensed by the New York Department of Financial Services operate under one of the most prescriptive cybersecurity rules in the US, and it specifically requires penetration testing.

02What is NYDFS Part 500?

23 NYCRR Part 500 is the New York State Department of Financial Services (NYDFS) Cybersecurity Regulation. It applies to covered entities licensed under New York banking, insurance or financial services law, with a second amendment (November 2023) that phased in stricter requirements through 2025.

Section 500.5 requires penetration testing by a qualified party at least annually, from inside and outside the network, plus automated vulnerability scanning and manual review. Firms must also appoint a CISO, notify NYDFS of qualifying incidents within 72 hours and certify compliance every year by April 15.

03How NYDFS Part 500 works

Requirements scale with firm size; larger Class A companies have extra obligations.

  1. 1.

    Program and policy

    Board-approved cybersecurity program and policies based on a risk assessment.

  2. 2.

    Technical controls

    MFA, asset inventory, access privilege limits, encryption and logging.

  3. 3.

    Testing

    Annual penetration testing and continuous vulnerability management.

  4. 4.

    Report and certify

    Report incidents within 72 hours and file an annual certification of compliance or acknowledgment of noncompliance.

04Threats and risks

NYDFS enforcement actions have clustered around a few failures.

  • Missing MFA

    Remote access and privileged accounts without multi-factor authentication.

  • Stale testing

    Pentests that are late, narrow or not acted on.

  • False certification

    Certifying compliance without the evidence behind it, which has led to multimillion-dollar penalties.

  • Slow notification

    Missing the 72-hour reporting window after an incident.

05How Parameter helps

Parameter turns the annual pentest requirement into a continuous record you can certify against.

  • Inside and outside

    The pentesting agents test applications and APIs, and EASM covers the external perimeter.

  • Continuous scanning

    Managed vulnerability scanning supports the scanning requirement.

  • Evidence trail

    Dated findings, fixes and retests support the April 15 certification.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your NYDFS Part 500 program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.