01Introduction
Banks, insurers and other firms licensed by the New York Department of Financial Services operate under one of the most prescriptive cybersecurity rules in the US, and it specifically requires penetration testing.
02What is NYDFS Part 500?
23 NYCRR Part 500 is the New York State Department of Financial Services (NYDFS) Cybersecurity Regulation. It applies to covered entities licensed under New York banking, insurance or financial services law, with a second amendment (November 2023) that phased in stricter requirements through 2025.
Section 500.5 requires penetration testing by a qualified party at least annually, from inside and outside the network, plus automated vulnerability scanning and manual review. Firms must also appoint a CISO, notify NYDFS of qualifying incidents within 72 hours and certify compliance every year by April 15.
03How NYDFS Part 500 works
Requirements scale with firm size; larger Class A companies have extra obligations.
- 1.
Program and policy
Board-approved cybersecurity program and policies based on a risk assessment.
- 2.
Technical controls
MFA, asset inventory, access privilege limits, encryption and logging.
- 3.
Testing
Annual penetration testing and continuous vulnerability management.
- 4.
Report and certify
Report incidents within 72 hours and file an annual certification of compliance or acknowledgment of noncompliance.
04Threats and risks
NYDFS enforcement actions have clustered around a few failures.
Missing MFA
Remote access and privileged accounts without multi-factor authentication.
Stale testing
Pentests that are late, narrow or not acted on.
False certification
Certifying compliance without the evidence behind it, which has led to multimillion-dollar penalties.
Slow notification
Missing the 72-hour reporting window after an incident.
05How Parameter helps
Parameter turns the annual pentest requirement into a continuous record you can certify against.
Inside and outside
The pentesting agents test applications and APIs, and EASM covers the external perimeter.
Continuous scanning
Managed vulnerability scanning supports the scanning requirement.
Evidence trail
Dated findings, fixes and retests support the April 15 certification.

