Compliance

NYCRR 500

The New York State Department of Financial Services (DFS) has been closely monitoring the growing threat that nation-states, organized groups, and independent criminals pose to information and financial systems. Increasingly, cybercriminals exploit technological vulnerabilities to reach sensitive electronic data.

23 NYCRR 500 is a regulatory standard governing the financial-services industry in New York. It requires each covered institution to maintain a cybersecurity program, designate a Chief Information Security Officer (CISO), and implement access controls, asset management, data governance, secure software-development practices, annual compliance certification, and more.

The regulation requires banks, insurance companies, and other DFS-regulated financial-services institutions to establish and maintain a cybersecurity program designed to protect consumers and ensure the safety and soundness of New York State’s financial-services industry.

Key elements

A compliant cybersecurity program must:

  • Adopt a written cybersecurity policy
  • Identify and assess internal and external cybersecurity risks to the security or integrity of stored data
  • Use defensive infrastructure, policies, and procedures to protect IT systems from unauthorized access or malicious acts
  • Detect cybersecurity events
  • Respond to detected events to mitigate negative effects
  • Recover from events and restore normal operations
  • Fulfill applicable regulatory reporting requirements

It also requires:

  • A designated Chief Information Security Officer
  • Cybersecurity training for employees
  • Management of third-party service-provider risk
  • Incident monitoring and reporting
  • Information security audits

The program must be able to generate alerts when cybersecurity events are detected. CYK helps DFS-regulated firms build, document, and maintain a program that meets these requirements.

Ask us about NYCRR 500 compliance