NYDFS Cybersecurity Rule: Requirements and Compliance
Key Takeaways
The NYDFS Cybersecurity Rule establishes mandatory cybersecurity requirements for NYDFS-regulated financial institutions.
Covered entities must maintain risk-based cybersecurity programs, policies, controls, and governance processes.
Certain cybersecurity incidents require notification to NYDFS within 72 hours, with additional ransomware reporting obligations.
Part 500 places significant emphasis on vendor oversight and third-party cybersecurity risk management.
Compliance often begins with assessing applicability, identifying gaps, strengthening controls, and testing response procedures.
The NYDFS Cybersecurity Rule is one of the most detailed cybersecurity regulations applicable to financial services companies in the United States. Codified as 23 NYCRR Part 500, the rule establishes minimum cybersecurity standards for organizations regulated by the New York State Department of Financial Services (NYDFS), including banks, money transmitters, virtual currency businesses, insurance companies, and other financial institutions.
The NYDFS Cybersecurity Rule has undergone several important changes since it was first introduced. Recent amendments expanded governance requirements, added new obligations for certain institutions, and increased regulatory expectations around incident reporting and cybersecurity oversight. For regulated financial services firms, cybersecurity has become a boardroom and compliance issue as much as a technology issue.
This article covers the scope of the rule, the organizations it applies to, key compliance requirements, reporting obligations, third-party risk management expectations, and practical steps firms can take when assessing their cybersecurity programs.
At InnReg, we help fintechs, money transmitters, banks, crypto companies, and other regulated financial institutions build and manage cybersecurity compliance programs.
What Is the NYDFS Cybersecurity Rule?
The NYDFS Cybersecurity Rule is a cybersecurity regulation issued by the New York State Department of Financial Services under 23 NYCRR Part 500. It establishes minimum cybersecurity requirements for financial institutions and other businesses regulated by NYDFS, requiring them to develop, implement, and maintain risk-based cybersecurity programs.
Unlike many cybersecurity frameworks that operate as voluntary guidance, Part 500 is a regulatory requirement. Covered entities must comply with specific obligations related to governance, risk assessments, access controls, incident response, third-party risk management, reporting, and cybersecurity oversight.
Why the Rule Was Created
NYDFS adopted the rule in response to growing cybersecurity threats facing the financial services sector. Financial institutions routinely store sensitive customer information, process financial transactions, and operate critical infrastructure, making them attractive targets for cybercriminals.
The regulation was designed to establish a baseline set of cybersecurity controls across the industries supervised by NYDFS. The goal is not to eliminate cyber risk, but to require firms to identify, assess, and manage cybersecurity risks through a structured program.
Since the rule's adoption in 2017, NYDFS has continued to update its requirements as cyber threats, technologies, and business models have evolved.
Which Institutions Are Covered
The rule applies to entities operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization issued by NYDFS.

The exact applicability depends on an organization's relationship with NYDFS and whether any exemptions or limited exemptions apply.
Why Fintechs Should Pay Attention, Even if They Are Not Directly Regulated
Many fintech companies assume the NYDFS Cybersecurity Rule only matters if they hold a New York license. In practice, the rule often influences cybersecurity expectations across the broader financial services ecosystem.
A fintech may not be directly covered by Part 500, but its customers or partners might be. Banks, money transmitters, and other regulated firms often look for cybersecurity controls that are consistent with NYDFS expectations when reviewing vendors and service providers.
In practical terms, that can mean questions about incident response, multi-factor authentication, penetration testing, risk assessments, vendor oversight, and board or management reporting.
Who Must Comply With the NYDFS Cybersecurity Rule?
The NYDFS Cybersecurity Rule applies to organizations that operate under a license, registration, charter, certificate, permit, accreditation, or similar authorization issued by the New York State Department of Financial Services. These organizations are referred to in the Regulation as "Covered Entities."
Banks
Part 500 applies to a wide range of banking institutions supervised by NYDFS, including state-chartered banks, trust companies, and certain foreign bank branches operating in New York.
Cybersecurity has become a significant supervisory focus for banking regulators over the past decade. As banking services become increasingly digital, institutions face growing risks from ransomware, business email compromise, credential theft, third-party breaches, and other cyber threats.
As a result, banks subject to the NYDFS Cybersecurity Rule must maintain a cybersecurity program that is appropriate for their risk profile and operations. Regulators generally look beyond technical controls and assess governance, risk management practices, vendor oversight, and incident response capabilities as part of the broader compliance framework.
Learn how InnReg helps banks navigate regulatory requirements →
Money Transmitters
Money transmitters licensed by NYDFS must also comply with the NYDFS Cybersecurity Rule. This category includes many payment companies, remittance providers, digital wallet operators, and other businesses that move money on behalf of customers.
Because money transmitters often process high transaction volumes and maintain sensitive customer information, cybersecurity remains an important area of regulatory focus. Firms are expected to evaluate cyber risks, implement appropriate controls, and maintain documented cybersecurity procedures.
Learn how InnReg helps money transmitters →
Virtual Currency Businesses
The rule also applies to much of New York's regulated crypto industry. Exchanges, custodians, wallet providers, and other firms operating under a BitLicense are generally covered.
For these businesses, cybersecurity is closely tied to core operations. If a trading system becomes unavailable or privileged access credentials are compromised, the impact may extend well beyond technology teams. Customer assets, transaction activity, and regulatory obligations can all be affected.
That reality is reflected in how NYDFS approaches supervision. Cybersecurity is treated as an enterprise risk issue, not simply an IT function.
Insurance Companies
The rule also covers insurance companies regulated by NYDFS. Insurers often maintain significant volumes of personal, financial, and health-related information, making cybersecurity risk management a key regulatory concern.
Part 500 requires insurers to adopt risk-based cybersecurity programs and implement controls appropriate to their operations, systems, and risk profile.
Mortgage-Related Businesses
The rule applies to various mortgage industry participants regulated by NYDFS, including mortgage bankers, mortgage brokers, mortgage servicers, and mortgage loan originators operating under New York licensing requirements.
These organizations routinely handle sensitive borrower information, financial records, and supporting documentation. As a result, cybersecurity controls and incident response capabilities remain important regulatory expectations.
—
Entity Type | Why Cybersecurity Matters |
|---|---|
Banks | Protect customer funds, financial data, and critical banking infrastructure. |
Money Transmitters | Process large transaction volumes and maintain sensitive customer information. |
Virtual Currency Businesses | Manage digital assets, wallets, trading platforms, and custody systems. |
Insurance Companies | Store significant volumes of personal, financial, and health-related information. |
Mortgage-Related Businesses | Handle borrower records, financial documents, and sensitive personal data. |
Other Licensed Financial Institutions
Part 500 extends beyond the categories above. Other NYDFS-regulated entities may also be covered, including:
Licensed lenders
Sales finance companies
Check cashers
Foreign bank branches
Certain trust companies
Other financial services businesses licensed by NYDFS
Because applicability is tied to NYDFS authorization status, firms should review their licensing structure carefully when determining whether the rule applies.
Exemptions and Limited Exemptions
Part 500 recognizes that not all regulated entities operate at the same scale. As a result, NYDFS has created a number of exemptions and limited exemptions for smaller organizations.
Companies should be careful not to assume that an exemption removes all obligations under the rule. In many cases, certain cybersecurity, reporting, and risk management requirements remain in place even when an exemption applies.
Organizations relying on an exemption should carefully review the applicable provisions of Part 500 to determine which obligations remain in place.
Key Requirements of the NYDFS Cybersecurity Rule
The NYDFS Cybersecurity Rule is built around a risk-based approach to cybersecurity. Rather than prescribing a single set of technical controls for every organization, Part 500 requires covered entities to develop cybersecurity programs that are appropriate for their size, complexity, operations, and risk profile.
The regulation addresses a broad range of cybersecurity and governance areas:
Cybersecurity Program Requirements
At the center of the NYDFS Cybersecurity Rule is the requirement to maintain a cybersecurity program designed to identify, assess, protect against, detect, respond to, and recover from cybersecurity risks and events.
Part 500 leaves room for different approaches. The cybersecurity program for a regional bank will not look identical to the program used by a cryptocurrency exchange or a money transmitter. What matters is whether the program addresses the risks associated with the firm's business, systems, and data.
A community bank faces different cybersecurity challenges than a crypto exchange. A money transmitter operates differently from either of them. Customer data, transaction flows, technology stacks, and third-party dependencies vary from one business model to another, and regulators take those differences into account.
A strong cybersecurity program is not limited to firewalls, endpoint protection, or other technical safeguards. It also includes the policies, procedures, governance structures, and operational processes that support day-to-day risk management.
The rule places cybersecurity within the broader governance framework of the organization. While information security teams may manage many of the day-to-day controls, oversight responsibilities frequently extend well beyond the technology department.
From a regulatory perspective, documentation and execution matter just as much as design. Firms should be prepared to show how risks are identified, what controls have been implemented, and how those controls are monitored over time.
Written Cybersecurity Policies
Part 500 requires covered entities to maintain written cybersecurity policies approved by a senior governing body or senior officer. These policies serve as the foundation of the organization's cybersecurity program and help establish how cybersecurity risks are managed across the business.
The rule identifies a number of areas that policies should address, where applicable to the organization. Examples include information security, access controls, business continuity and disaster recovery, systems and network security, vendor management, incident response, customer data privacy, and risk assessment processes.
Written policies are not intended to sit on a shelf after they are approved. As technology, business operations, and cybersecurity risks change, organizations should review and update their policies to reflect those developments. A policy written several years ago may not adequately address new systems, vendors, products, or threat scenarios.
For many firms, policy governance extends beyond the information security team. Compliance personnel, legal teams, risk managers, business leaders, and senior management may all contribute to policy development, review, and oversight depending on the organization's structure.
During examinations, regulators often review both the policies themselves and the processes supporting them. Firms should be prepared to demonstrate how policies are approved, communicated, maintained, and incorporated into day-to-day operations.
Risk Assessments
Risk assessments sit at the core of the NYDFS Cybersecurity Rule. Part 500 requires covered entities to maintain a documented risk assessment process that informs the design of their cybersecurity program.
Before deciding which cybersecurity controls to implement, organizations first need a clear picture of the risks they face. That analysis often considers the firm's systems, data, business activities, third-party relationships, and potential operational impacts if something goes wrong.
Risk assessments are not intended to be completed once and forgotten. Technology changes. New products are launched. Vendors are added. Employees gain access to different systems. Each of these developments can introduce new cybersecurity risks that may need to be evaluated.
For many organizations, risk assessments become the starting point for decisions involving access controls, monitoring, incident response planning, vendor oversight, cybersecurity investments, and policy updates. NYDFS expects cybersecurity controls to be informed by risk, not selected at random or adopted solely because another company uses them.
From an examination perspective, documentation matters. Regulators may review how risks were identified, how they were evaluated, what decisions were made as a result, and whether the assessment process is being updated as the organization changes over time.
Multi-Factor Authentication Requirements
Multi-factor authentication (MFA) is one of the core security controls Part 500 addresses. Covered entities are generally required to implement MFA for access to information systems, although alternative controls may be permitted in certain circumstances.
The requirement reflects a simple reality: passwords alone are often not enough. MFA helps reduce the risk of unauthorized access resulting from stolen or compromised credentials.
NYDFS pays close attention to access management during examinations. Firms should be able to explain where MFA has been implemented and document any decisions to use alternative controls.
Asset Inventory and Data Management
Asset inventory and data management form a basic part of cybersecurity risk management. Organizations should maintain an understanding of the systems they use, the information they collect, and the locations where that information is stored.
NYDFS expects firms to maintain visibility into both technology assets and sensitive data. This can help support access controls, incident response efforts, retention practices, and broader cybersecurity governance.
Access Privileges and Identity Management
Who has access to what? Regulators ask this question frequently because excessive access rights can increase the impact of a cybersecurity incident.
Part 500 expects firms to manage user access in a controlled manner and limit permissions to what employees need to perform their jobs. Access rights should also be reviewed periodically, particularly when employees change roles or leave the organization.
NYDFS may review how accounts are created, monitored, modified, and disabled, as well as how organizations manage privileged users with elevated system access.
Vulnerability Management and Penetration Testing
Cybersecurity controls can weaken over time. New systems are deployed, software changes are made, and previously unknown vulnerabilities are discovered. For that reason, Part 500 requires organizations to identify and address vulnerabilities within their technology environment.
Testing serves a practical purpose: finding weaknesses before someone else does. Vulnerability assessments and penetration tests can reveal outdated software, misconfigurations, access control issues, and other security gaps that may not be visible during day-to-day operations.
NYDFS expects organizations to assess their environments periodically and address issues identified through the testing process.
From an examination perspective, regulators may review testing results, remediation efforts, and documentation showing how identified vulnerabilities were prioritized and addressed.
Logging and Monitoring
Organizations cannot respond to suspicious activity if they don’t know it’s happening. For that reason, Part 500 requires covered entities to maintain controls that support detecting and investigating cybersecurity events.
Logging and monitoring help firms identify unusual activity, investigate security incidents, and understand what happened when a system is compromised. Depending on the organization, this may include monitoring user activity, system access, network traffic, security alerts, and other events across the technology environment.
From a regulatory perspective, visibility matters. NYDFS may review how security events are monitored, how logs are retained, and whether the organization can use that information to support investigations and incident response activities.
Encryption Requirements
Encryption plays an important role in protecting sensitive information from unauthorized access. Part 500 generally requires covered entities to implement encryption controls for nonpublic information, both in transit and at rest.
Not every environment looks the same, and the rule recognizes that. In situations where encryption may not be feasible, organizations may use alternative compensating controls if those controls are approved and supported by their risk assessment process.
From an examination perspective, regulators may review how sensitive information is protected, where encryption has been implemented, and how decisions regarding alternative safeguards have been documented.
Incident Response and Business Continuity
Cybersecurity incidents are not hypothetical events. For that reason, Part 500 requires covered entities to maintain written incident response plans outlining how cybersecurity events will be identified, escalated, investigated, and addressed.
Business continuity is closely connected to incident response. Organizations should understand how critical operations would continue during a disruption and how systems would be restored following a cybersecurity event.
Regulators may review incident response procedures, testing activities, recovery plans, and evidence that these processes are periodically updated.
NYDFS Cybersecurity Rule Reporting Obligations
The NYDFS Cybersecurity Rule includes several reporting and certification obligations. The requirements below address cybersecurity event notifications, ransomware payment reporting, and annual compliance certifications.

Cybersecurity Event Notifications
Part 500 requires covered entities to notify NYDFS when certain cybersecurity events occur. In many cases, notification must be made within 72 hours of determining that a reportable cybersecurity event has occurred.
When a cybersecurity incident occurs, one of the first questions is whether it triggers a reporting obligation. The answer depends on the details of the event and whether it falls within the categories NYDFS identified.
Seventy-two hours can pass quickly during a cybersecurity incident. Firms should understand who makes reporting decisions and how NYDFS will assess potential notification obligations when an event occurs.
Ransomware Payment Reporting
The NYDFS Cybersecurity Rule includes specific reporting requirements related to ransomware payments. Covered entities that make a ransomware payment may be required to notify NYDFS within 24 hours of making the payment.
The reporting obligation does not end there. Part 500 also requires a follow-up submission, generally within 30 days, describing the circumstances surrounding the payment, the reasons it was made, and the organization's due diligence and response efforts.
Given the short reporting timeframe, organizations should understand in advance how ransomware-related decisions will be escalated, documented, and evaluated from both an operational and regulatory perspective.
Annual Certification of Compliance
The NYDFS Cybersecurity Rule requires covered entities to submit an annual certification of compliance or, where applicable, an acknowledgment identifying areas of noncompliance. The filing is intended to provide NYDFS with visibility into an organization's compliance with Part 500.
The certification process involves more than completing a form. Organizations should have sufficient documentation and supporting evidence to evaluate whether applicable requirements have been implemented and maintained.
Senior officers and governing bodies often play an important role in the certification process. As a result, many firms review their cybersecurity programs, controls, policies, and compliance status before making annual submissions to NYDFS.
NYDFS Cybersecurity Rule and Third-Party Risk Management
Third-party vendors play a significant role in many financial services businesses. As a result, the NYDFS Cybersecurity Rule includes specific expectations around vendor oversight and third-party cybersecurity risk management.
Vendor Security Requirements
Third-party vendors can create cybersecurity risks that are difficult to detect from inside the organization. A software provider, cloud platform, managed service provider, or other vendor may have access to sensitive data, critical systems, or important business functions.
For that reason, Part 500 requires covered entities to maintain policies and procedures designed to assess and manage third-party cybersecurity risks. This often includes due diligence before onboarding a vendor, contractual cybersecurity requirements, and ongoing monitoring of vendor relationships.
From a regulatory perspective, vendor oversight is not a one-time exercise. NYDFS may review how vendors are evaluated, what cybersecurity expectations are established, and how organizations monitor vendor risks over time.
Learn how InnReg helps fintechs develop vendor risk management programs →
Cloud Providers and Fintech Vendors
Many fintech companies rely on cloud providers, API integrations, banking partners, software vendors, and other third parties to deliver products and services. While these relationships can support growth and innovation, they can also introduce additional cybersecurity risks.
A vendor's cybersecurity issue can quickly become your cybersecurity issue. Service disruptions, data breaches, misconfigurations, and access management failures can affect customers, operations, and regulatory obligations even when the incident originates outside the organization.
For that reason, organizations should understand where critical dependencies exist and how those risks are managed. NYDFS expects firms to maintain oversight of important third-party relationships rather than treating cybersecurity as solely the vendor's responsibility.
Based on InnReg’s hands-on experience with 100+ fintechs, Regly’s vendor management module helps firms track and assess vendor relationships →
NYDFS Cybersecurity Rule for Crypto and Fintech Companies
Fintech and digital asset companies often face cybersecurity risks that differ from those of traditional financial institutions. The sections below examine how the NYDFS Cybersecurity Rule applies to several common fintech and crypto business models.
Virtual Currency Businesses and BitLicense Holders
Virtual currency businesses licensed by NYDFS are generally subject to the same core cybersecurity requirements found throughout Part 500. However, the operational realities of the crypto industry can create additional cybersecurity challenges that regulators expect firms to address.
For many digital asset firms, cybersecurity is closely tied to core business operations. A security issue affecting a wallet environment, custody platform, or trading system can quickly become an operational and regulatory issue as well.
NYDFS has consistently treated cybersecurity as a major area of focus within the virtual currency sector. Organizations should understand how cyber risks are identified, escalated, and managed across the business, not just within the technology team.
Embedded Finance and Banking-as-a-Service Risks
Embedded finance and Banking-as-a-Service (BaaS) models often involve multiple parties operating within the same product ecosystem. A fintech may rely on a sponsor bank, middleware provider, cloud infrastructure vendor, payment processor, and other service providers to deliver customer-facing services.
Learn more about Banking-as-a-Service →
In many embedded finance models, a single customer transaction may involve several different organizations working behind the scenes. Each connection point introduces another area that may require security oversight and monitoring.
As a result, cybersecurity responsibilities are not always confined to one company. Organizations should understand where third parties fit into their technology stack and how those relationships affect operational and cybersecurity risk.
AI, Automation, and Emerging Technology Risks
The challenge with emerging technology is not always the technology itself. It is how quickly it becomes part of day-to-day operations.
A business may begin using AI tools for customer support, compliance reviews, software development, or internal productivity. Over time, those tools can gain access to large volumes of data and become integrated into critical workflows. That reality creates cybersecurity questions that firms should be prepared to address.
Learn more about AI compliance →
See also:
Practical Steps for Fintech Firms
Complying with the NYDFS Cybersecurity Rule often requires more than implementing technical controls. Many organizations begin by evaluating existing practices, identifying gaps, and prioritizing areas that require additional attention.

1. Identify Applicability
The first step is determining whether the NYDFS Cybersecurity Rule applies to the organization. Applicability often depends on licensing status, regulatory oversight, and whether the company qualifies for any exemptions or limited exemptions under Part 500.
2. Perform a Gap Assessment
Before investing time and resources into new controls, it helps to identify what already exists. Many organizations discover they have addressed portions of Part 500 and can focus their efforts on a smaller number of remaining gaps.
3. Update Cybersecurity Governance
A cybersecurity program involves more than the information security team. Senior management, compliance personnel, operational leaders, and other stakeholders often play a role in oversight and risk management activities.
4. Strengthen Technical Controls
Technical controls tend to accumulate over time. The more difficult question is whether they continue to address the risks the organization faces today. Reviewing existing safeguards can help identify gaps, outdated practices, and areas requiring additional attention.
5. Improve Vendor Oversight
A fintech may outsource infrastructure, software development, payments, cloud hosting, or customer support. The responsibility for managing cybersecurity risk, however, does not disappear when a function is outsourced.
Learn how Regly helps fintechs track vendor relationships →
6. Build Reporting Workflows
Reporting deadlines can arrive quickly during a cybersecurity incident. Organizations should know who is responsible for evaluating notification obligations and how potential reporting events are escalated internally.
7. Test Incident Response Procedures
Cybersecurity incidents rarely unfold exactly as expected. Testing response procedures can help teams understand their roles, identify weaknesses in existing processes, and improve coordination before an incident occurs.

Need help with fintech compliance?
Fill out the form below and our experts will get back to you.
What Examiners Typically Review
Cybersecurity examinations typically focus on more than written policies. Regulators often evaluate whether cybersecurity controls are operating in practice and whether the organization can demonstrate compliance with applicable requirements:
Policies and procedures: Most examinations begin with a review of core cybersecurity documentation. This may include policies, risk assessments, vendor oversight records, incident response plans, and other materials supporting the cybersecurity program.
Technical evidence: Regulators typically want to see more than policies and procedures. Evidence such as penetration testing reports, vulnerability assessments, access reviews, and remediation records often becomes part of the examination process.
Board reporting: Part 500 places significant emphasis on governance and oversight. Examiners may review how cybersecurity matters are communicated to senior management and governing bodies, including reporting processes, risk discussions, and decision-making records.
Incident documentation: When cybersecurity incidents occur, regulators often review how the event was identified, investigated, escalated, documented, and resolved. They may also evaluate whether applicable reporting obligations were satisfied and whether lessons learned were incorporated into the organization's cybersecurity program.
—
The NYDFS Cybersecurity Rule is not simply a cybersecurity regulation. It is a governance, risk management, and operational framework that affects how regulated financial institutions identify, manage, and respond to cyber risks.
While the specific requirements will vary depending on the organization, most firms benefit from regularly reviewing their cybersecurity controls, vendor oversight practices, incident response capabilities, and reporting procedures. Regulatory expectations continue to evolve, and cybersecurity programs should be reviewed with the same mindset.
For organizations operating under NYDFS supervision, a clear understanding of Part 500 can help support both cybersecurity readiness and regulatory compliance efforts.

Kushal Abeywickrama is the Chief Operating Officer at InnReg with over 10 years of experience in broker-dealer compliance, supervision, and regulatory operations across FINRA-regulated firms. He holds Series 7, 24, 4, 63, and 57 FINRA licenses and has previously held roles at HSBC and BlackSwan Technologies.
How Can InnReg Help?
InnReg is a global regulatory compliance and operations consulting team serving financial services companies since 2013.
We are especially effective at launching and scaling fintechs with innovative compliance strategies and delivering cost-effective managed services, assisted by proprietary regtech solutions.
If you need help with compliance, reach out to our regulatory experts today:
Related Articles















