Home
/
Learning Center
/
The 6 Pillars of the NYDFS Cybersecurity Regulation

The 6 Pillars of the NYDFS Cybersecurity Regulation

By
Roni Saban
The 6 Pillars of the NYDFS Cybersecurity Regulation
Table of Contents

What is the NYDFS Cybersecurity Regulation?

The NYDFS Cybersecurity Regulation (23 NYCRR Part 500) is a New York rule that requires DFS-covered financial services entities to maintain risk-based cybersecurity programs, controls, and incident reporting processes to protect sensitive systems and nonpublic information.

We will discuss the six core requirements:

  1. Cybersecurity governance and accountability
  2. Risk assessments and vulnerability management
  3. Third-party service provider security
  4. Access controls and identity security
  5. Logging, monitoring, and threat detection
  6. Incident response and operational resilience

Most organizations can prove they completed a vendor review, but far fewer can prove they understand their actual third-party exposure. That gap matters more under the NYDFS Cybersecurity Regulation, especially after the final tranche of the Second Amendment took effect on November 1, 2025. 

78% of CEOs at highly cyber-resilient organizations say third-party and supply chain vulnerabilities are the biggest obstacle to improving resilience. Yet many organizations still rely on point-in-time oversight, even as vendors become more deeply embedded in critical systems. 

The amended regulation introduced more stringent requirements for vulnerability management, asset visibility, and incident reporting, making it harder to rely solely on annual assessments and vendor attestations. But who does the NYDFS Cybersecurity Regulation apply to, and what does compliance now require?

What Is the NYDFS Cybersecurity Regulation, and What Does It Cover?

The NYDFS Cybersecurity Regulation, formally known as 23 NYCRR Part 500, establishes mandatory cybersecurity requirements for covered entities regulated by the New York State Department of Financial Services.

New York State introduced the regulation in 2017 to strengthen cybersecurity governance, incident response, third-party security, and the protection of nonpublic information across the financial sector. Unlike frameworks focused primarily on documentation and policy management, NYDFS emphasizes risk-based cybersecurity controls, operational resilience, and ongoing risk reduction.

The amended regulation also moved compliance expectations beyond annual reviews and point-in-time attestations. Expanded requirements around vulnerability management, asset inventories, incident reporting, and third-party oversight increasingly require organizations to maintain continuous, evidence-based visibility into cyber exposure. 

The Second Amendment to Part 500 was adopted in 2023 and implemented in phases, with the final compliance requirements taking effect on November 1, 2025. 

The amendments significantly reinforced that shift by: 

  • Expanding governance obligations
  • Increasing accountability for CISOs and senior leadership
  • Strengthening vulnerability management expectations
  • Introducing stricter third-party cybersecurity oversight requirements
  • Tightening incident reporting obligations

Organizations that fail to comply may face financial penalties, operational restrictions, reputational damage, and heightened regulatory scrutiny. In fact, NYDFS has already imposed million- and multimillion-dollar penalties against organizations for failures such as weak access controls and insufficient oversight of operational cyber risk. Some of the companies that have been penalized include First American, EyeMed, PayPal, GEICO, and Travelers.

NYDFS Cybersecurity Regulation Key Milestones

Who Does the NYDFS Cybersecurity Regulation Apply To?

The NYDFS Cybersecurity Regulation applies to covered entities operating under the oversight of the New York State Department of Financial Services. In practice, that commonly includes organizations such as:

  • Banks
  • Insurance companies
  • Mortgage lenders and servicers
  • Money transmitters
  • Fintechs
  • Other DFS-regulated entities operating in New York

The 6 Pillars of the NYDFS Cybersecurity Regulation

1. Cybersecurity Governance and Accountability

NYDFS requires covered entities to maintain a formal cybersecurity program with documented policies, executive oversight, employee cybersecurity training, and a designated CISO or equivalent security leader. The amended Part 500 requirements increased accountability for senior leadership and board-level oversight, requiring greater involvement in cybersecurity governance, reporting, and risk management. 

Regulators increasingly expect leadership teams to demonstrate that cybersecurity governance actively informs operational decision-making. Security programs now need clear escalation paths, defined ownership over cyber risk, and consistent executive visibility into material security issues.

2. Risk Assessments and Vulnerability Management

NYDFS requires covered entities to maintain a written risk assessment that informs the design of their cybersecurity programs. Under Part 500, organizations must identify internal and external cybersecurity risks, evaluate the adequacy of existing controls, and define how they will mitigate or accept identified risks.

The regulation also requires annual penetration testing and ongoing vulnerability management processes to identify publicly known vulnerabilities, validate the effectiveness of existing safeguards, and support timely remediation. 

Organizations need documented processes to identify critical systems, maintain visibility into assets, prioritize vulnerabilities based on risk, respond to newly discovered threats, remediate control gaps, and reassess cyber risk when changes to business operations, technology, or threat conditions materially affect the organization. 

Organizations should reassess exposure whenever they detect meaningful operational change, including:

  • New integrations introduced during product development
  • AI agents and tooling connected to internal knowledge bases
  • Changes in regulated information exposure
  • Scope drift beyond the original intake
  • Newly disclosed vulnerabilities or breaches
  • Shadow IT or unsanctioned vendor adoption

Those requirements become significantly more difficult in large, interconnected environments, especially when organizations rely on vendor-submitted artifacts without independently validating what those artifacts actually demonstrate.  

Changes that should trigger risk reassessements

3. Third-Party Service Provider Security

Organizations must maintain written third-party cybersecurity policies and implement processes for vendor due diligence, supplier risk assessment, access management, and protection of nonpublic information shared with external service providers.

The regulation also requires organizations to evaluate the adequacy of vendor cybersecurity practices based on the level of risk presented by the relationship. That includes assessing access privileges, cybersecurity controls, use of multi-factor authentication, and the sensitivity of systems or information accessible to the vendor.

Those requirements become significantly more challenging across large SaaS ecosystems and interconnected third-party environments, particularly as the amended regulation places greater emphasis on ongoing third-party diligence and on organizations' ability to understand the actual exposure created by vendor relationships. 

The level of risk a vendor creates depends on the relationship itself. A vendor with limited access may present minimal exposure, while one embedded in critical systems may introduce significant organizational risk. 

Mature TPRM programs now prioritize:

  • Targeted follow-up requests tied to identified gaps
  • Validation of vendor artifacts against observable signals
  • Visibility into actual organizational usage
  • Detection of scope drift over time
  • Identification of unsanctioned third-party adoption
  • Continuous Risk Signal Collection across external intelligence and internal telemetry

To address that gap, a new generation of TPRM platforms is emerging that focuses less on collecting information and more on understanding exposure and translating findings into meaningful risk insights.

Lema transforms TPRM teams from compliance auditors into Risk Engineers. Its platform helps organizations validate vendor claims, understand the blast radius of third-party relationships, and connect vendor findings to actual organizational exposure. 

By combining Forensic AI Assessment, OSINT Recon, and Blast Radius Mapping, Lema surfaces risk insights that go beyond what traditional assessments and point-in-time reviews typically reveal. Then, Agentic Risk Engineering brings together vendor artifacts, external intelligence, and internal usage context into coherent risk insights with clear mitigation guidance that teams can quickly understand and act on.

third-party permission example

4. Access Controls and Identity Security

NYDFS requires organizations to implement:

  • Multi-factor authentication (MFA)
  • Least-privilege access controls
  • Secure authentication and password policies
  • Identity and access management processes
  • Restrictions on unauthorized access
  • Periodic review of user access privileges

The regulation places significant emphasis on controlling access to sensitive systems and nonpublic information. Organizations must maintain clear processes for granting, modifying, reviewing, and removing access across employees, contractors, third-party vendors, applications, and privileged accounts.

The amended Part 500 requirements also strengthened MFA expectations, particularly for remote access, privileged accounts, and access to critical systems. Where MFA is not feasible, covered entities must implement reasonably equivalent or more secure compensating controls that are approved by the CISO (or equivalent) and reviewed annually. 

5. Logging, Monitoring, and Threat Detection

NYDFS requires organizations to maintain audit trails and logging capabilities to ensure sufficient visibility to support investigations and operational oversight. The regulation requires organizations to identify unauthorized access, suspicious activity, and potential cybersecurity events affecting sensitive systems and nonpublic information. Security teams, therefore, need reliable processes for collecting logs and reviewing anomalies. They also need IT operations analytics to identify unusual operational behavior and access changes.

Many organizations already collect enormous volumes of logs and security telemetry. The challenge is transforming that information into clear, defensible evidence that demonstrates effective monitoring, investigation, and incident response. Organizations should be able to explain: 

  • How risk decisions were made
  • What evidence supported those decisions
  • Which controls were validated
  • How third-party exposure was assessed
  • What mitigation actions occurred
  • Whether identified risks materially affected operations

Regulators expect organizations not only to detect and respond to cyber risk, but also to demonstrate how those decisions were made and supported over time. Lema helps organizations generate One-Click Evidence of Due Diligence that connects vendor artifacts, external intelligence, operational context, and risk decisions into audit-ready reporting. Instead of relying on fragmented spreadsheets and disconnected workflows, security teams can provide regulators, auditors, and executives with clear evidence of cybersecurity oversight grounded in actual organizational exposure.

NYDGS Organizational Requirments

6. Incident Response and Operational Resilience

NYDFS requires covered entities to maintain written incident response plans that define how the organization manages cybersecurity incidents once they occur. Part 500 requires organizations to:

  • Establish escalation procedures
  • Assign response responsibilities
  • Coordinate internal and external communications
  • Maintain recovery processes for affected systems and operations.

The regulation also imposes strict reporting obligations. Covered entities must notify NYDFS within 72 hours after determining that a reportable cybersecurity incident has occurred. 

Under the amended regulation, reporting obligations can also be triggered by qualifying cybersecurity events affecting third-party service providers. As a result, organizations must understand not only whether a vendor experienced an incident, but also whether that incident creates material exposure within their own environment. 

This significantly raises the importance of third-party diligence under Section 500.11. Organizations need more than completed questionnaires and vendor attestations. They need evidence-based visibility into vendor controls, operational dependencies, access levels, and blast radius to determine whether a third-party incident creates reporting obligations or meaningful business impact. 

Organizations that make an extortion payment in connection with a cybersecurity event must also notify NYDFS within 24 hours and submit a written explanation within 30 days describing why the payment was necessary and what alternatives they considered. 

To comply with this part of the regulation, organizations must not only maintain preventative security controls but also demonstrate that they can contain incidents quickly, restore business operations safely, document response actions appropriately, and coordinate regulatory reporting under tight timelines.

NYDFS Is Pushing Organizations Beyond Point-in-Time Assessments

The amended NYDFS regulation reflects a broader shift toward continuous, evidence-based cybersecurity oversight. Requirements around vulnerability management, asset inventories, incident reporting, and third-party security increasingly require organizations to maintain visibility into actual exposure rather than relying solely on annual assessments, questionnaires, and attestations. 

Lema helps organizations move beyond point-in-time vendor oversight toward evidence-driven operational visibility grounded in actual business impact. Its platform combines Forensic AI Assessment, OSINT Recon, Blast Radius Mapping, Continuous Risk Signal Collection, and Agentic Risk Engineering to surface risk insights that traditional TPRM workflows frequently miss. 

Instead of simply collecting more artifacts, the platform helps Risk Engineers verify vendor-submitted materials, understand operational dependency, surface meaningful risk insights, identify changing exposure, and prevent the operational risks that traditional TPRM workflows frequently fail to surface.

Book a demo to see the risks that questionnaires and vendor attestations don’t surface.

FAQs

What Is the NYDFS Cybersecurity Regulation?

The NYDFS Cybersecurity Regulation, formally known as 23 NYCRR Part 500, is a cybersecurity framework introduced by the New York Department of Financial Services for financial institutions and regulated entities operating in New York. The regulation requires organizations to maintain risk-based cybersecurity programs, implement security controls, manage third-party risk, report cybersecurity incidents, and maintain governance processes designed to protect sensitive systems and nonpublic information.

Who Needs to Comply With NYDFS?

The regulation applies to entities regulated by the New York Department of Financial Services, including banks, insurance companies, mortgage lenders, financial services firms, and other licensed financial institutions operating in New York. Some smaller organizations may qualify for limited exemptions, but most covered entities must comply with the core cybersecurity, governance, incident response, and third-party risk requirements outlined in Part 500.

What Are NYDFS Requirements?

NYDFS requires organizations to maintain a formal cybersecurity program supported by written policies, risk assessments, vulnerability management, multi-factor authentication, audit trails, incident response planning, third-party cybersecurity controls, and executive oversight. Covered entities must also conduct penetration testing, monitor cybersecurity activity, report qualifying cybersecurity events within required timelines, and maintain evidence demonstrating compliance with Part 500.

Does NYDFS Require Third-Party Cybersecurity Oversight?

Yes. NYDFS Part 500 requires covered entities to maintain written policies and procedures for assessing and managing the cybersecurity risks posed by third-party service providers. In practice, that means more than collecting questionnaires or annual attestations. Organizations need risk-based diligence that reflects the vendor’s access, the sensitivity of the data involved, and the potential business impact if the relationship creates exposure or an incident. 

About the Author
Roni Saban
VP Marketing
Roni leads marketing at Lema AI, the agentic TPRM platform replacing checkbox compliance with real Risk Engineering. She's building the category from the ground up, making the case that third-party risk shouldn't be a questionnaire exercise, but an active, evidence-backed discipline that surfaces the risks checklists never will.