NYDFS Cybersecurity Regulation
The NYDFS Cybersecurity Regulation is a binding rule issued by the New York State Department of Financial Services that requires financial services companies it oversees to protect customer information and their information technology systems from cyber threats. It generally requires covered entities to maintain a cybersecurity program, adopt a written security policy, and have an incident response plan that includes notifying regulators of certain breaches. Because it is law rather than a voluntary standard, it applies specifically to entities regulated by the Department in New York and carries legal force.
Codified at Title 23 NYCRR Part 500, the NYDFS Cybersecurity Regulation is a principles-based regulatory framework promulgated by the New York State Department of Financial Services to promote the protection of customer information and the information technology systems of regulated entities. It imposes obligations on 'Covered Entities' — persons operating under a license, registration, charter, or similar authorization under New York banking, insurance, or financial services law — to establish and maintain a documented cybersecurity program, adopt a written cybersecurity policy, and implement an incident response plan with breach notification procedures to the Department. As a jurisdiction-specific legal instrument, its reach is defined by DFS regulatory authority in New York rather than by voluntary adoption; it should not be conflated with voluntary standards such as ISO/IEC 27001 or the NIST Cybersecurity Framework, though covered entities may draw on such frameworks to support compliance. The regulation has been amended over time (including a Second Amendment), so specific requirements, effective dates, thresholds, and any exemptions should be verified against the current official text published by the NYDFS. This entry is informational and does not address the fact-specific application of these requirements to any particular organization.
Why it matters
The NYDFS Cybersecurity Regulation is significant because it is binding law, not a voluntary standard, and it targets a concentrated and systemically important sector: the banks, insurers, and financial services companies operating under New York regulatory authority. New York's status as a major financial center means that a rule issued by the Department of Financial Services can reach a wide range of institutions, and non-compliance carries legal consequences rather than merely the loss of a certification or contractual benefit. For compliance officers and legal counsel, this distinction matters: obligations under Part 500 are enforceable by the Department, whereas alignment with frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework remains voluntary unless separately incorporated by law or contract.
Who it's relevant to
Inside NYDFS Cybersecurity Regulation
Common questions
Answers to the questions practitioners most commonly ask about NYDFS Cybersecurity Regulation.

