If you handle New York residents' financial data, the New York Department of Financial Services Cybersecurity Regulation, 23 NYCRR 500, applies to you. It is one of the most technically specific cybersecurity regulations in the United States, and it does not issue warnings before it enforces.
Recent penalties make the stakes concrete. In 2024, the Department of Financial Services fined Gemini Trust Company 37 million dollars for failing to assess and oversee a third-party lending partner. In 2025, Block, Incorporated was fined 40 million dollars for board-level policy failures and gaps in business continuity planning. These are not edge cases. They are the current baseline for what non-compliance costs.
Unlike frameworks organizations often treat as privacy compliance exercises, 23 NYCRR 500 mandates specific technical controls with no ambiguity about what counts as satisfying them.
Section 500.5 requires annual penetration testing and biannual vulnerability assessments. Section 500.9 requires a documented, periodically updated risk assessment that drives the rest of the cybersecurity program. Section 500.12 requires multi-factor authentication, or an equally effective risk-based alternative, for anyone accessing internal networks from outside them. Section 500.14 requires both ongoing monitoring of authorized user activity and regular cybersecurity awareness training. Section 500.16 requires a written incident response plan with defined roles, escalation paths, and communication protocols.
The Department of Financial Services has stated plainly that multi-factor authentication deficiencies are the most exploited gap behind the breaches it investigates. A 2023 amendment, finalized on a phased rollout through November 2025, expanded the multi-factor authentication requirement to cover any individual accessing any information system, not just external network access, and added a formal requirement to maintain a documented, regularly updated inventory of information system assets.
A few misconceptions come up constantly.
“We're not a bank, so this doesn't apply to us.” Any entity operating under a license, registration, charter, or similar authorization under New York banking, insurance, or financial services law is a covered entity. That includes fintechs, payment processors, insurtech companies, lending platforms, cryptocurrency exchanges, and investment advisors.
“We don't have New York employees, so we're exempt.” Physical location of staff is irrelevant. If the entity holds a qualifying New York authorization and serves New York customers, it is in scope regardless of where it is headquartered.
“We're small, so we qualify for the exemption.” The limited exemption under Section 500.19 applies to covered entities meeting any one of three conditions: fewer than 10 employees, less than 5 million dollars in gross annual New York revenue, or less than 10 million dollars in year-end total assets. Meeting any single threshold qualifies for the exemption, not all three simultaneously, which makes more organizations eligible than most assume. It is worth confirming which exemption applies to a given entity directly against current Department of Financial Services guidance, since the 2023 amendment introduced a separate, higher-threshold exemption specific to the expanded multi-factor authentication requirement.
The Department of Financial Services does not send warning letters. It issues consent orders, which are public settlements requiring both remediation and fines, and in severe cases it can suspend an entity's ability to conduct business in New York. Enforcement has been climbing since 2022, with a steady pace of multi-million dollar consent orders. The Gemini and Block cases above are the clearest recent evidence that the exposure is real, not theoretical, and that the size of an organization does not determine the size of the fine.
Organizations discovering their exposure late tend to follow a similar sequence. The first two weeks go to building a complete asset inventory and mapping current controls against the specific sections that apply, identifying gaps before anything else. The next two weeks focus on the highest-impact, lowest-effort fixes: implementing multi-factor authentication everywhere it is missing, documenting existing penetration test and vulnerability scan results, and drafting an incident response plan.
The following two weeks formalize what got fixed quickly: deploying risk-based authentication where multi-factor authentication alone is not practical, writing a formal cybersecurity policy, and designating a Chief Information Security Officer if one is not already named. The final stretch is certification and audit preparation: a board-level cybersecurity review, the annual certification submission due April 15 covering the prior calendar year, and getting audit-ready on the assumption that a Department of Financial Services review could arrive within six months.
For managed service providers and managed security service providers serving fintech, lending, payment processing, or insurtech clients, NYDFS compliance work is not a one-time engagement. It renews every year, because the certification does. Asset inventory, gap analysis and remediation, and annual certification support together represent a substantial annual client engagement, and the certification requirement means it comes back every cycle rather than ending after the first year.
RiskAct™ auto-maps regulatory obligations across more than 40 frameworks, including NYDFS 23 NYCRR 500, and translates identified risks into Regulatory Impact Insights so compliance teams can see where exposure sits against the requirements that actually apply to them.
Sources
About NetraScale™: RiskAct™ auto-maps regulatory obligations across more than 40 frameworks, including NYDFS 23 NYCRR 500, and translates identified risks into Regulatory Impact Insights so compliance teams can see where exposure sits against the requirements that actually apply to them.