Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 November 2023.
A vulnerability and incident reporting rule binding private bodies.
As of 20 September 2026.
What it requires
- This duty reaches your organization only if it is a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law, or the Financial Services Law, regardless of whether it is also regulated by another agency. Declare provides_financial_services where that status holds; the limited exemptions in 500.19 do not reach this section, so a small or otherwise exempt covered entity owes the Superintendent-notice duty in full.
- Notify the Superintendent electronically, in the form set forth on the Department's website, as promptly as possible but no later than 72 hours after you determine that a Cybersecurity Incident has occurred at your organization, an affiliate, or a third-party service provider: an event that requires notice to a government or supervisory body, that has a reasonable likelihood of materially harming a material part of your normal operations, or that results in the deployment of ransomware within a material part of your information systems.
- Promptly provide the Superintendent any information requested about a reported incident, and continue updating the Superintendent with material changes or new information previously unavailable; the regulation states no separate numbered clock for either duty.
- Where you make an extortion payment in connection with a cybersecurity event, notify the Superintendent of the payment within 24 hours of making it, and within 30 days of the payment provide a written description of why the payment was necessary, the alternatives you considered, and the diligence you performed, including under Office of Foreign Assets Control rules.
- By April 15 of each year, submit to the Superintendent electronically either a written certification that you materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections you did not materially comply with and a remediation timeline, each signed by your highest-ranking executive and your Chief Information Security Officer.
If you get it wrong
Criminal exposureNo
Who enforces it
Enforcement body
The Superintendent of Financial Services.
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 500.17 of 23 NYCRR Part 500 requires a Covered Entity to notify the Superintendent of Financial Services electronically as promptly as possible but no later than 72 hours after determining that a Cybersecurity Incident has occurred at the covered entity, its affiliates, or a third-party service provider.
A Cybersecurity Incident is a Cybersecurity Event, a broader term covering any attempt to gain unauthorized access to or misuse an information system, that also either requires notice to a government or supervisory body, carries a reasonable likelihood of materially harming a material part of normal operations, or results in the deployment of ransomware within a material part of the covered entity's information systems.
Each covered entity must promptly provide the Superintendent with any information the Superintendent requests about a reported incident and must continue updating the Superintendent with material changes or new information, with no separate numbered clock on either duty.
Where a covered entity makes an extortion payment in connection with a cybersecurity event, it must notify the Superintendent of the payment within 24 hours of making it and, within 30 days of the payment, provide a written description of why the payment was necessary and what alternatives and compliance diligence it performed.
By April 15 each year, a covered entity must submit either a written certification that it materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections it did not materially comply with and a remediation timeline, signed by its highest-ranking executive and its Chief Information Security Officer.
The limited exemptions in 23 NYCRR 500.19(a), (c) and (d), covering a small covered entity and an entity without its own information systems or nonpublic information, each work by naming the sections they relieve, and none of them names section 500.17, so an entity holding one of those still owes the Superintendent-notice duty in full.
Subsections 500.19(b), (e) and (g) work the other way, exempting their named classes from the requirements of the whole Part, which carries section 500.17 with it.
Section 500.11 requires a covered entity to adopt its own policies and contractual protections for a third-party service provider, including contractual notice to the covered entity of a cybersecurity event, so Part 500 reaches a third-party service provider only through the covered entity's own duties and never binds the provider directly unless the provider independently qualifies as its own covered entity.
When LexLint raises it
provides_financial_services
Read the law
Current text of the official compilation of codes
rules and regulations, New York Codes, Rules and Regulations Title 23, part 500, as mirrored by Cornell Law School's Legal Information Institute the Department of Financial Services' own PDF text was not accessible for this citation.
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.