New York policy
NYDFS 23 NYCRR Part 500 (Cybersecurity Regulation, Second Amendment)
Regulation · amended Nov 2023; phased through 2025
- Jurisdiction
- New York State
- Applies to
- DFS-covered financial institutions, insurers, and licensees
- Effective
- amended Nov 2023; phased through 2025
What it requires
Requires cybersecurity program, CISO, MFA, 72-hour incident reporting, governance, and annual certification
cybersecurityfinanceregulationny-statenypolicy
Free account
Create a free account
Track New York policy and save searches across the Network. Free. No card required.
Want to turn policy like this into market and network moves? Build your Market Network Strategic Plan →
