23 NYCRR 500 for Hudson Valley Insurance Agencies and Financial Services: The Annual Certification Your CEO Has to Sign

What the amended NYDFS cybersecurity regulation means for insurance agencies from Poughkeepsie to Newburgh, and why the compliance deadline is closer than you think.

By Jim Venuto | January 20, 2026 | Hudson Valley CISO

A few months ago, I sat down with the owner of a mid-sized insurance agency in Dutchess County. He had been in the business for over twenty years, built a solid book of commercial and personal lines, employed about thirty people across two offices. He knew regulation. He understood E&O exposure, market conduct exams, and the intricacies of surplus lines filings. But when I asked him about his annual 23 NYCRR 500 certification, he looked at me like I had started speaking a different language.

Then I explained it: every year, he personally—not his IT vendor, not his office manager, but he as the senior governing body of his company—had to sign a certification to the New York Department of Financial Services affirming that his agency was in material compliance with a detailed cybersecurity regulation. That the controls were in place. That the risk assessment was current. That the policies had been reviewed and approved. His signature. His liability.

He went quiet for about ten seconds. Then he said, “Nobody told me that.”

He is not alone. Across the Hudson Valley, from Kingston to Middletown, from Beacon to Goshen, insurance agencies and small financial services firms operate under the jurisdiction of the NYDFS and are subject to 23 NYCRR Part 500. Many of them know it exists. Far fewer understand what it actually requires of them after the November 2023 amendments took effect. This post is meant to change that.

What 23 NYCRR 500 Actually Is

23 NYCRR Part 500 is the cybersecurity regulation issued by the New York State Department of Financial Services. It originally went into effect in March 2017 and was substantially amended in November 2023, with new requirements phasing in through late 2025. The regulation applies to every entity operating under a license, registration, charter, certificate, permit, or similar authorization under the New York Banking Law, Insurance Law, or Financial Services Law. That includes insurance agencies, brokers, managing general agents, premium finance companies, mortgage brokers and bankers, licensed lenders, and money transmitters.

If your agency is licensed by the NYDFS, this applies to you. The regulation does not care whether you have five employees or five hundred. It does not care whether you feel like you are "too small to be a target." It does not care whether your carrier handles most of the data. You hold policyholder information. You are a covered entity.

The Tiered Structure

The 2023 amendments introduced a tiered compliance structure based on the size and revenue of the covered entity. Class A companies are the largest—those with over 2,000 employees or over $1 billion in gross annual revenue, including affiliates. They face the most stringent requirements, including independent audits of their cybersecurity programs and more rigorous board-level oversight.

Standard covered entities make up the broad middle tier. Most insurance agencies in the Hudson Valley fall here. You have the full complement of requirements: written cybersecurity policies, a designated CISO, risk assessments, penetration testing, vulnerability assessments, multi-factor authentication, encryption standards, incident response planning, third-party service provider due diligence, and annual certification.

The small business exemption applies to entities with fewer than 20 employees (including independent contractors), less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in total year-end assets. If you qualify, you receive limited exemptions from certain requirements—but not from the core obligations. You still need a cybersecurity program, a written policy, access controls, a risk assessment, and you still have to file the annual certification. The exemption is narrower than most people assume.

The CISO Requirement: You Need One, But It Does Not Have to Be on Payroll

Section 500.4 of the regulation requires every covered entity to designate a qualified individual as Chief Information Security Officer, responsible for overseeing and implementing the cybersecurity program. For a twenty-person insurance agency in Orange County, hiring a full-time CISO is not realistic. The regulation accounts for this. The CISO function can be fulfilled by a third-party service provider or an affiliate. What matters is that someone qualified is accountable, that they report to the senior governing body at least annually, and that their role is documented.

This is where the fractional CISO model becomes relevant. A fractional or virtual CISO provides the strategic oversight, policy development, regulatory reporting, and board communication that the regulation demands, scoped to the size and complexity of your organization. They work alongside your existing IT provider—they do not replace them. Your IT company keeps the network running. The CISO ensures that the cybersecurity program meets regulatory standards and that you can demonstrate compliance when asked.

Key distinction: Your managed service provider handles your firewalls, patching, and endpoint protection. Your CISO handles your cybersecurity program governance, risk assessment methodology, regulatory filings, and policy framework. These are different functions. Treating them as the same thing is one of the most common compliance gaps I see in Hudson Valley agencies.

The Core Requirements in Plain Terms

Risk Assessment. You must conduct a periodic risk assessment that is documented, updated to address changes in your environment, and used to inform your cybersecurity program. This is not a checkbox questionnaire from your IT vendor. It is a structured evaluation of the threats and vulnerabilities relevant to your specific operations, data, and systems. The amended regulation requires that the risk assessment be updated at least annually and whenever a material change to your business or technology environment occurs.

Penetration Testing and Vulnerability Assessments. The 2023 amendments replaced the old prescriptive testing requirements with a risk-based approach. You must now have a monitoring and testing program that includes continuous monitoring or annual penetration testing, as well as automated vulnerability scans. Most agencies will find that an annual penetration test combined with quarterly vulnerability scanning satisfies the requirement, but the specifics should be driven by your risk assessment.

Multi-Factor Authentication. MFA is required for any individual accessing the covered entity's information systems from an external network, for remote access to the network, and for all privileged accounts. The amendments tightened this significantly. If your employees are logging into your agency management system, email, or remote desktop with just a username and password, you are out of compliance. There is no exemption from this requirement for small businesses.

Encryption. Nonpublic information must be encrypted both in transit and at rest. Where encryption is not feasible, you must document compensating controls and obtain CISO approval. For most agencies, this means ensuring that email containing policyholder data uses TLS at minimum, that laptops and workstations use full-disk encryption, and that databases storing customer information are encrypted.

Incident Response. You need a written incident response plan that addresses internal processes for responding to cybersecurity events, roles and responsibilities, communication plans, and remediation procedures. When a cybersecurity event occurs, you must notify the NYDFS Superintendent within 72 hours if the event has a reasonable likelihood of materially harming any part of your normal operations, or if you make a ransom payment. The reporting requirements under the amended regulation are broader than many agencies realize.

Third-Party Service Provider Security. You must have a written policy governing the security of information systems and nonpublic information accessible to or held by third-party service providers. This includes due diligence processes, minimum cybersecurity practices required of vendors, periodic risk assessments of third parties, and contractual protections. For an insurance agency, your third parties likely include your agency management system provider, your cloud and email provider, your IT managed service provider, and any outside vendors with access to policyholder data.

Training and Awareness. Cybersecurity awareness training must be provided to all personnel. The amended regulation also requires specialized training for cybersecurity personnel. Annual phishing simulations and security awareness programs are the standard approach, but the content should be tailored to the actual threats your agency faces.

The Annual Certification: What Your Signature Means

Every year, on or before April 15, each covered entity must file a certification of material compliance with the NYDFS through the DFS cybersecurity portal. The certification covers the prior calendar year. The senior governing body—typically the agency principal, CEO, or managing partner—must sign it. Alternatively, you may file an acknowledgment of noncompliance that identifies the areas where you fall short, your remediation timeline, and the steps being taken to address each gap.

This is not a soft obligation. When you sign the certification, you are personally attesting that your organization has maintained a cybersecurity program that materially complies with the regulation throughout the preceding year. You are affirming that you have reviewed the relevant documentation, that the risk assessment is current, that the policies are in effect, and that the controls are operating. If the NYDFS later determines that your certification was inaccurate, you face potential enforcement action including monetary penalties, consent orders, and reputational damage.

The amended regulation made the consequences clearer. Penalties can reach $1,000 per violation per day, and the NYDFS has demonstrated a willingness to pursue enforcement against organizations of all sizes. Signing the certification without actually verifying compliance is not a defensible strategy.

Building the Evidence Pack

If your CEO or principal has to sign an annual certification, they need evidence to rely on. That evidence should be compiled into a structured compliance package that is reviewed before the certification is filed. The following table outlines what that package should contain.

Evidence Item Description Frequency
Risk Assessment Report Documented assessment of threats, vulnerabilities, and risks to the agency's information systems and nonpublic information. Must reflect current environment and be aligned with NYDFS methodology expectations. Annual minimum; update upon material changes
Penetration Test Results Report from a qualified third party documenting external and internal penetration testing scope, findings, and remediation status. Should map findings to risk levels. Annual
Vulnerability Scan Reports Automated scan results showing identified vulnerabilities across the agency's network, systems, and applications, with evidence of remediation for critical and high findings. At least quarterly; continuous monitoring preferred
MFA Deployment Documentation Configuration records confirming MFA is enabled for all remote access, external-facing systems, privileged accounts, and email. Include system screenshots or admin console exports. Annual review; document changes as they occur
Encryption Status Documentation Records confirming encryption in transit (TLS for email, HTTPS for web applications) and at rest (full-disk encryption on endpoints, database encryption). Document any compensating controls with CISO sign-off. Annual review
Third-Party Vendor Inventory Complete list of third-party service providers with access to agency systems or nonpublic information, including risk rating, date of last due diligence review, and contractual cybersecurity provisions. Annual review; update when vendors change
Security Awareness Training Records Documentation of training completion for all personnel, including dates, topics covered, and participation rates. Include phishing simulation results with click rates and follow-up actions. Annual minimum
Incident Response Plan Written plan covering detection, response, notification, and recovery procedures. Must include NYDFS 72-hour notification requirements and roles/responsibilities for key personnel. Annual review and update; test at least annually
Cybersecurity Policies Written policies approved by the senior governing body or CISO covering all areas required by Section 500.3: information security, access controls, business continuity, data retention, systems monitoring, and others. Annual review and approval
CISO Annual Report Written report from the CISO to the senior governing body covering the status of the cybersecurity program, material risks, results of testing, and planned improvements for the coming year. Annual

Each of these items should be dated, version-controlled, and stored in a manner that allows retrieval during a regulatory examination. If the NYDFS sends you an information request—and they do send them, including to small agencies—you need to produce these documents in a reasonable timeframe. "We had it but can't find it" does not satisfy an examiner.

Recent Enforcement Actions and What They Signal

The NYDFS has made clear through its enforcement actions that 23 NYCRR 500 is not an aspirational guideline. In recent years, the department has pursued significant penalties against regulated entities for cybersecurity failures. A major title insurance company was fined for failing to implement proper access controls and MFA, resulting in a breach affecting millions of records. Multiple insurance and financial services companies have entered into consent orders over deficiencies including outdated risk assessments, failure to implement MFA, inadequate vendor management, and misleading certifications.

The pattern in these enforcement actions is worth noting. The NYDFS is not only penalizing organizations for having breaches. They are penalizing organizations for lacking the controls the regulation requires, whether or not a breach has occurred. They are also scrutinizing the accuracy of annual certifications. If you certified compliance and the department later finds that you did not actually have the controls in place, the certification itself becomes the problem.

For a Hudson Valley insurance agency, the practical risk is real. The NYDFS conducts targeted examinations of smaller entities, not just the large carriers and banks. An agency in the Mid-Hudson region is just as subject to examination as one in Manhattan. Geographic distance from the Financial District offers no insulation from regulatory oversight.

Getting From Where You Are to Where You Need to Be

If you are reading this and realizing that your agency has gaps, the worst thing you can do is nothing. The second worst thing is to panic and throw money at a technology solution without understanding what the regulation actually requires. Here is a reasonable path forward.

Start with a gap assessment. Compare your current cybersecurity practices against each section of 23 NYCRR 500 as amended. Identify where you are compliant, where you have partial controls, and where you have nothing in place. Be honest about it. This assessment becomes the foundation for your remediation plan and, if necessary, your acknowledgment of noncompliance filing.

Designate your CISO function. Whether that person is internal or external, make the designation formal and documented. Ensure they have the authority and access needed to oversee the cybersecurity program and report to the senior governing body. If you are engaging a fractional CISO, make sure the engagement letter clearly defines the scope, responsibilities, and reporting cadence.

Prioritize MFA, encryption, and your risk assessment. These are the areas where the NYDFS has shown the most enforcement interest, and they are also the areas where many agencies have the largest gaps. MFA can typically be deployed across an agency's core systems within a few weeks. Encryption for endpoints and email in transit is largely a configuration exercise with modern tools. The risk assessment takes more time to do properly, but it is the document that drives everything else in your program.

Build the evidence habit. Compliance is not a one-time project. It is an ongoing operational discipline. Every time a vulnerability scan runs, the results should be filed. Every time training is completed, the records should be saved. Every time a policy is reviewed, the approval should be documented. By the time April 15 comes around, the evidence pack should already be assembled from the prior year's activities, not created in a rush during the first week of April.

If your insurance agency or financial services firm needs help navigating 23 NYCRR 500 compliance, gap assessments, or fractional CISO services, visit hudsonvalleyciso.com to learn how we help Hudson Valley businesses build cybersecurity programs that satisfy regulators and actually protect the business.

References

NYDFS Cybersecurity Resource Center – 23 NYCRR Part 500
NYDFS Press Releases – Enforcement Actions
NYDFS Cybersecurity Guidance and FAQs
23 NYCRR Part 500 – Full Regulation Text