Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

NYDFS · 23 NYCRR Part 500

Financial-services audit trail & incident notice.

Applies to: NY-regulated financial-services companies. Built · 2nd Amendment in force

What the signed record shows

Audit-trail records, authorized-user monitoring, and incident detail supporting 72-hour notice.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: 23 NYCRR §500.6/.7/.14/.16/.17

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

New York State Department of Financial Services Cybersecurity Requirements for Financial Services Companies, 23 NYCRR Part 500 (Second Amendment effective 1 November 2023). Provisions addressed:

§500.6
Audit trail: systems to reconstruct material financial transactions and audit trails to detect/respond to cybersecurity events; retain (a)(1) records >=5 years and (a)(2) records >=3 years.
§500.14
Monitoring and training: risk-based controls to monitor authorized- user activity and detect unauthorized access/use/tampering; Class A companies centralize logging and security-event alerting.
§500.17
Notices to the superintendent within 72 hours of a cybersecurity incident; extortion-payment notice within 24 hours.
§500.7
Access privileges and management (least privilege).
§500.16
Incident response and business continuity management.

Taken from the Regulayer entry for this instrument, which is built against the primary text.