Law / United States / New York

New York Department of Financial Services Cybersecurity Regulation, Incident Response and Business Continuity Management

23 NYCRR 500.16

In force.

A sector security regimes rule binding private bodies.

Enforcement body
The Superintendent of Financial Services.
Instrument type
a regulation made under an act
Obligation class
Security, Governance

As of .

What it requires

  • It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The limited exemption in section 500.19(a) lifts these duties for a covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides. Section 500.19(c) lifts section 500.16 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.16 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates.
  • Establish written plans, as part of your cybersecurity program, that contain proactive measures to investigate and mitigate cybersecurity events and to ensure operational resilience, including incident response, business continuity and disaster recovery plans.
  • Design the incident response plan to enable prompt response to, and recovery from, any cybersecurity event materially affecting the confidentiality, integrity or availability of your information systems or the continuing functionality of any aspect of your business or operations, and address in it, for different types of events including ransomware: its goals; internal response processes; roles, responsibilities and levels of decision-making authority; external and internal communications and information sharing; remediation of identified weaknesses; documentation and reporting; recovery from backups; root cause analysis; and updating of the plan.
  • Design the business continuity and disaster recovery plan to ensure the availability and functionality of your information systems and material services and to protect your personnel, assets and nonpublic information during a cybersecurity-related disruption, and include at minimum: the documents, data, facilities, infrastructure, services, personnel and competencies essential to continued operations; the supervisory personnel responsible for each aspect of the plan; a plan to communicate with essential persons during a disruption; procedures for timely recovery of critical data and information systems and resumption of operations; procedures for backing up essential information with sufficient frequency and storing it offsite; and the third parties necessary to the continued operations of your information systems.
  • Ensure that current copies of the plans, or the relevant portions, are distributed or otherwise accessible, including during a cybersecurity event, to all employees necessary to implement them, and provide relevant training on their roles and responsibilities to all employees responsible for implementing them.
  • Test your incident response and business continuity and disaster recovery plans with all staff and management critical to the response, and your ability to restore critical data and information systems from backups, periodically and at least annually, and revise the plans as necessary.
  • Maintain backups necessary to restore material operations, and protect them adequately from unauthorized alterations or destruction.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Section 500.16 requires a covered entity, as part of its cybersecurity program, to establish written plans that contain proactive measures to investigate and mitigate cybersecurity events and to ensure operational resilience, including incident response, business continuity and disaster recovery plans.

The incident response plan must be reasonably designed to enable prompt response to, and recovery from, any cybersecurity event materially affecting the confidentiality, integrity or availability of the covered entity's information systems or the continuing functionality of any aspect of its business or operations.

It must address nine areas for different types of cybersecurity events, including ransomware: its goals, internal response processes, roles and decision-making authority, communications and information sharing, remediation of identified weaknesses, documentation and reporting, recovery from backups, root cause analysis, and updating of the plan.

The business continuity and disaster recovery plan must be reasonably designed to ensure the availability and functionality of the covered entity's information systems and material services and to protect its personnel, assets and nonpublic information in the event of a cybersecurity-related disruption to its normal business activities.

That plan must at minimum cover six matters: the essentials of continued operations, the supervisory personnel responsible, communication with essential persons during a disruption, timely recovery of critical data and systems, backing up essential information with offsite storage, and the third parties necessary to continued operations.

Current copies of the plans must be distributed or otherwise accessible, including during a cybersecurity event, to all employees necessary to implement them, and relevant training must be provided to all employees responsible for implementing them.

A covered entity must test its incident response and business continuity and disaster recovery plans, and its ability to restore critical data and information systems from backups, periodically and at least annually, and revise the plans as necessary. A covered entity must also maintain backups necessary to restore material operations, adequately protected from unauthorized alterations or destruction.

The covered entity's duty to notify the Superintendent of a cybersecurity incident is set out in section 500.17. Its duty to notify the Superintendent of an extortion payment is also set out in section 500.17.

A covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides, is exempt from section 500.16 under that section.

Section 500.19(c) and (d) name section 500.16 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. Part 500 took effect on , and its Second Amendment on .

Section 500.22(d)(2) gives covered entities one year from the effective date of the Second Amendment to comply with its new requirements in section 500.16.

When LexLint raises it

When your app profile says your app provides financial services.

Back to the example  ·  Lint your app