Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Meeting NYCRR500 Requirements with Discovery and Encryption

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

PK Discovery and PK Encryption combine intelligent data discovery, classification, and data protection to enable enterprise-wide control over sensitive data. Financial services organizations and their third party service providers can improve their data security and privacy protection while ensuring compliance with 23 NYCRR 500 and other government regulations and industry mandates.

What 23 NYCRR 500 Requires

New York State adopted 23 NYCRR 500 for financial services institutions licensed or authorized by the Department of Financial Services. It took effect in March 2017 and phased in over two years, with the final provisions landing in March 2019.

Its approach is broader than earlier US law, setting minimum standards across risk assessment, policy creation, access control, data protection and event reporting rather than addressing a single data type.

Who It Applies To

With narrow exceptions for smaller organizations, it reaches every bank, investment company and financial services firm doing business in New York, whether or not the firm is based there.

Many covered entities also fall under GDPR and the CCPA. Those two are more sweeping, but the overlap is substantial enough that work done for one regime generally counts toward the others, provided the underlying inventory is shared rather than rebuilt per regulation.

What Non-Compliance Costs

New York banking law authorizes penalties of up to $2,500 for each day a violation continues, up to $15,000 a day where there is a reckless or unsound practice or a pattern of misconduct, and up to $75,000 a day for a knowing and willful violation.

Because the penalties accrue daily rather than per incident, the duration of a gap matters as much as its severity.

The Annual Certification

Covered entities file a Certification of Compliance each April, attesting to continuous safeguarding of sensitive customer data. Six things sit behind that signature.

A formal cybersecurity program with documented policies. Regular risk assessments. Demonstrated application security. Data protection methods including encryption. Access controls that limit who can reach sensitive information. And notification to the New York DFS within 72 hours of a breach or security incident.

The 72-Hour Clock Is the Hard Part

Three days is not long to establish what was taken. An organization that already knows what data sat in the affected systems can assess and notify inside the window. One that has to find out starts the investigation and the clock at the same moment.

Continuous discovery is what converts that from an emergency into a lookup, and it is the same inventory the certification depends on.

Third Parties Are Covered Indirectly

The law reaches service providers who hold nonpublic information without licensing them. Covered organizations must develop third party security policies that apply many of the same mandates to providers the DFS does not regulate.

In practice that means the inventory has to extend past the organization’s own systems to what was shared, with whom, and under what terms, which is the part most programs discover late.

How This Overlaps With Other Regimes

Four of the six certification requirements are things GDPR, the CCPA and PCI DSS also ask for in some form: an inventory, access control, encryption and breach notification. The deadlines and the wording differ; the underlying work does not.

Organizations that build the inventory once and report from it several times spend materially less than those running a separate project per regulation, and their answers agree with each other, which is its own benefit when two regulators ask about the same incident.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.