Skip to content

/nydfs-expert

NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill nydfs-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/nydfs-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk

SKILL.md

nydfs-expert.SKILL.md
name: nydfs-expert
description: NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management.
allowed-tools: Read, Glob, Grep, Write

NYDFS Expert

Deep expertise in New York Department of Financial Services (NYDFS) 23 NYCRR 500 cybersecurity requirements for financial services institutions.

Expertise Areas

NYDFS 23 NYCRR 500 Overview

**Official Title**: "Cybersecurity Requirements for Financial Services Companies" **Authority**: New York Department of Financial Services (Superintendent) **Effective Date**: March 1, 2017 (phased implementation through February 2019) **Major Amendment**: November 1, 2023 (significant updates) **Scope**: Financial services institutions operating in New York State **Annual Certification**: Due April 15 each year

**Regulatory Authority**:

  • NY Financial Services Law Section 201
  • NY Insurance Law Section 302
  • NY Banking Law Article 2
  • Superintendent's emergency rulemaking authority

**Purpose**:

  • Protect consumer financial data
  • Ensure operational resilience of financial sector
  • Establish minimum cybersecurity standards
  • Promote cybersecurity risk management culture
  • Align NY with leading cybersecurity practices

Covered Entities

**Financial Institutions Subject to 23 NYCRR 500**:

  • State-chartered banks
  • Foreign bank branches in NY
  • Trust companies and private bankers
  • Insurance companies (life, health, P&C)
  • Insurance agents and brokers
  • Licensed lenders and mortgage companies
  • Money transmitters
  • Virtual currency businesses (BitLicense)
  • Premium finance agencies
  • Any entity operating under NYDFS supervision

**Exemptions from Coverage**:

  • Entities exempt from licensing
  • Entities with <10 employees, <$5M revenue, <$10M assets (limited exemptions for certain requirements)
  • Charitable organizations (some)

**Affiliate Entities**:

  • Parent companies may be covered
  • Subsidiaries subject if meet criteria
  • Shared services models common

23 Sections Deep Dive

**500.00 - Introduction**

Purpose and scope of regulation.

**500.01 - Definitions**

**Key Defined Terms**:

  • **Affiliate**: Entity that controls, is controlled by, or is under common control
  • **Authorized User**: Person with access to Information Systems
  • **Board of Directors**: Governing body or senior officer(s)
  • **Covered Entity**: Entity required to comply with 23 NYCRR 500
  • **Cybersecurity Event**: Act that threatens confidentiality, integrity, or availability
  • **Information System**: Systems owned/operated by covered entity or service providers
  • **Multi-Factor Authentication**: At least two of: knowledge, possession, inherence
  • **Nonpublic Information**: Business-related information not publicly available + private customer information
  • **Penetration Testing**: Simulated attack to identify exploitable vulnerabilities
  • **Privileged Account**: Account with elevated access rights
  • **Risk Assessment**: Process to identify reasonably foreseeable threats
  • **Senior Officer**: Senior executive with regular contact with Board
  • **Service Provider**: Third party granted access to Information Systems or Nonpublic Information

**500.02 - Cybersecurity Program**

**Requirements**:

  • Maintain cybersecurity program based on Risk Assessment
  • Written policies and procedures
  • Protect confidentiality, integrity, and availability
  • NIST Cybersecurity Framework alignment (recommended)

**Program Elements Must Include**:

  • Information security
  • Data governance and classification
  • Asset inventory and device management
  • Access controls and identity management
  • Business continuity and disaster recovery
  • Systems operations and availability
  • Systems and network security
  • Systems and application development
  • Physical security and environmental controls
  • Customer data privacy
  • Vendor and third-party management
  • Risk assessment
  • Incident response

**Risk-Based Approach**:

  • Tailor to size, complexity, resources
  • Focus on material risks
  • Document risk-based decisions
  • CISO approval of risk-based approaches

**500.03 - Cybersecurity Policy**

**Written Policy Required**:

  • Board of Directors approved
  • Addresses all areas in 500.02
  • Reviewed and updated regularly
  • Communicated to personnel

**Policy Must Address**:

1. Information security 2. Data governance and classification 3. Asset inventory and device management 4. Access controls and identity management 5. Business continuity and disaster recovery planning 6. Systems operations and availability concerns 7. Systems and network security 8. Systems and application development and quality assurance 9. Physical security and environmental controls 10. Customer data privacy 11. Vendor and third-party service provider management 12. Risk assessment 13. Incident response

**Board Approval**:

  • Annual review minimum
  • Documented Board approval
  • Updates as needed
  • Version control

**500.04 - Chief Information Security Officer (CISO)**

**CISO Requirement**:

  • Designated qualified individual
  • Can be employee, affiliate, or third-party
  • Oversees and implements cybersecurity program
  • Enforces cybersecurity policy
  • Reports to Board of Directors or Senior Officer

**CISO Responsibilities**:

  • Program oversight and implementation
  • Policy development and enforcement
  • Annual risk assessment
  • Board reporting
  • Incident response leadership
  • Third-party risk oversight
  • Compliance management
  • Resource planning

**Reporting**:

  • To Board or Senior Officer
  • Annual report minimum
  • Incident notifications
  • Material changes (15-day notice)

**Qualifications**:

  • Adequate expertise and resources
  • Financial services experience (preferred)
  • Regulatory compliance knowledge
  • Technical and leadership skills

**Material Change Notification** (500.18):

  • 15
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked