The Protocol CollectiveAll guides

Guide

NYDFS Part 500: what a covered entity actually has to show

New York's cybersecurity regulation, 23 NYCRR Part 500, is one of the clearer examples of a rule that rewards being able to show your working. It sets out what a covered entity must have, and the recent amendments have raised the bar on governance and evidence.

The spine of the rule

A written cybersecurity program based on a risk assessment, a designated CISO who reports to the board, access controls and multi-factor authentication, an incident response plan with reporting obligations, third-party service-provider oversight, and periodic certification by senior leadership. Class A companies carry additional expectations.

Where entities get caught

The certification is only as good as the evidence behind it. Signing off that controls are in place, without the records to support it, is the exposure. The rule effectively asks for a living program with an audit trail, not a policy that was written once and filed.

A structure that keeps the record

The Protocol Collective's dashboards map obligations like Part 500 to the evidence that proves them, in one owned file, paid once, updated for life. Built from public frameworks.

Explore The Protocol Collective

General information about compliance and program structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks.