Penetration testing for the New York DFS cybersecurity regulation

If your company holds a license, registration, or charter from the New York Department of Financial Services, its cybersecurity regulation applies to you. That covers banks, insurers and insurance agencies, mortgage companies, money transmitters, and other financial businesses licensed in New York. The regulation asks for penetration testing every year, from both inside and outside your systems. This page explains what it says and how to get both tests done without a consulting engagement.

Penetration testing for the New York DFS cybersecurity regulation

What the regulation says

Section 500.5 of the regulation (23 NYCRR Part 500) requires covered entities to conduct penetration testing "from both inside and outside" the boundaries of their information systems, at least annually, by a "qualified internal or external party." It also requires automated scans of your systems for vulnerabilities, and prompt fixes ranked by risk.

Inside and outside means two tests

  • The outside test checks what an attacker on the internet can reach: your public websites, remote access, and anything else exposed.
  • The inside test starts from a foothold on your network and shows how far an intruder could move.

An external test on its own does not satisfy the regulation. You need both.

The small company exemption

Smaller covered entities, for example those with fewer than 20 employees, may qualify for a limited exemption under section 500.19 that removes the annual penetration testing requirement. Check section 500.19 or ask your compliance advisor before you rely on it. Many exempt firms still test because their insurer or a business partner asks for it.

Both tests, one checkout

Each test starts the same day, safely attempts real exploitation, includes retests after you fix findings, and ends with an executive summary and a technical report for your records and your examiner.

When you need an engineer

If your examiner or your own policy calls for a test led by a named engineer, our managed penetration testing team does that.

This page is general information, not legal advice. Ask your attorney or compliance advisor how the regulation applies to your business.

See pen test pricing and buy online · Talk to a specialist

Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, FTC Safeguards Rule, cyber insurance, penetration test cost

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.