New York’s 23 NYCRR 500 cybersecurity regulation names insurance agents and brokers directly as covered entities, and even agencies small enough to qualify for the limited exemption still have to file an annual compliance certification, run a risk assessment, and enforce MFA.
Most agency owners I talk to have heard of this regulation in passing. Fewer know it actually names their profession by title. New York’s Department of Financial Services doesn’t leave insurance agencies to guess whether a banking cybersecurity rule applies to them. It says so directly.
Why This Regulation Names Your Agency Specifically
23 NYCRR Part 500 covers “covered entities,” and the Department’s own resource center lists insurance agents and brokers by name, right alongside banks and mortgage companies. Anyone operating under a license, registration, or similar authorization through New York’s Insurance Law falls under this rule.
Banks get most of the press coverage on this regulation. Insurance agencies rarely do. Same rule, though. The requirements apply the same way regardless.

The Exemption Most Small Agencies Assume They Have
Here’s where confusion actually starts. A limited exemption exists under Section 500.19, and a lot of small agencies qualify. Three thresholds. Fewer than 20 employees and independent contractors, combined with affiliates. Under $7.5 million in gross annual revenue, averaged across the last three fiscal years. Under $15 million in year-end total assets. Meeting any one of the three qualifies you. Not all three.
Qualifying for the exemption doesn’t mean nothing applies. The Department’s own compliance checklist for limited-exempt entities still requires an annual cybersecurity certification, a reviewed risk assessment, cybersecurity awareness training, third-party vendor oversight, and MFA. Five separate obligations. “Limited” is the operative word. Not “none.”
| Requirement | Limited-Exempt Agencies | Full Covered Entities |
|---|---|---|
| Annual certification | Required | Required |
| Dedicated CISO | Excused | Required |
| Risk assessment | Required | Required |
| Annual penetration testing | Excused | Required |
| MFA enforcement | Required | Required |

What “Covered” Actually Means Day to Day
The MFA requirement here is more specific than most owners expect. It has to combine two of three factor types, something you know, something you have, something you are. A password alone doesn’t count. Neither does single sign-on running without MFA layered on top of it. As of November 2024, this covers remote access, any third-party application touching nonpublic information, and every privileged account in the agency, not just the ones logging in from home.
Third-party vendor oversight trips up agencies constantly, since most rely on outside software for policy management and claims processing. A vendor’s own compliance certificate isn’t enough on its own. The Department’s guidance is direct about this: relying solely on a provider’s certification is not adequate due diligence. Your agency still owns the responsibility for what that vendor touches.
The same nonpublic-information stakes show up in New York’s other big data law. VJNetworks covered how the SHIELD Act’s own small-business threshold works, which uses a similar any-one-of-three test but different numbers and a different scope entirely. Agencies sometimes assume meeting one automatically satisfies the other. It doesn’t.

The Deadlines That Actually Matter
Put April 15 on the calendar before anything else on this list. That’s when your annual certification of material compliance, or an acknowledgment of noncompliance with a remediation plan attached, is actually due to the Department. April 29 covers reviewing and approving your written cybersecurity policies and updating your risk assessment for the year. November 1 is the deadline for annual awareness training across the whole staff.
If something actually goes wrong, the clock moves faster. Cybersecurity incidents get reported within 72 hours of determining one occurred. Ransomware extortion payments get reported within 24 hours. Neither deadline waits for a convenient moment to start.
- Confirm whether your agency qualifies for the limited exemption, using the actual thresholds, not a guess.
- Check MFA coverage specifically against the current standard: two factor types, covering remote access, third-party NPI apps, and every privileged account.
- Pull your vendor list and confirm you have more than just a certificate on file for each one.
- Put April 15 and April 29 on the calendar now, not the week before.
- Write down who signs the certification. It has to be a senior officer alongside the CISO, or the equivalent role if you’re limited-exempt.
Questions Agency Owners Actually Ask Me
We’re a two-person agency. Does 23 NYCRR 500 even apply to us?
If we qualify for the limited exemption, are we actually off the hook?
How does this compare to the SHIELD Act? Do we need to comply with both?
Who actually has to sign the annual compliance certification?
What actually happens if we miss the April 15 deadline?
Insurance agencies get named in this regulation specifically, and that’s not a technicality worth ignoring. VJNetworks has helped small businesses across the Tri-State area work through exactly this kind of compliance for over 20 years, through cybersecurity work built around VJNetworks’ managed IT services, not generic advice written for banks. A free assessment checks where your own agency actually stands against these requirements.
Further reading: the DFS Cybersecurity Resource Center covers the full text and current guidance directly.
A free assessment checks your agency’s setup against what 23 NYCRR 500 actually requires at your size. No obligation, no sales pitch.
