Cybersecurity and DFS compliance for insurance agencies.
DFS cybersecurity compliance for a New York insurance agency means meeting 23 NYCRR Part 500, in full or under the section 500.19 limited exemption, and then certifying it every April 15. VJNetworks builds and documents those controls.
due every year
The April 15 filing is a signature. Most agencies treat it as a form.
Signing takes about four minutes. Somebody logs into the DFS portal, picks the certification of material compliance over the acknowledgment of noncompliance, signs, and closes the tab. Underneath that click sits a year of evidence which either exists or doesn’t, and the Department has been blunt about what it thinks of the gap. Its 2025 consent order against a licensed insurance agent put it in one line, that a covered entity should not certify that it is in compliance with the regulation when in fact it is not.
The other thing that changed is the calendar. Every transitional period written into the amended rule has now expired, the last of them on November 1, 2025, when the expanded multi-factor authentication requirement at section 500.12 and the asset inventory requirement at section 500.13(a) came into force. No phase-in remains to point at. An agency that was waiting for the deadlines to finish arriving can stop waiting. They finished.
Geography confuses agency owners more than size does. Part 500 follows the license rather than the office, so a Hackensack agency whose producers are licensed in New York is a covered entity like any agency on Route 59. New Jersey has no equivalent regulation, although NJ licensed insurers and producers do owe a written information security program with administrative, technical, and physical safeguards under N.J.A.C. 11:1-44, which implements Gramm-Leach-Bliley. This page covers the security layer specifically. It sits alongside our broader IT services for insurance agencies and brokers and our general cybersecurity services.
What the limited exemption actually excuses.
Nearly every independent agency we talk to qualifies for the limited exemption at section 500.19(a), and nearly every one of them overestimates what it buys. It removes ten sections. It leaves the rest.
Who qualifies
Any one of three thresholds does it. Fewer than 20 employees and independent contractors counting affiliates, under $7.5 million in gross annual revenue in each of the last three fiscal years, or under $15 million in year-end total assets. Or, not and. A twelve-person agency clears the first without anybody having to open the books. Most agencies do.
What it removes
Ten sections come off. Governance and a named CISO, vulnerability management and penetration testing, audit trails, application security, dedicated security staff, the monitoring and endpoint-detection parts of 500.14, encryption of nonpublic information at 500.15, and the written incident response and business continuity plan at 500.16. That is the whole list.
What it never touches
The half an attacker actually meets. Multi-factor authentication, access privileges, a written password policy, an annual risk assessment, vendor policy and vendor assessments, asset inventory, secure disposal of nonpublic information, annual awareness training, incident and extortion reporting, and the April 15 filing itself. None of that is optional.
Where agencies are actually exposed.
Multi-factor that a migration quietly dropped
This is not hypothetical. In its August 2025 consent order against Healthplex, Inc., a DFS-licensed independent adjuster and insurance agent, the Department found the company had multi-factor authentication on its previous email system, moved to Microsoft 365 earlier in 2021, and never confirmed the control was fully operational for people reaching webmail from an outside browser. Nobody retested the path. A phishing email asking an employee to sign in to collect a fax did the rest, and the penalty came to two million dollars.
A mailbox nobody has ever emptied
Section 500.13 asks for policies and procedures to securely dispose of nonpublic information once it is no longer needed. Agency inboxes are where that requirement goes to die. Applications, loss runs, driver’s license scans a client emailed in 2018, all of it still sitting in a mailbox that one compromised password opens. Nothing ever leaves. The retention policy is the control. Almost nobody has one. Check yours.
A risk assessment written for somebody else
A downloaded template with the agency name typed in is not a risk assessment. DFS settled with a limited-exemption licensee in August 2026 for $250,000, and inadequate risk assessment sat at the center of the findings. Ask who wrote yours. Small does not mean unexamined.
A 72-hour clock nobody has rehearsed
Section 500.17(a) gives you 72 hours from determining a reportable event occurred. Who makes that call today? Healthplex learned of its incident on November 24, 2021 and reported it to the Department on April 8, 2022. Four and a half months. That was a separate violation from the one that caused the breach, and it is the easiest of all of these to avoid, because it costs nothing to decide in advance who makes the call and where the portal login lives.
Six pieces of work, scoped to an agency.
Exemption and gap assessment
Which of the three thresholds you meet, which sections that leaves live, and a ranked list of what is missing against each one.
MFA everywhere it is named
Remote access to your systems, remote access to any third-party application holding client data, and every privileged account. Then a test from outside the office, because that is the path Healthplex missed and the one an attacker takes. Actually run it.
Access and password policy
A written password standard, permissions cut back to what each role needs, and an access review you can actually date. Producers leave. Their carrier portal logins usually don’t.
Asset inventory and disposal
An inventory of the systems you run and a retention rule that finally empties the mailboxes. Both written down, not remembered.
Vendor oversight under 500.11
Every vendor reaching client data listed, a written policy governing them, and a periodic assessment on file. Your IT provider goes on that list first. Ours does.
Reporting and the annual filing
Who decides an event is reportable, who files inside 72 hours, and the evidence pack that makes next April’s certification a review rather than a guess. Decide it before you need it.
Your agency management system and the carrier portals are inside the perimeter, not beside it.
Whichever agency management system your team runs, the day still moves through it and through a dozen carrier portals, each with its own login and its own idea of what good authentication looks like. Controls designed without that in mind get worked around by the second week, usually by whoever is fastest at quoting. We tune them against how producers actually work, and we keep Microsoft 365 and Azure configured so the security settings survive the next tenant change instead of quietly reverting.
Is this the right fit for your agency?
Built for
Independent agencies, brokerages, and adjusters across Rockland, Westchester, and Bergen running roughly 5 to 60 people, where at least one producer holds a New York license and nobody on staff owns security as a job title.
It also works as a standalone engagement. Plenty of agencies already have an IT provider they like and just need the Part 500 layer built and documented around what is already there. That is common.
Probably not for
Carriers and national brokerages with an internal security team, a named CISO, and a compliance department that owns the filing already. Different problem, different engagement.
Agencies whose procurement requires their vendors to hold SOC 2 certification. Better said now than at the end of a proposal.
Numbers worth checking before you take our word for it.
Four steps from unsure to documented.
Scoping call
Thirty minutes. Headcount, which states your producers are licensed in, what you filed last April, and who handles IT today.
Assessment
We settle the exemption question, test the controls you believe are running, and list every vendor touching client data, including the ones nobody remembers signing up for, since those are usually the ones missing from the written policy 500.11 asks you to keep.
Ranked findings
A gap register mapped section by section, in priority order, with what each one costs to close. You keep it either way.
Remediate and maintain
We close the gaps in order, then keep the documentation current on a review schedule, so the following April the filing is a reading exercise rather than a scramble to reconstruct a year nobody wrote down.
About DFS cybersecurity for insurance agencies.
We qualify for the limited exemption. Doesn’t that cover most of this?
It covers ten sections and leaves the rest. The gap is wider than most owners expect. The exemption at 500.19(a) drops governance, vulnerability management, audit trails, application security, security personnel, parts of monitoring, encryption, and the written incident response plan. Multi-factor authentication, access control, the risk assessment, vendor oversight, asset inventory, training, breach reporting, and the April 15 certification all still apply exactly as they do to a carrier.
Realistically, does DFS ever come after an agency our size?
Yes, and one of the more recent examples was a limited-exemption licensee. In August 2026 DFS announced a $250,000 settlement with a company that qualified for the exemption on the revenue threshold, with an inadequate risk assessment among the findings. The regulator’s own materials are aimed squarely at small entities. Read that again. Small is not the same as invisible.
We’re based in Bergen. Does Part 500 reach us at all?
If any of your producers hold a New York license, yes. The license travels. The regulation attaches to it rather than to the address, which catches a lot of Tri-State agencies that assumed a New Jersey office kept them out of it. New Jersey has no direct equivalent, though NJ licensed insurers and producers do owe a written information security program under N.J.A.C. 11:1-44, and Gramm-Leach-Bliley applies to client financial data wherever you sit.
MFA is switched on in Microsoft 365. Are we done with 500.12?
Switched on and enforced on every path are different things, and the difference is where agencies get caught. The Healthplex order turned on exactly that gap, a tenant migration that left webmail reachable from an outside browser without the second factor. Test it from a personal device on a home connection. Actually do it. Then repeat for every third-party portal holding client data, and for each privileged account, because those are the three places the section names.
What if we file the certification and something turns out to be missing?
Then the acknowledgment of noncompliance was the right form, and it exists for that reason. It names the sections you did not materially comply with and sets out a remediation timeline, which is a very different posture from a certification that turns out to be wrong. Agencies avoid it because it feels like an admission. File the accurate one. It reads far better than a certification somebody later has to walk back.
Is VJNetworks itself a covered entity under Part 500?
No. Only DFS-licensed businesses are covered entities, so the regulation reaches us indirectly, through your own section 500.11 duty to govern and assess third-party service providers. We would rather be transparent about that than let it sit fuzzy. It is also why we document our own practices in a form you can put in front of an examiner instead of handing you a certificate and asking you to trust it.
How is this different from the managed IT you already offer agencies?
Same team, narrower scope. Our insurance agency IT work covers the whole environment, help desk through hardware and carrier portal support. This is the security and Part 500 layer on its own, and it can run as a separate engagement if your current provider handles everything else well. Our general cybersecurity services page covers the same discipline outside a regulated setting.
For the longer walk through the regulation itself, we wrote up what NY insurance agencies must actually do under 23 NYCRR 500. A formal security risk and vulnerability assessment is usually the first concrete step, and if a carrier or your own broker is pushing you on coverage, our cyber insurance readiness audit covers the overlap.
Find out what your next certification would actually be signing.
A free security assessment settles whether the limited exemption applies to your agency, tests the controls Part 500 still requires of you, and hands back a ranked gap register. You keep the findings whether you hire us or not.
