Leela

Insurance information security

Working draft · Version 1 · Research date 2026-09-14

1. Purpose and scope

Part 500 provides a cybersecurity framework for DFS covered entities. Its obligations and exemptions vary. Use the DFS current resource center and validate the operative text and compliance dates before adopting this draft.

Confirm licensing and any section-specific exemptions. An exemption from one provision is not necessarily an exemption from the entire regulation.

2. Adoption and accountability

The accountable policy owner must confirm the legal entity, products, customer locations, applicable laws and exemptions before adoption. Maintain an applicability register and obtain management approval of procedures, owners, retention and deadlines. This template does not claim legal review or complete compliance coverage. An industry selection is a suggestion, not evidence of a legal duty.

3. Operating controls

3.1 Maintain a risk-based security program

Owner: CISO. Trigger: At material risk changes and the company’s annual program review.

Identify assets and nonpublic information, document risk, assign accountable security leadership and obtain the required policy approval. Map each applicable Part 500 provision and exemption to an owner.

Evidence: Risk assessment, policy approval and scope register.

3.2 Monitor access and protective controls

Owner: Security operations lead. Trigger: On access changes and security alerts.

Apply access, authentication, encryption and monitoring controls appropriate to the applicable provisions and recorded risks. Route exceptions to the authorized approver with a compensating control and expiry date.

Evidence: Access review, control evidence and exception register.

3.3 Assess service-provider security

Owner: Third-party risk lead. Trigger: Before onboarding a provider and at material changes.

Evaluate providers handling sensitive systems or data, record due diligence, negotiate required contractual controls and monitor identified risks. Retain the basis for the review cadence.

Evidence: Provider assessment, contract controls and follow-up.

3.4 Rehearse response and assess notifications

Owner: Incident commander. Trigger: At a cybersecurity event and response exercise.

Invoke the incident plan, preserve evidence and involve security, legal and accountable executives. Determine regulator and other notification duties, including triggering facts and time limits, using the applicable rule. Record filing decisions and receipts.

Evidence: Incident timeline, notification assessment and exercise findings.

4. Exceptions, review and records

Log deviations with the affected control, risk, interim action, owner and resolution date. Escalate missed statutory duties immediately to the responsible compliance lead; internal exceptions cannot waive law. Keep versioned approvals and follow the confirmed retention schedule and any legal hold. Review after material legal, product or operating changes.

5. Authorities and limitations

  • NYDFS Cybersecurity Regulation: 23 NYCRR Part 500 (scope and exemptions must be confirmed).
  • Research as of 2026-09-14; confirm the current operative requirements.
  • Template status: draft, awaiting organization-specific and legal review.
  • Company review cadences, operational steps and evidence examples are proposed implementation controls, not quotations from law.