top of page

23 NYCRR 500: The NYDFS Cybersecurity Regulation Every New York Mortgage Broker Must Answer To

Rather than relying on vague promises, we build security programs for brokers structured around the NYDFS Cybersecurity Regulation and 23 NYCRR 500 standards that any examiner or lender will recognize.

Compliant Standards, Unified Program

The NIST Cybersecurity Framework (CSF)

The framework used by banks to organize security. We map your 23 NYCRR 500 compliance against it, function by function: Govern, Identify, Protect, Detect, Respond, and Recover for the NYDFS Cybersecurity Regulation.

Microsoft's Zero Trust Model

Verify explicitly and assume breach. Since your stack runs on Microsoft 365, building on this security architecture for 23 NYCRR 500 and the NYDFS Cybersecurity Regulation keeps things simple and cost-effective.

Stated Plainly

This security program aligns with NIST CSF and Microsoft Zero Trust to meet 23 NYCRR 500 requirements. A rigorous self-assessment against the NYDFS Cybersecurity Regulation is the right-sized answer for a broker-sized shop. It is what you can afford, and it is exactly what your lending partners and examiners are asking for. Our goal is to ensure your firm meets the NYDFS Cybersecurity Regulation standards honestly.

One-Time Fee. What's Included

  • A full 23 NYCRR 500 risk assessment. A written security program (WISP) mapped to NIST CSF Conditional Access + MFA setup. The documentation packet for any examiner asking about the NYDFS Cybersecurity Regulation posture.

Coverage Across All States

A strict adherence to theĀ 23 NYCRR 500 mandates ensures compliance with the state of New York while also covering, or in many cases surpassing the state specific overlays across the nation. l

New York Brokers

NY enforces the strict NYDFS Cybersecurity Regulation, and examiners expect 23 NYCRR 500 risk assessments to be active. If licensed in NY, we build your NYDFS Cybersecurity Regulation refresh cycle in from the start to ensure you are always compliant with 23 NYCRR 500.

Exceptions for Smaller Brokerages

Most of 23 NYCRR 500 was written with banks and insurers in mind, not five-person brokerages. New York's Limited Exemption (500.19(a)) recognizes that -- and most independent mortgage brokers qualify.

You likely qualify for the Limited Exemption if your brokerage has:
  • Fewer than 20 employees, including independent contractors, who work at or for the business in New York
  • Less than $7.5 million in gross annual revenue from New York business operations in each of the last three fiscal years
  • Less than $15 million in year-end total assets, calculated with affiliates under GAAP

Meeting any one of these generally qualifies you. DFS updates these thresholds periodically, so we confirm your exact status as part of onboarding.

What the Exemption Excuses You From

Qualifying brokers are generally excused from the most resource-intensive requirements: a dedicated full-time CISO, annual penetration testing and bi-annual vulnerability assessments, a standalone cybersecurity personnel function, and some of the formal written incident response documentation larger institutions must maintain.

What You Still Need

Exempt or not, every broker still needs a cybersecurity policy, a risk assessment, access controls, and multi-factor authentication for remote access. That baseline is exactly where we come in.

We Speak Auditor

Our expertise comes from sitting in on real conversations with New York auditors while a client of ours is in the middle of an exam. Many DFS examiners built their mental model of security around on-premises servers and manual patching -- so when a broker's answer is 'everything is cloud-based,' the conversation can stall. We're the translator in the room.

How Modern Brokerages Actually Run

We walk the auditor through how a modern Microsoft 365 shop actually works: every line-of-business app is cloud-hosted, not sitting on a server in a closet. Employee PCs receive security and feature updates automatically, on a managed schedule. We see that physical Windows devices have a TPM chip so we can encrypted a harddrive while giving end users the ability to sign-in without a secret, or hardware device containing a secret. The Business Version of Windows 11 now comes standard with a TPM chip allowing hard drive encryption and decryption with a Windows Hello authentication service. For those mortgage brokers with loan officer's working from their personal devices we can deploy tools that enable a broker to ensure company data is either in accessible, or actually removed from the device at employee seperation. This is where most data loss occurs, especially on mobile devices where emails are downloaded in the Outlook app for quick access. With out th requried Mobile Application Managent service configured properly, loan officer can walk away with several active loan files, that were already submitted to just go ahead and resubmit them with a different lender at a different mortage company. Microsoft has the tools you need to protect your data, they're just not enabled by default. Adding security policies can cause anger and frustration when a Loan Officer needs to upoload a file to the wholesale lender's web portal but they get blocked from downloading a file to their harddrive by one of these policies. Careful consideration has to go into depoying these policies where the decision maker decides the level of security overlays vs. data that's easily accessible from a personal device. This is why some companies utilize our virtual desktop servicce allowing remote users to work from their personal device, have the full freedeom to download, and upload mortage docments while still retainging data in a virtuallized PC that's fully controled by IT. These are the types of ddecisions that are disussed during a risk assesment. Every hard drive is encrypted by default. And Entra ID (formerly Azure AD) is the control point protecting everything that lives in Outlook, OneDrive, SharePoint, and Teams -- enforcing who can sign in, from where, and under what conditions.

Translating Line-of-Business Tools

Examiners occasionally call to ask us about the security behind platforms brokers use daily, like PointCentral. A tool like PointCentral does have multi-factor authentication -- it just doesn't look like the push-notification MFA an examiner expects to see, so it can read as a gap when it isn't one. We explain how it actually works so the audit reflects reality.

New York is a demanding state to run a small mortgage operation in. We take the security half of that off your plate -- without the excessive per-user, per-month fees larger firms charge.

bottom of page