23 NYCRR Part 500, Second Amendment: What Changed for Our New York Clients
Risk assessments with teeth, CISO reporting lines, MFA everywhere, 72-hour notifications. What the amended NYDFS rules actually require and how covered entities keep up. A mid sized mortgage servicer in Westchester emailed us in a mild panic the week the Second Amendment's phased deadlines started landing. They'd filed their annual certification for years, assumed Part 500 was a solved problem, and then read the amended text. "We certify compliance," the CFO wrote, "but I'm no longer sure that's true." That is the correct instinct. The Second Amendment to 23 NYCRR Part 500 didn't just tweak the old rule. It moved the certification bar and gave the Department a much sharper set of things to examine against. I'll walk through what actually changed for covered entities, what the class of larger companies designated as Class A companies now carries on top of that, and how we run the whole obligation through RISKMON so the annual certification is something you can stand behind rather than hope nobody tests. The risk assessment stopped being a formality Section 500.9 always required a risk assessment. The amendment made it a living document. It has to be updated when the business or technology environment changes materially, and it must actually drive the security program, so the controls, the policies, the monitoring all have to trace back to it. Regula