Under 23 NYCRR 500, a cybersecurity incident starts a 72-hour clock to notify the Superintendent, whether it happened in your building or a vendor's. Pay a ransom and that clock drops to 24 hours. Every April, your CISO signs a certification saying the whole thing works.
23 NYCRR 500 applies to entities licensed under NY Banking, Insurance, or Financial Services Law. It draws a specific line between a "cybersecurity event" and a reportable "cybersecurity incident" — and most of the exposure lives in that distinction.
| Trigger | Deadline | What's Required |
|---|---|---|
| Cybersecurity Incident | 72 hours | Notice to the Superintendent once an event materially harms normal operations, requires notice to another government body, or involves ransomware deployment — at your entity, an affiliate, or a third-party service provider. |
| Extortion / Ransom Payment | 24 hours, then 30 days | Notice within 24 hours of payment, followed by a written explanation: why it was necessary, what alternatives were considered, and what diligence and sanctions checks were done. |
| Annual Certification | Due April 15 | Signed by the CISO and the highest-ranking executive — either certifying material compliance or acknowledging noncompliance with a remediation timeline. Supporting records held 5 years. |
Answer these yourself. If you hesitate on more than one, that's worth twenty minutes on a tabletop before it's worth twenty minutes with a regulator.
The biggest institutions run coordinated, sector-wide cyber exercises once a year. Most banks either aren't in the room for those, or only get tested that one time. This is what happens in between.
The five questions above, plus a short written breakdown of where your answers likely put you relative to Part 500's actual thresholds. No pitch, no call needed to get value out of it.
A single realistic scenario — wire fraud, business email compromise, or ransomware reaching your core banking environment through a vendor — played against the real 72-hour classification-to-notification chain. Tests who actually owns the reportability call and whether the notice can be drafted and out the door before the clock runs out.
A cascading incident that starts at a third-party processor, forces a live ransom-payment decision with the 24-hour clock already running, and lands on your CISO's desk two weeks before they'd otherwise be signing the April certification. Board-level, high pressure, built around your actual vendor relationships.
Reply with where you landed. You'll get a straight read on it back, no obligation.
Send My Answers TableTop@CranialThunder.com