The Clocks You're Already On

23 NYCRR 500 applies to entities licensed under NY Banking, Insurance, or Financial Services Law. It draws a specific line between a "cybersecurity event" and a reportable "cybersecurity incident" — and most of the exposure lives in that distinction.

TriggerDeadlineWhat's Required
Cybersecurity Incident 72 hours Notice to the Superintendent once an event materially harms normal operations, requires notice to another government body, or involves ransomware deployment — at your entity, an affiliate, or a third-party service provider.
Extortion / Ransom Payment 24 hours, then 30 days Notice within 24 hours of payment, followed by a written explanation: why it was necessary, what alternatives were considered, and what diligence and sanctions checks were done.
Annual Certification Due April 15 Signed by the CISO and the highest-ranking executive — either certifying material compliance or acknowledging noncompliance with a remediation timeline. Supporting records held 5 years.

The Questions That Matter

Answer these yourself. If you hesitate on more than one, that's worth twenty minutes on a tabletop before it's worth twenty minutes with a regulator.

Learn. Practice. Do.

The biggest institutions run coordinated, sector-wide cyber exercises once a year. Most banks either aren't in the room for those, or only get tested that one time. This is what happens in between.

Learn

Free • Self-Assessment

The five questions above, plus a short written breakdown of where your answers likely put you relative to Part 500's actual thresholds. No pitch, no call needed to get value out of it.

Practice

Half-Day TTX

A single realistic scenario — wire fraud, business email compromise, or ransomware reaching your core banking environment through a vendor — played against the real 72-hour classification-to-notification chain. Tests who actually owns the reportability call and whether the notice can be drafted and out the door before the clock runs out.

Full inject sequence and facilitator materials shared during scoping.

Do

Full-Day • Crisis

A cascading incident that starts at a third-party processor, forces a live ransom-payment decision with the 24-hour clock already running, and lands on your CISO's desk two weeks before they'd otherwise be signing the April certification. Board-level, high pressure, built around your actual vendor relationships.

Scenario design is built around your institution, your vendors, and your regulator relationship.

Send Your Five Answers

Reply with where you landed. You'll get a straight read on it back, no obligation.

Send My Answers TableTop@CranialThunder.com
No phone. No sales team. One expert. Direct access.