Regulatory

What NYDFS Section 500.16 requires for incident-response testing

Law & Forensics Editorial
Editorial illustration for the article "What NYDFS Section 500.16 requires for incident-response testing".

The New York Department of Financial Services expects covered entities to prove that their incident response plans work, not merely that the plans exist. Section 500.16 of 23 NYCRR Part 500 sets that expectation in writing. Under the Second Amendment to Part 500, which took effect on November 1, 2023, a covered entity must maintain written incident response and business continuity and disaster recovery plans and test them at least annually with all staff and management critical to the response. Several of the amended requirements carried a one-year transition period and took effect on November 1, 2024. For general counsel, CISOs, and boards at DFS-licensed banks and insurers, the practical question is no longer whether to run a tabletop exercise but how to structure one that satisfies the regulation and produces evidence of readiness.

The plain text of the testing obligation

Section 500.16 addresses two forms of resilience planning that the amendment now treats together: incident response and business continuity and disaster recovery. Under Section 500.16(a), each covered entity must establish written plans containing proactive measures to investigate and mitigate cybersecurity events and to ensure operational resilience, including incident response plans and business continuity and disaster recovery plans. Section 500.16(d) then requires the entity to test, at least annually, both those plans with all staff and management critical to the response, and its ability to restore its critical data and information systems from backups. The pairing matters. A firm that can detect and contain an intrusion but cannot restore operations has not demonstrated resilience, and the regulation now reaches both capabilities within a single section.

The annual cadence is the anchor. The regulation does not treat testing as a one-time certification event or something to be performed only after an actual incident. It requires a recurring exercise, conducted at least once each year, that involves the people who would carry out the plan in a live event. The phrase "all staff and management critical to the response" is doing real work here. A tabletop that includes only the security team, or only outside consultants, does not meet the intent of a test designed to confirm that the organization can execute its plan under pressure, and the reference to management is explicit in the text.

The amendment also specified what an incident response plan must contain. Section 500.16(a)(1) sets out the elements the plan must address, including the internal processes for responding to a cybersecurity event, the goals of the plan, the definition of clear roles and responsibilities and levels of decision-making authority, external and internal communications, and requirements for documenting and reporting the incident and the response. Testing is the mechanism that connects that written content to operational reality. A plan that names roles, escalation paths, notification obligations, and recovery procedures is only as good as the organization's demonstrated ability to follow it.

Why senior leadership participation is now the expectation

The most consequential shift in the Second Amendment is not a single technical control. It is the elevation of governance. Section 500.17(b) requires the covered entity to submit, each year by April 15, either a written certification of material compliance with Part 500 or a written acknowledgment that it did not fully comply, and that filing must be signed by the covered entity's highest-ranking executive and its chief information security officer. That accountability does not stop at signing a certification. It runs through the testing obligation.

Section 500.4 places responsibility for the cybersecurity program with senior leadership, requiring the CISO to report in writing at least annually to the senior governing body on the program and material risks. Read alongside Section 500.16's requirement to test with staff and management critical to the response, these provisions make the case that a Section 500.16 test is incomplete if the people accountable for the program never sit in the room.

Practically, this means the annual exercise should surface the decisions that only senior officers can make. Those include when to notify the Department, whether to authorize an extortion payment, how to weigh operational continuity against containment, and how to coordinate legal, communications, and regulatory response. A test that never forces those decisions leaves the highest-risk moments of an incident unrehearsed. The regulation's governance provisions, combined with the requirement to test with management critical to the response, point toward exercises where senior leadership participates rather than observes.

How the testing obligation fits the broader Part 500 structure

Section 500.16 does not operate in isolation. It sits inside a risk-based program that the regulation has required since it took effect on March 1, 2017, with an initial 180-day transitional compliance period ending August 28, 2017. The resilience requirement is one of a set of running obligations: a documented risk assessment, a written cybersecurity policy approved by a senior officer or the senior governing body, a designated and qualified CISO, technical safeguards including multi-factor authentication and encryption, penetration testing and vulnerability assessments, third-party service provider oversight, resilience planning, and reporting and certification.

Two of those neighboring obligations shape how a Section 500.16 test should be designed. First, the reporting rules create hard deadlines that a tabletop should exercise. Under Section 500.17, a covered entity must notify the Superintendent as promptly as possible but no later than 72 hours after determining that a cybersecurity incident has occurred, and, under Section 500.17(c), must give notice within 24 hours of making an extortion payment and provide a written description of the reasons the payment was necessary within 30 days. An incident response test that ignores those clocks misses one of the regulation's most time-sensitive expectations. Second, the definitions in Section 500.1 tell participants what actually triggers those obligations. Under Section 500.1(g), a cybersecurity incident is a cybersecurity event that impacts the covered entity and requires notice to a government body, self-regulatory agency, or other supervisory body; that has a reasonable likelihood of materially harming a material part of the covered entity's normal operations; or that results in the deployment of ransomware within a material part of its information systems. A well-built exercise tests whether participants can recognize when an event crosses into a reportable incident.

Scope also determines who must comply. Section 500.1(e) defines a covered entity as any person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation, or similar authorization under the Banking Law, the Insurance Law, or the Financial Services Law, regardless of whether the entity is also regulated by another government agency. Because that definition applies regardless of other oversight, compliance with SEC, FINRA, or federal banking rules does not substitute for Part 500. Section 500.19 provides limited exemptions for the smallest entities, those with fewer than 20 employees and independent contractors, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets. Even entities that qualify for a limited exemption remain subject to a number of core sections, so they should confirm which obligations still apply rather than assume the resilience and reporting expectations are waived.

What a defensible annual test looks like

A test that satisfies Section 500.16 and produces useful evidence tends to share several features. It is documented, it is recurring, and it involves the people who would run the plan.

  • It exercises both incident response and recovery. Because the amendment pairs incident response with business continuity and disaster recovery, a defensible test should probe not only detection and containment but also restoration of critical data and information systems from backups.
  • It includes staff and management critical to the response. The regulation's reference to management, read against its governance provisions, supports exercises in which senior officers make the escalation, notification, and payment decisions the plan assigns to them.
  • It runs against real deadlines. Building the 72-hour incident notice and 24-hour extortion-payment notice into the scenario tests whether the organization can meet the reporting obligations under Section 500.17.
  • It generates a record. Documentation of who participated, what gaps emerged, and how the plan was updated afterward supports the annual certification and demonstrates that the plan was tested rather than merely filed.

The NYDFS built Part 500 to require that firms design programs matched to their specific risk profile rather than follow a single prescriptive checklist. Section 500.16 applies that philosophy to readiness. The regulation does not dictate a script for the annual exercise. It requires that the plans be written, that they be tested at least once a year, that staff and management critical to the response take part, and that the organization test its ability to restore critical data and information systems from backups. For covered entities, the reliable path to compliance is an exercise that puts the plan, the deadlines, and the accountable leaders under realistic pressure, then feeds what it uncovers back into the plan before the next incident arrives.

Written by

Law & Forensics Editorial

Editorial team, Law & Forensics

The editorial team at Law & Forensics, the firm behind Tabletop.ai.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.