logo

Highlights of New York’s Cybersecurity Regulation 23 NYCRR Part 500

ID: d7747cfd-bbcf-55ef-8d38-13f214e74cfd

STIX ID: report--d7747cfd-bbcf-55ef-8d38-13f214e74cfd

Feed Name: HackerOne Blog

Date Published: 2023-09-22

Date Updated: 2026-06-11

...
...

This HackerOne post explains that as of September 4, 2018 several sections of New York's 23 NYCRR Part 500 cybersecurity regulation became enforceable, with emphasis on penetration testing and vulnerability assessments (§500.05), audit trail requirements (§500.06), and application security (§500.08). The article recommends hacker-powered penetration testing, vulnerability disclosure programs, and HackerOne products (VDP, response platform, bug bounty/crowdsourced testing) as ways for covered financial entities to meet compliance and improve security posture.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.