NYDFS Part 500

Proven Identity. Nonpublic Information Protected.

Support NYDFS Part 500 cybersecurity requirements with phishing-resistant MFA

NYDFS Part 500 requires covered entities to run effective multi-factor authentication and protect nonpublic information. TokenCore™ delivers FIDO2-certified, hardware-bound authentication that proves the authorized person before access is granted.

No shared secret. No code to phish. No fallback.

NYDFS Part 500 Masthead

The Rule

Written for Covered Entities.

Understanding NYDFS Part 500 cybersecurity requirements

NYDFS Part 500 sets cybersecurity obligations for financial institutions operating in New York, with authentication and the protection of nonpublic information at the center.

Overview of Part 500

A cybersecurity regulation for institutions under NYDFS supervision. Identity controls sit at its core.

Covered Entities

Banks, insurers, and financial services operating in New York fall in scope. The obligation is direct.

Protection of Nonpublic Information

Sensitive data has to be defended at the point of access. That point is identity.

Annual Compliance Certification

Covered entities certify their program each year. Evidence has to hold up.

Identity as a Critical Control

Strong identity strengthens the access controls required throughout Part 500.

The Requirement

MFA That Actually Holds.

What does NYDFS require for multi-factor authentication?

Part 500 names multi-factor authentication as a core control across remote and internal access. The intent is strong authentication that an attacker cannot bypass.

Section 500.12 Multi-Factor Authentication

Strong authentication across remote and internal access.

  • Remote access requirements
  • Internal network access
  • Risk-based authentication
  • Strong authentication controls
Section 500.12 Multi-Factor Authentication

Why Authentication Is Central

Identity is where a cybersecurity program is won or lost.

  • Access protection
  • Identity verification
  • Credential security
  • Risk reduction
Why Authentication Is Central
image 233

The Guide

Map Every Requirement.

Download the NYDFS Part 500 Requirements Mapping Guide

The mapping guide shows how phishing-resistant authentication aligns with NYDFS cybersecurity requirements, section by section. A practical resource for teams building toward compliance.

The Support

One Standard. Every Control.

How TokenCore™ supports NYDFS cybersecurity controls

Privileged Access Security (500.7)

Privileged Access Security (500.7)

Privilege bound to a verified individual, and revoked cleanly.

  • Access privileges
  • Identity assurance
  • Revocation controls
Phishing-Resistant MFA (500.12)

Phishing-Resistant MFA (500.12)

Possession and biometric proof, bound to the hardware.

  • Possession factor
  • Biometric factor
  • Hardware-bound authentication
  • FIDO2 security
Strong Cryptographic Protection

Strong Cryptographic Protection (500.15)

Keys generated and held in a tamper-proof secure element.

  • Secure elements
  • Private key protection
  • Strong encryption architecture
Monitoring and auditability (500.14)

Monitoring and Auditability (500.14)

Every access event traceable to the person behind it.

  • Authentication logging
  • Identity telemetry
  • Audit trails
Incident Response Readiness (500.16)

Incident Response Readiness (500.16)

Close the credential path attackers rely on.

  • Reducing credential-based attacks
  • Ransomware prevention
  • Account takeover reduction
Third Party Security Controls (500.11)

Third-Party Security Controls (500.11)

External access held to the same proven standard.

  • Contractors
  • MSPs
  • Vendor access
  • External workforce security

Beyond Legacy MFA

The Code Is the Weakness.

Why financial institutions are moving beyond legacy MFA

Risks of OTP Authentication

A one-time code can be entered by anyone who intercepts it. A shared secret is a secret an attacker can hold too.

Push Fatigue Attacks

Approval prompts can be worn down until someone taps yes. TokenCore™ has nothing to approve and nothing to pressure.

AiTM and Reverse Proxy Phishing

Relay pages capture codes in real time and pass them through. There is no code to relay when the fingerprint stays on the device.

Why FIDO2 Delivers Stronger Protection

The credential is bound to the hardware and the person. Nothing to phish, nothing to reuse, nothing to send.

See It in Action

Make Identity Absolute

Strengthen identity security for NYDFS-regulated environments

See how TokenCore™ strengthens authentication controls, reduces identity-related cyber risk, and supports NYDFS cybersecurity requirements across your workforce and third parties.