Legal sources with official primary sources

Printed ·

Skip to main content
Skip to the answer

Back to the agent

Section node

Notice of a cybersecurity event

23 NYCRR 500.17

What this page is
Section node, 23 NYCRR 500.17
Checked against the official source
2026-08-15Changed
Responsible publisher
ExploreWorld Legal, editorial deskLiability position
Jurisdiction
23 NYCRR Part 500
Section node
incident
Read
2026-08-15
Hash
sha256:8e2c0fe4c1651e29

Outcomes resting on this section

The rules below point to this section in their outcome. The verdict is a machine classification, not a judgment on an individual matter.

  • nydfs-incident

    Notice of the cybersecurity event is late

    23 NYCRR 500.17(a) requires notice to the supervisor as promptly as possible and no later than 72 hours after determining that the event is notifiable. 23 NYCRR 500.17(b) requires an annual certification.

    prohibited, Requirement applies

  • nydfs-exempt

    A limited exemption applies, the core requirements remain

    23 NYCRR 500.19 exempts certain smaller entities from parts of the regulation. The exemption does not cover the program and policy in 500.2 and 500.3, the risk assessment in 500.9 or the notice in 500.17.

    risk, Requirement applies conditionally

  • nydfs-base

    The regulation applies to the business

    23 NYCRR Part 500 applies to every entity licensed under New York banking, insurance or financial services law. The requirements cover the program, the responsible function, authentication and notice.

    risk, Requirement applies

Section nodes

The verdict is a machine classification of the outcome, not legal advice and not a compliance decision.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit