What 23 NYCRR 500 Means for Your Bank's Insurance

I keep finding the same coverage gap in community bank D&O policies. On page 35, give or take a few pages, the policy has an exclusion — “arising out of any cyber event.” What that clause does is block D&O coverage for anything connected to a data breach: the investigation phase, the formal defense, everything. The provision that gets hit first is called “pre-claim investigative costs,” which is supposed to cover regulatory inquiries before formal charges are filed. The declarations page says that coverage exists. The exclusion on page 35 says it doesn’t.

I’ve been pointing this gap out to the banks for a while now, and the reaction is almost always the same. Nobody knew.

The enforcement track record

23 NYCRR 500 is the NYDFS cybersecurity regulation that requires every New York-regulated financial institution to maintain a cybersecurity program, report breaches within 72 hours, and certify compliance annually. It applies to all entities regulated by NYDFS, including state-chartered community banks operating in New York.

This gap is especially a concern for community banks based in New York. It became a real problem when NYDFS started collecting fines. Since 2024, they collected $63 million in cybersecurity penalties under Part 500.

Genesis Global paid $8 million. GEICO paid $9.75 million. PayPal paid $2 million for something as basic as not requiring MFA.

In October 2025, NYDFS swept eight auto insurers in a single action for unprotected NPI in public-facing web apps: $19 million. All crypto firms, insurers, fintechs. No community banks yet.

Community banks should be paying attention. Part 500 doesn't have a small-bank carve-out.

The per-day penalty rates are flat:

  • Standard violations: $2,500 per day
  • Reckless conduct: $15,000 per day
  • Willful violations: $75,000 per day

The amended regulation became fully effective November 2025, and the enforcement triggers are wider now than when those early crypto fines hit.

Will NYDFS pursue community banks? I don’t know. What I do know is that the violations triggering these fines aren’t esoteric. Missing MFA. Incomplete risk assessments. Late breach notification. False compliance certifications. I see some of these violations in IT audits on a regular basis.

The costs nobody budgets for

Let’s say your bank has a data breach. You follow your playbook: you notify NYDFS within 72 hours, you activate the incident response plan, you notify customers. That part is expensive but you have prepared for it.

After that, the bills start piling up in ways your budget didn’t account for: NYDFS sends a request for information. FDIC opens its own examination. AG’s office calls separately. Each agency wants its own document production and its own meetings with the board. You need separate outside counsel for each. Keep in mind: Nobody has yet filed charges. Nobody has yet issued a formal order, which is what would trigger the D&O policy’s defense costs coverage. But there are still lots and lots of questions that need lots and lots of lawyers to answer.

I’ve estimated what this might cost. One regulatory inquiry runs above $100,000 in outside counsel in the first six months, and that’s conservative. Three inquiries at once? I’ve heard estimates past $500,000.

D&O policies have a provision for this phase: “pre-claim investigative costs.” That pays for responding to regulatory inquiries before formal proceedings begin. In the community bank programs I’ve audited, this provision has not held up, and the reason goes back to the cyber exclusion on page 35.

How this plays out: The D&O form has an exclusion saying "arising out of any cyber event." A data breach is a cyber event. The NYDFS investigation arose from a data breach. The investigative costs claim arises from the investigation of that data breach. The carrier rejects the claim — cyber is excluded. The bank paid for the coverage, the D&O declarations page lists a sublimit, but the cyber exclusion language overrides all of it.

I asked brokers whether they read the cyber exclusion part before renewal and explain the implications to their clients. The answers I am hearing aren’t encouraging.

There are more ways the coverage can fall short. Some programs cap investigative costs at $100,000. And some banks just have not selected the coverage at all. Nobody flagged it at renewal. That one frustrates me because it’s the easiest to fix.

Penalties and personal exposure

Civil money penalties under Part 500 can't be insured, FDIC prohibits it. The defense costs that come before the penalty? Those can be insured, in theory, but if the D&O won't cover them, directors end up absorbing the penalty and the legal bills.

Many board members of community banks are volunteer directors. They rarely connect a cybersecurity regulation to their personal financial exposure caused by a gap in their D&O coverage their broker hasn’t raised. I’m not confident most brokers have thought about it either.

What you can check right now

Pull your D&O policy and look for three things.

1
Is investigative costs coverage selected? If it isn't listed, ask your broker whether it was offered and declined. Some programs make it optional. Some don't offer it to financial institutions at all.
2
What's the investigative costs limit? $100,000 doesn't cover one regulatory inquiry running six months, let alone three at the same time.
3
Read the cyber exclusion. If it says "arising out of any cyber event" or anything close, that clause makes the investigative costs line item on your declarations page useless.

If any of these three checks come back wrong, your program has a gap that needs attention before your next renewal.

Your examiner confirmed the D&O policy exists. That doesn’t tell you whether it pays when NYDFS starts asking questions.

If you want a more thorough review of your insurance program, get in touch.

The D&O cyber exclusion is one of five ways coverage breaks down when three policies interact. I mapped the others in Five Common Cyber Incidents, Three Policies, and the Gaps Between Them.

Joerg Proeve, Founder and Independent Risk Advisor
Joerg Proeve

Founder of Breezy Risk. 20 years of insurance, background in cybersecurity and engineering. Audits insurance for community banks and credit unions.

More about Joerg →